Legal / Privacy

Policy

Privacy policy

We do not store full prompt or completion bodies in the product database. Accepted requests do produce the short, automatically redacted operations summary disclosed below. We do not retain full bodies, sample them for quality, or use them for training. What follows is the complete list of what we do keep.

Prototype notice. The commitments are real; counsel may tighten the wording before launch.

Everything we store, exactly

Every category of data minirouter stores, what it contains, and the reason it exists.
We keepWhich isBecause
Operations message summariesUp to 200 characters from the latest user turn of an accepted request, after automatic removal of likely credentials, links, email addresses, code blocks and wallet-like values; sent without account, key, model, billing or response fields to our private Slack workspaceA small operations activity feed. Automatic redaction reduces exposure but cannot guarantee that every sensitive detail in free text is removed
Aggregate page analyticsPage, referrer, country, browser, operating system and device class processed by Vercel Web Analytics; no account, wallet, key, prompt or completion fieldsUnderstanding aggregate site traffic. Vercel documents this as cookie-free and uses a site-specific visitor hash that expires after 24 hours
Product analytics (optional)A random HMAC pseudonym, public page, bounded campaign codes, referrer hostname, funnel events, and an immutable local acquisition link to the account created from that visitMeasuring whether an offer leads to a key, credit, and successful request; collected only after consent
Usage recordsToken counts (in / out / cached), model id, serving upstream, timestamps, latency, costBilling and the per-request receipts we show you
Ledger entriesEvery credit and debit, double-entryYour balance is a sum over this ledger; you can export it as CSV
Deposit transactionsChain, transaction hash, amount, sending and receiving addressesCrediting your deposit and answering “I sent it but don’t see it”
API keysA hash of the key and its prefix — never the key itselfAuthentication; the plaintext key is shown once and not kept
Email (optional)Only if you chose to give oneBalance alerts at 20% and 5% of a 7-day burn; nothing else
Screening resultsPass/fail of sanctions-list checks on direct depositsThe legal floor for operating the direct rail; see /pay/no-kyc

That table is exhaustive. If a category is not in it, we do not hold it — there is no name, no phone number, no ID document, no device fingerprint, and no stored full conversation body beyond the bounded operations summary disclosed above.

Third parties

Public pages send page-view data to Vercel Web Analytics. Vercel documents this as cookie-free, first-party analytics that cannot track a visitor across different sites. We do not attach an account identifier, wallet, email, key, prompt, completion, or billing record to those events.

Separately, if you consent, public pages send a small allowlisted product event to our own domain. Those events carry no Mixpanel browser SDK, ad pixel, session recorder, or fingerprinting script . We keep the pseudonymous source record in MiniRouter’s database and, when remote reporting is enabled, project it server-to-server to an EU-resident Mixpanel project. We do not send an IP address, full user agent, raw referrer URL, account identifier, wallet, email, key, prompt, or completion.

When a consented visit creates its first account and API key, we store an immutable account-to-visitor acquisition link in MiniRouter’s own database for the retention window. It is used to derive key, payment, and successful-request funnel events. The local account ID and that linkage are never exported to Mixpanel.

For an accepted inference request, our edge sends the short operations message summary described above to a private Slack channel. Slack processes and retains that notification under our workspace settings. Redaction is deliberately aggressive, but free text is open-ended: do not put credentials or other secrets in a prompt and assume any automatic filter is perfect.

Your requests necessarily reach the upstream provider that serves the model; the provider sees the prompt content, under its own policy. On the aggregator payment rail, Relay screens transactions against Chainalysis — that is their infrastructure, stated precisely on /pay/no-kyc. We do not sell or rent stored data, and do not disclose it beyond the processors and payment infrastructure named above.

Retention, requests and changes

Usage and ledger records are kept for as long as the balance they account for exists, because they are the balance. Deposit transaction records are kept as long as the law governing payments requires. There is deliberately little else to retain or delete — for accountless keys, we could not link stored data to a person even if asked to. The The Privacy choices control lets you stop optional MiniRouter product analytics or delete its local pseudonymous record and request deletion from the reporting projection. Mixpanel processes that request asynchronously and says it may take up to 30 days; we retain the pseudonymous completion evidence for 13 months, while pending or failed deletion work is never aged away. Other product analytics records expire after 13 months. The control does not disable aggregate Vercel page views. This does not delete financial or usage records kept for billing and payment obligations. Operations summaries follow the Slack workspace retention settings and are not controlled by the analytics preference.

Questions or requests: privacy@minirouter.sh. Material changes to this policy are dated in the changelog.