Legal
Privacy Policy
Last updated September 9, 2026
1. Who we are
PennyRouter (“PennyRouter,” “we,” “us,” or “our”) operates pennyrouter.com and the associated API gateway (collectively, the “Service”). This Privacy Policy describes the information we collect from users of the Service, the purposes for which we process it, and the rights and choices available to you.
2. Information we collect
- Account information. The email address and credentials used to authenticate to the Service, together with the basic profile details you provide or that are supplied by an OAuth provider (such as Google or GitHub) where you elect to use one.
- Upstream API credentials. Where you elect to connect your own provider credentials (for example, an Anthropic or OpenAI API key), those credentials are stored in encrypted form so that the gateway may use them on your behalf. Such credentials are used solely to route your requests and for no other purpose.
- Aggregate usage statistics. Per-request metadata, including token counts, cache hit and miss status, model selection, latency, and computed cost. This metadata supports the reporting presented in your dashboard, including savings calculations. It does not include the text of your prompts or of the model’s responses.
- Payment information. Subscription and pay-as-you-go payments are processed by Stripe. We neither receive nor store your payment card number; such information is handled by Stripe in accordance with its own privacy policy.
3. Information we do not retain
We do not log, store, or otherwise retain the content of your requests or of the model’s responses. Request content transits the gateway solely for the purpose of routing it to the applicable provider and returning the response to you; it is not written to a database and is not retained following completion of the request processing and cost calculation. We do not sell your personal data, and we do not use your prompts or completions to train any model.
4. Cookies
We use a strictly necessary cookie to maintain your authenticated session and to authorize your requests to the dashboard. We do not use cookies for advertising or for cross-site tracking.
5. How we use information
We process the information described above in order to:
- Operate the routing, caching, and billing functions that constitute the Service
- Present accurate usage and savings reporting in your dashboard
- Communicate with you regarding your account, billing, or changes material to security
- Improve routing and caching behavior on the basis of aggregate, non-identifying statistics
6. Disclosure to third parties
We disclose information only to the service providers necessary to operate PennyRouter (including Stripe for payment processing, our hosting and database providers, and the AI providers to which you direct your requests), where required by applicable law or legal process, or in connection with a merger, acquisition, or sale of all or substantially all of the business. We do not sell personal data to third parties.
7. Security
We maintain reasonable technical and organizational measures designed to protect your information, including encryption of stored upstream credentials. No method of transmission or storage is entirely secure, however, and we cannot guarantee absolute security.
8. Your rights and choices
You may review or update your account information, disconnect upstream API credentials, or delete your account at any time through your dashboard or by contacting us by email. Certain information may be retained following account deletion where we have a legal obligation or legitimate business reason to do so, including for the maintenance of billing records.
9. Children
The Service is not directed to children under the age of 13, and we do not knowingly collect personal information from them.
10. Changes to this policy
We may amend this Privacy Policy from time to time. In the event of a material change, we will post the revised policy on this page and update the “last updated” date above. Your continued use of the Service following such posting constitutes acceptance of the amended policy.
11. Governing law
This Privacy Policy is governed by the laws of the State of Georgia, without regard to its conflict of law principles.
12. Contact
Inquiries regarding this Privacy Policy or the handling of your data may be directed to [email protected].