Legal
Privacy Policy
Last updated: September 24, 2026
This policy explains how Virouter processes information when you use virouter.com and the Virouter API gateway (the “Service”).
Information we collect
Account information: email address, account identifiers, authentication information (including a password hash where password sign-in is used), and profile details provided by an identity provider when you choose social sign-in.
API usage and security information: request metadata such as account and API-key identifiers, model and provider, token and generation usage, timestamps, status, latency, request size, and billing results. We may process IP address and user-agent information for security, abuse prevention, and incident investigation.
Content sent through the service: API request content is forwarded to the selected upstream model provider to fulfil the request. Standard gateway usage records are designed to retain usage and billing metadata rather than prompt and response bodies. Separate product features, including asynchronous generation and user-created assistant or playground features, may store inputs or outputs needed to provide that feature. Do not send sensitive personal information unless you have a lawful basis and have assessed the relevant provider's terms.
Payment information: payments are handled by the payment method or provider presented at checkout. Virouter records transaction and package details and payment-provider identifiers/status needed to reconcile payments and credit quota. Virouter does not receive or store full payment-card numbers through its application checkout records.
Support communications: if you contact support, we process information and attachments you provide to respond and resolve your request. Do not include passwords, full API keys, or payment-card details.
How we use information
We use information to provide and maintain Virouter, authenticate accounts, route API requests, calculate and display usage, credit and reconcile payments, provide support, enforce rate limits and acceptable-use rules, prevent fraud and abuse, secure the service, troubleshoot errors, and meet applicable legal obligations. We do not sell personal information.
Data retention
We retain account, usage, support, and transaction records for as long as reasonably needed to provide the service, maintain billing records, prevent abuse, resolve disputes, and meet legal obligations. Retention periods vary by data type and feature; we do not promise a single fixed deletion period for all records. You may request account deletion, but some transaction, security, or dispute records may need to be retained where required or permitted by law.
Security
We use access controls and technical and organizational measures intended to protect information. Internet transmission and storage cannot be guaranteed to be completely secure. You are responsible for safeguarding your credentials and API keys and should rotate a key promptly if it may have been exposed.
Your choices and requests
Depending on applicable law, you may request access to, correction of, or deletion of personal information, or object to or restrict certain processing. Email [email protected] from your account email where possible. We may need to verify your identity and may retain information where legally required or permitted.
Children
Virouter is not intended for children below the minimum age permitted to use online services under laws applicable to them. We do not knowingly seek to collect children's personal information. Contact us if you believe a child has provided personal information.
Changes to this policy
We may update this policy as the service or legal requirements change. We will update the date below when a revision is published and provide additional notice of material changes where required.
Contact
Privacy requests: [email protected]. Customer and billing support: [email protected]. Security reports: [email protected].