Legal / Privacy

Policy

Privacy policy

We do not save prompt or completion content. It is not stored in the product database, written to logs or traces, sampled for quality, used for training, or sent to Slack, analytics, or another operational side channel. What follows is the complete list of what we do keep.

Last updated 31 August 2026.

Everything we store, exactly

Every category of data microrouter stores, what it contains, and the reason it exists.
We keepWhich isBecause
Aggregate page analyticsPage, referrer, country, browser, operating system and device class processed by Vercel Web Analytics; no account, wallet, key, prompt or completion fieldsUnderstanding aggregate site traffic. Vercel documents this as cookie-free and uses a site-specific visitor hash that expires after 24 hours
Product analytics (on by default)A random HMAC pseudonym, public page, bounded campaign codes, referrer hostname, funnel events, and an immutable local acquisition link to the account created from that visitMeasuring whether an offer leads to a key, credit, and successful request; on unless you turn it off under Privacy choices
Usage recordsToken counts (in / out / cached), model id, serving upstream, timestamps, latency, costBilling and the per-request receipts we show you
Ledger entriesEvery credit and debit, double-entryYour balance is a sum over this ledger; you can export it as CSV
Deposit transactionsChain, transaction hash, amount, sending and receiving addressesCrediting your deposit and answering “I sent it but don’t see it”
API keysA hash of the key and its prefix — never the key itselfAuthentication; the plaintext key is shown once and not kept
Email (optional)A verified email address, your account-message preferences, and — only if you separately opt in — the time and source of your product-update consent plus its Resend contact-sync statusAuthentication, account recovery, requested alerts, important service messages, and optional product updates
Screening resultsPass/fail of sanctions-list checks on direct depositsThe legal floor for operating the direct rail; see /pay/no-kyc

That table is exhaustive. If a category is not in it, we do not hold it — there is no name, no phone number, no ID document, no device fingerprint, and no stored prompt, completion, or full conversation body.

Third parties

Public pages send page-view data to Vercel Web Analytics. Vercel documents this as cookie-free, first-party analytics that cannot track a visitor across different sites. We do not attach an account identifier, wallet, email, key, prompt, completion, or billing record to those events.

Separately, unless you turn it off under Privacy choices, public pages send a small allowlisted product event to our own domain. Those events carry no Mixpanel browser SDK, ad pixel, session recorder, or fingerprinting script . We keep the pseudonymous source record in MicroRouter’s database and, when remote reporting is enabled, project it server-to-server to an EU-resident Mixpanel project. We do not send an IP address, full user agent, raw referrer URL, account identifier, wallet, email, key, prompt, or completion.

When a measured visit creates its first account and API key, we store an immutable account-to-visitor acquisition link in MicroRouter’s own database for the retention window. It is used to derive key, payment, and successful-request funnel events. The local account ID and that linkage are never exported to Mixpanel.

We use Resend to deliver email. Resend processes the recipient address and delivery status for account email. If you separately opt in to Product updates, we also send it your subscription, campaign-delivery, and unsubscribe state. Resend may retain a suppression record after you unsubscribe so the address is not accidentally mailed again.

Your requests necessarily reach the upstream provider that serves the model; the provider sees the prompt content, under its own policy. On the aggregator payment rail, Relay screens transactions against Chainalysis — that is their infrastructure, stated precisely on /pay/no-kyc. We do not sell or rent stored data, and do not disclose it beyond the processors and payment infrastructure named above.

Retention, requests and changes

Usage and ledger records are kept for as long as the balance they account for exists, because they are the balance. Deposit transaction records are kept as long as the law governing payments requires. There is deliberately little else to retain or delete — for accountless keys, we could not link stored data to a person even if asked to. The Privacy choices control lets you stop MicroRouter product analytics, which is on by default, or delete its local pseudonymous record and request deletion from the reporting projection. Mixpanel processes that request asynchronously and says it may take up to 30 days; we retain the pseudonymous completion evidence for 13 months, while pending or failed deletion work is never aged away. Other product analytics records expire after 13 months. The control does not disable aggregate Vercel page views. This does not delete financial or usage records kept for billing and payment obligations. You can turn Product updates off in dashboard settings or use the unsubscribe link in an email. We then remove the address from MicroRouter’s product-update audience; Resend may keep the suppression record described above.

Questions or requests: privacy@microrouter.xyz. Material changes to this policy are dated in the changelog.