aigw

Privacy

Last updated: [DATE]

aigw is an EU-hosted AI gateway operated by [Company legal name] ([jurisdiction]). We do not sell your data, run ad networks, or feed it to third-party trackers. This page describes what we collect, why, and where it lives. It is provided for transparency; the definitive terms for your use are the signed agreement between us, which takes precedence where the two differ.

What we collect

  • Account: your email address (sign-in identifier), display name (optional), and workspace name. No passwords are stored; sign-in is magic-link based, with optional TOTP.
  • Usage metadata: for every request routed through the gateway we record metadata such as the model, token counts, cost, latency, status, and the subject or key that made the call. We use this for governance, budgets, billing, and observability. This metadata is always recorded.
  • Prompt and response content: off by default. The content of your prompts and the model's responses is only stored if you opt in to content logging for your workspace. When enabled, content is redacted on ingest to remove detected secrets and sensitive data before it is stored.
  • Provider API keys: the keys you supply for your model providers are stored encrypted at rest and used to call those providers on your behalf. We do not use them for any other purpose.
  • Audit log: a tamper-evident record of actions taken in your workspace, who took them, and when. We use it for support, security, and abuse investigation.
  • Server logs: standard HTTP access logs (request path, status, IP, user-agent), kept for a short period for debugging and security.

What we don't collect

  • Prompt or response content, unless you opt in to content logging.
  • Analytics from third-party ad trackers (no Google Analytics, Segment, Meta pixel, etc.).
  • Cross-site fingerprints or cookies for advertising.

Where data lives

aigw is EU-hosted and your data stays in region. Account, metadata, audit, and any opted-in content are stored on infrastructure located in the EU. When we route a request, the prompt is sent to the model provider you selected using your own key; that provider processes it under your contract and its own terms.

Subprocessors

We use a small set of subprocessors to run the service:

  • Hetzner: EU hosting and infrastructure.
  • Stripe: billing and payment processing.
  • [confirm subprocessor list, for example email delivery, before publishing.]

The model providers you route to are not our subprocessors; they act under your own provider contracts. We align our handling of personal data with the GDPR. We do not claim SOC 2, ISO, or HIPAA certification.

Retention

We keep account, metadata, and audit records for as long as your workspace is active and for a reasonable period afterward, then delete or anonymize them. Any opted-in content is retained according to the retention window you configure. Server logs are kept only briefly. Specific retention periods are set out in the signed agreement.

Your rights

Under the GDPR you have the right to access, correct, export, and delete your personal data, and to object to or restrict certain processing. Contact us to exercise these rights and we will respond within the time the law allows.

Contact

Questions, data requests, or anything that looks like an incident: hello@aigw.app.