Legal

Privacy Policy

Last updated August 28, 2026

This policy explains what KoRouter — operated by NeoAIDA LLC (Wyoming, USA) — collects, why, and what you can do about it. We keep the data footprint small on purpose — the less we hold, the less there is to lose.

What we collect

Account data. Your email address, used for sign-in via one-time codes. Registration doesn't require a name or password. If you sign in with GitHub or Google, we also receive the email address, display name, and provider account ID that the provider shares with us.

API keys. Stored as a hash — the full key is shown only once, at creation, and we cannot recover it afterward.

Usage metadata. For each request we record metadata for billing, reconciliation, and abuse prevention: the model, token counts, cost, timestamp, status, latency, a request ID, the API key used, your IP address, your client's User-Agent string, and — when your client sends them — the X-Title and HTTP-Referer headers used to attribute usage to an application. This metadata is what you see on the Usage page. We do not store the content of your prompts or the model's completions. Request and response bodies pass through the gateway to the upstream provider and are not persisted by us.

Payment data. Purchases are handled by Stripe, our payment processor. Stripe collects and processes the payment credentials you enter at checkout. We do not receive or store full card numbers or card security codes. We retain limited transaction metadata needed to credit your balance, reconcile payments, prevent fraud, and handle refunds or disputes: provider transaction IDs, KoRouter order and account references, status, amounts, currencies, and applicable tax or settlement fields.

How we use it

To run the service: authenticate you, route and meter your requests, bill your balance, prevent abuse and fraud, and diagnose problems. We do not sell your data, and we do not use your prompts or completions to train models.

Third-party processing

To fulfill a request, its content is forwarded to the upstream provider that serves the model you call — such as Anthropic, OpenAI, or Google. Once your data reaches a provider, how it is used and retained is governed by that provider's own data-usage and privacy policies, not by us. Please review them directly:

Payments are processed by Stripe (see above). Payment credentials are submitted to Stripe, and KoRouter receives signed transaction notifications containing the limited data described above. Stripe receives the data needed to provide its part of the service.

Cookies

We use a session cookie to keep you signed in, and Google Analytics and Umami to understand aggregate site usage — Google Analytics sets its own analytics cookies, Umami is cookieless, and neither receives the query string of the pages you visit. We don't use advertising cookies.

Data retention

Account records are kept while your account is open. Per-request usage metadata, including IP addresses and User-Agent strings, is kept with your usage history while your account is open and as needed for billing, reconciliation, abuse prevention, and legal obligations; we may prune older per-request records sooner. Financial ledger entries and limited payment transaction records are retained as accounting records. You can request deletion of your account, subject to any records we must keep for accounting or legal reasons.

Your choices

You can view your keys, usage, and billing history in the console at any time, and reach us to access, correct, or delete your personal data. Depending on where you live, you may have additional rights over your data — contact us and we'll help.

Security

Traffic is served over HTTPS, and API keys are stored hashed. Full card numbers and card security codes are handled by Stripe rather than stored by KoRouter. Signed payment events are reduced to the limited reconciliation fields described above before storage. No system is perfectly secure, but we keep what we hold minimal and guard it accordingly.

Changes

We may update this policy as the service evolves; material changes update the date above. See also our Terms of Service.

Questions about this policy? Write to support@korouter.ai.