Privacy Policy
Effective August 15, 2026
Policy overview
Our underlying policy is that we want you to remain anonymous when using our service. We never store your prompts or model responses, and we keep as little data as possible. In some situations we process limited personal data, for example when you pay by card or send an email to support. This policy describes those cases.
What we never store
- Prompts, messages, model responses, and generated media
- Request and response bodies exchanged with model providers
- Activity logs of what you ask or which conversations you have
- Raw IP addresses in our application or access logs
- Full API keys, passwords, or recovery phrases
Request content is processed in memory only for the request that needs it and is gone when the request completes.
We use network information such as your IP address transiently to route requests, apply rate limits, and prevent abuse. On public informational pages, our self-hosted analytics service also uses the IP address and browser user agent transiently to derive a pseudonymous identifier that changes every day. We do not write raw IP addresses or full user agents to our application, access, or analytics logs.
Categories of personal data
Accounts
An anonymous account consists of a server-assigned username and hashed credentials. No email address or personal details are required or collected. A registered account additionally stores your email address and hashed password or OAuth identity.
Payments
- Card (handled by our payment provider): charge ID, last four digits of the card, card type, amount, and status
- Bitcoin and Lightning: the invoice and transaction data needed to confirm the payment. Note that the Bitcoin blockchain is public.
Usage metadata
To settle your prepaid balance we record the model, token counts, cost, status, and timestamp of each request, linked to an opaque account identifier. This contains no request content.
Public website analytics
We collect limited first-party analytics on public informational pages: a generalized page path, timestamp, external referring domain, browser, operating system, broad device type, country, and clicks on sign-up, API-key, Chat, and documentation calls to action. Those clicks carry no link or form properties. Model and provider detail paths are grouped rather than stored by name. We do not collect URL queries, search text, account identifiers, chat or Studio activity, payment activity, session recordings, heatmaps, or persistent visitor identifiers. No analytics event is sent from authentication, account, Chat, Studio, recovery, payment, or receipt pages.
Support
Support by email: your email address and other information you have written in the email. Please do not include prompts, API keys, or recovery phrases when contacting support.
How long is the personal data saved?
Account and usage records are kept while your account is active. Payment data is kept as long as needed to handle refunds, disputes, and the statutory accounting retention periods that apply to us, after which it is deleted. Support emails are deleted once they are no longer needed to resolve the request. Detailed public website analytics is deleted after 90 days and is not included in our application database backups.
Cookies and your device
We use first-party session cookies for account sessions. Our self-hosted public-page analytics writes no analytics data to cookies or local storage and uses no advertising identifiers, cross-site tracking, or third-party analytics service. Browser Do Not Track and Global Privacy Control signals disable it. Chat and Studio can keep history in your own browser for convenience; Ghost Mode disables this, and clearing site data removes it.
Security
We apply reasonable technical and organizational measures designed to protect the limited personal data we hold, including encryption in transit, hashed credentials, and access controls. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
Third-party recipients
Personal data is shared only with suppliers performing services on our behalf: payment providers and, for request content, the provider of the model you select. Requests we forward are not tied to your account identity, and each model in the catalog shows a privacy label describing what its route guarantees.
Each provider processes the request content we forward under its own terms and privacy commitments, which we review before routing to it. On an Anonymous route the provider can see the prompt while serving it and its retention is not guaranteed; Private, TEE, and E2EE routes carry the stronger provider or cryptographic guarantee described on the route.
We do not sell your personal data, we do not share it for cross-context behavioral advertising, and we do not use it to build advertising profiles.
The rights of individuals
You may request access to, correction of, or deletion of personal data regarding you by contacting us at the address below. In most cases we will not be able to provide you with any data, since we do not store data that identifies you; an anonymous account was never connected to a person, and we cannot produce records that do not exist. We may need to verify that you control the account before acting on a request.
Children
The service is intended for adults. It is not directed to children, and we do not knowingly collect personal data from anyone under 18. If we learn that we have collected such data, we delete it. If you believe a minor has provided us personal data, contact us at the address below.
Contact information
AnonRouter is operated by Sunday Labs LLC, 30 N Gould St #56887, Sheridan, Wyoming 82801, United States.
To exercise your rights or ask a question about this policy, contact contact@anonrouter.ai.
Updates
This Privacy Policy may be updated and, in such case, a new version will be published on this website. See also the Terms of Service.