Privacy Policy
Effective September 24, 2026
Policy overview
Our underlying policy is that we want you to remain anonymous when using our service. We never store your prompts or model responses, and we keep as little data as possible. In some situations we process limited personal data, for example when you pay by card or send an email to support. This policy describes those cases.
What we never store
- Prompts, messages, model responses, and generated media
- Request and response bodies exchanged with model providers
- Activity logs of what you ask or which conversations you have
- Raw IP addresses in our application or access logs
- Full API keys, passwords, or recovery phrases
Request content is processed in memory only for the request that needs it and is gone when the request completes.
We use network information such as your IP address transiently to route requests, apply rate limits, and prevent abuse. On the public pages listed below, our self-hosted analytics service also uses the IP address and browser user agent transiently to derive a pseudonymous identifier that changes every day. We do not write raw IP addresses or full user agents to our application, access, or analytics logs.
Categories of personal data
Accounts
An anonymous account consists of a server-assigned username and hashed credentials. No email address or personal details are required or collected. A registered account additionally stores your email address and hashed password or OAuth identity. Either kind of account can also have a temporary campaign snapshot, described under Campaign attribution below.
Payments
- Card (handled by our payment provider): charge ID, last four digits of the card, card type, amount, and status
- Bitcoin and Lightning: the invoice and transaction data needed to confirm the payment. Note that the Bitcoin blockchain is public.
Usage metadata
To settle your prepaid balance we record the model, token counts, cost, status, and timestamp of each request, linked to an opaque account identifier. This contains no request content.
Public website analytics
We collect limited first-party analytics on our public pages: the page path, timestamp, external referring domain, browser, operating system, broad device type, country, and clicks on sign-up, API-key, Chat, and documentation calls to action. Those clicks carry no link or form properties. Model, creator, and provider detail pages are recorded under their own catalog path, because which models people read about is what this measurement is for. Those paths are public catalog names, and a path that is not one is not recorded at all.
The Chat page records only that it was opened. No prompt, message, model response, attachment, conversation, or conversation identifier is ever sent to analytics, and your chats are not analytics data. Page analytics does not collect URL queries, search text, account identifiers, Studio activity, payment activity, session recordings, heatmaps, or persistent visitor identifiers. No page analytics event is sent from authentication, account, Studio, recovery, payment, or receipt pages.
Campaign attribution
When campaign attribution is enabled and you open certain public pages from a link we tagged, the site reads four campaign fields from that link (source, medium, campaign, and content) and removes campaign and ad-click parameters from the address bar. It sends only those four fields to our account service, which checks them against the campaigns we have registered. If they match one, it sets one signed cookie limited to its own address (control.anonrouter.ai) and counts the visit as a landing for that campaign. The cookie holds the first and most recent campaign you arrived from, the dates of those visits, and nothing unique to you. It expires 30 days after your first tagged visit by default, never more than 90, and later visits do not extend it. Signing in or creating an account clears it.
If you create an account while that cookie is valid, we keep a temporary campaign snapshot linked to the new account. It holds the first and most recent campaign, the day you signed up, the day the snapshot expires, and whether the account has reached three milestones: first API key, first successful request, and first payment. This snapshot is the only place we keep campaign data next to an account identifier.
We also record the sign-up and each milestone as a separate campaign event, and keep landings as one count per campaign and day, which stops growing at a fixed daily limit. A campaign event or landing count holds only the campaign, the day, and for a first payment a broad amount band, never the exact amount. It contains no account, payment, API key, or request identifier, no IP address or browser details, no page address or referring page, and no time of day. Campaign events are released only in batches of at least three that share the same event and exactly the same campaign, from complete UTC days. A group that stays smaller than that for a while has its campaign name replaced with "other" and waits again, and events that never reach a batch are deleted. Released batches are added to weekly counts per campaign, which never hold a count below three, and are copied to a separate internal site in our self-hosted analytics database, apart from public page analytics. Our reports hide any count below five.
Attribution never records prompts, responses, API keys, payment identifiers, ad-click identifiers, search terms, or exact payment amounts, and we do not share campaign data with advertising platforms. If your browser sends Do Not Track or Global Privacy Control when you visit or sign up, no campaign information is recorded for that visit or sign-up, and signing up with either signal on clears any campaign cookie you already have. A snapshot created before you turned either signal on can still record milestones until it is deleted.
Support
Support by email: your email address and other information you have written in the email. Please do not include prompts, API keys, or recovery phrases when contacting support.
How long is the personal data saved?
Account and usage records are kept while your account is active. Payment data is kept as long as needed to handle refunds, disputes, and the statutory accounting retention periods that apply to us, after which it is deleted. Support emails are deleted once they are no longer needed to resolve the request. Public website analytics events are deleted after 90 days. A campaign snapshot is deleted when its milestones have been recorded, when its window ends (30 days after sign-up by default, never more than 90), or when the account is disabled or closed, whichever comes first. Individual campaign events are deleted from our application database within weeks, whether or not they were released, and weekly campaign counts are kept for at most 400 days, a year plus the same week a year earlier. Snapshots, campaign events, and weekly counts are kept in our application database, so copies can remain in database backups until those backups expire. Campaign events copied to our analytics database are deleted there after 90 days, and the delivery receipts kept there so that no event is counted twice, which hold no campaign details, are deleted after 30 days. Our analytics database is not included in our application database backups.
Cookies and your device
We use first-party session cookies for account sessions and, when campaign attribution is enabled, the single campaign cookie described above. Our self-hosted page analytics sets no cookie, writes nothing to local storage, and uses no advertising identifiers, cross-site tracking, or third-party analytics service. Browser Do Not Track and Global Privacy Control signals disable page analytics, and they stop campaign attribution when you visit or sign up, as described above. Chat and Studio can keep history in your own browser for convenience; Ghost Mode disables this, and clearing site data removes it.
Security
We apply reasonable technical and organizational measures designed to protect the limited personal data we hold, including encryption in transit, hashed credentials, and access controls. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
Third-party recipients
Personal data is shared only with suppliers performing services on our behalf: payment providers and, for request content, the provider of the model you select. Requests we forward are not tied to your account identity, and each model in the catalog shows a privacy label describing what its route guarantees.
Each provider processes the request content we forward under its own terms and privacy commitments, which we review before routing to it. On an Anonymous route the provider can see the prompt while serving it and its retention is not guaranteed; Private, TEE, and E2EE routes carry the stronger provider or cryptographic guarantee described on the route.
We do not sell your personal data, we do not share it for cross-context behavioral advertising, and we do not use it to build advertising profiles.
The rights of individuals
You may request access to, correction of, or deletion of personal data regarding you by contacting us at the address below. In most cases we will not be able to provide you with any data, since we do not store data that identifies you; an anonymous account was never connected to a person, and we cannot produce records that do not exist. We may need to verify that you control the account before acting on a request.
Children
The service is intended for adults. It is not directed to children, and we do not knowingly collect personal data from anyone under 18. If we learn that we have collected such data, we delete it. If you believe a minor has provided us personal data, contact us at the address below.
Contact information
AnonRouter is operated by Sunday Labs LLC, 30 N Gould St #56887, Sheridan, Wyoming 82801, United States.
To exercise your rights or ask a question about this policy, contact contact@anonrouter.ai.
Updates
This Privacy Policy may be updated and, in such case, a new version will be published on this website. See also the Terms of Service.