1. Information we collect
- Account information, such as your email address, display name, password hash, locale, and account settings.
- Billing and transaction information, such as order identifiers, amounts, currency, payment status, and limited payment-provider records. We do not store complete payment-card details.
- Service data, such as API-key identifiers, selected models, token and cost totals, request status, timestamps, and rate-limit events.
- Technical data, such as IP address, browser and device information, operating system, referring page, cookies, and security logs.
- Support communications and other information you choose to provide to us.
2. API prompts and model output
We process prompts, files, and model output as needed to route requests, return responses, prevent abuse, investigate errors, and maintain service security. Depending on the selected model, request content is transmitted to the relevant upstream provider and is subject to that provider's data practices.
Do not submit sensitive personal information, confidential data, or regulated data unless you have confirmed that your use and the selected provider meet your legal and security requirements.
3. How we use information
- Provide, authenticate, meter, bill, maintain, and improve the service.
- Process purchases, subscriptions, refunds, and account requests.
- Detect fraud, abuse, outages, and security incidents and enforce our Terms.
- Respond to support inquiries and send transactional or important service notices.
- Comply with legal obligations and protect our rights and the rights of others.
4. Legal bases
Where applicable law requires a legal basis, we process information to perform our contract with you, comply with law, pursue legitimate interests such as security and service improvement, and, where required, based on your consent. You may withdraw consent at any time without affecting earlier processing.
5. How we share information
We share information only as reasonably necessary with model providers, payment processors, hosting and infrastructure vendors, security and support vendors, professional advisers, and authorities when legally required. We may also transfer information as part of a merger, financing, acquisition, or sale of assets, subject to appropriate protections.
We do not sell personal information or share it for cross-context behavioral advertising.
6. Retention
We retain account, transaction, usage, and security records for as long as reasonably needed to provide the service, meet accounting or legal obligations, resolve disputes, and prevent abuse. Retention periods vary by data type and legal requirement. We delete or de-identify information when it is no longer needed, unless law requires longer retention.
7. Security
We use administrative, technical, and organizational safeguards designed to protect information, including access controls, credential hashing, transport encryption, monitoring, and restricted production access. No internet service can guarantee absolute security, so you should also protect your password and API keys.
8. International processing
Hyperouters and its providers may process information in countries other than your own. Where required, we use contractual or other recognized safeguards for international transfers. Laws in those countries may differ from the laws where you live.
9. Your choices and rights
- Review or update available account information in the console.
- Request access, correction, deletion, restriction, objection, or portability where applicable law provides those rights.
- Disable non-essential cookies through browser controls, understanding that essential cookies are required for sign-in and security.
- Contact us to appeal a privacy decision or ask a question about our data practices.
10. Children
The service is not directed to children under 13, and we do not knowingly collect their personal information. If local law requires a higher minimum age to consent to online services, that higher age applies. Contact us if you believe a child provided information without appropriate authorization.