YOUR DATA AND YOUR WORKSPACE

Privacy policy

Last updated:

This policy explains how ZRouter handles information when you visit our website, use your account, or send requests through the gateway.

Privacy at a glance

ZRouter processes account and usage information to run your workspace. AI requests are sent to the providers selected by your routing settings. Request logs can include prompts and responses when body logging is enabled. Stripe processes checkout payments, and Google or GitHub can provide sign-in when available.

1. Who this policy covers

ZRouter is developed and maintained by NEXUS AI. This policy covers the ZRouter website, dashboard, gateway API, zctl CLI, and account MCP service operated by our team.

If you use a separately operated or self-hosted ZRouter deployment, its operator controls that deployment's data practices. Contact that operator about its configuration, retention, and privacy obligations. External websites and services have their own privacy policies.

2. Information we process

  • Account and sign-in information: email address, account identifiers, password hashes for email sign-in, sessions, and linked Google or GitHub identity identifiers and verified email addresses. The sign-in provider handles your provider password.
  • Workspace settings and credentials: API key names and identifiers, token hashes, virtual model definitions, provider connections, encrypted BYOK credentials, and configured budgets and limits.
  • AI requests and activity: submitted prompts, messages, files or other inputs supported by the endpoint, generated responses, selected models and providers, timestamps, token counts, latency, errors, and request identifiers. Enabled logging can store request and response content, including revisions made during routing.
  • Billing records: credit purchases, balances, reservations, ledger entries, payment status, and Stripe transaction identifiers. Card details are entered through Stripe Checkout rather than stored in the ZRouter account database.
  • Technical and support information: connection and diagnostic information, which can include IP addresses, browser or client details, service logs, and information you send when contacting us.

3. How we use information

We use information to create and authenticate accounts, route requests, return model responses, manage provider connections, calculate usage and charges, enforce budgets and rate limits, and provide account tools. We also use relevant information to send account and billing notices, answer support requests, investigate errors or abuse, protect the service, and meet applicable legal and accounting obligations.

Where data protection law requires a legal basis, these activities rely on providing the service you request, legitimate interests such as service security and support, legal obligations, or consent where required. The applicable basis depends on the activity and your location.

4. AI providers and request content

ZRouter forwards request content and the parameters needed to fulfill it to the selected AI provider. Virtual model routing, failover, and request processing can involve more than one configured provider. BYOK requests use your saved provider credential to authenticate the connection to that provider.

AI providers apply their own retention, security, and model improvement policies. Those practices can vary by provider, model, account type, and your provider settings. Using ZRouter does not override a provider's terms or guarantee that a provider never retains data or uses it for training.

Review the relevant provider's policy before sending personal, confidential, or regulated information. Submit only information you are authorized to share. See the BYOK guide and virtual model guide for connection and routing behavior.

5. Services and information sharing

Information is shared as needed to deliver the functions you use:

  • AI providers: receive routed request content and necessary connection information.
  • Stripe: receives checkout information, including your account email, purchase amount, and order references, and returns payment status and transaction references.
  • Google and GitHub: handle their sign-in flow when you choose that option. ZRouter receives the identity information needed to link or create your account.
  • Infrastructure and communications services: process information necessary to host the service, store records, deliver account emails, and support operations.
  • Clients you connect: zctl and MCP clients receive the account information returned by the operations you authorize. An AI assistant or its service may process tool results under its own policies.

We may disclose relevant information when required by law or when necessary to investigate abuse, enforce service terms, or protect users and the service. A business transfer may involve service records, subject to applicable privacy obligations.

6. Cookies and browser storage

ZRouter uses browser session storage for account session tokens and temporary workspace state. Google and GitHub sign-in use short-lived cookies to validate the authorization flow. These mechanisms support sign-in and account security.

You can clear browser storage or control cookies through your browser settings. Blocking necessary storage can prevent sign-in or interrupt account features. External sign-in and checkout services may use their own cookies. The marketing page templates do not include third-party advertising trackers.

7. Security and retention

ZRouter hashes account passwords and authentication tokens, encrypts saved BYOK credentials at rest, and scopes account access to the authenticated user. We use these controls to reduce unauthorized access. No storage or transmission method is completely secure.

Retention depends on the record type and deployment settings. The default configuration keeps request logs for 30 days and usage records for 90 days; operators can change these settings, including keeping records without automatic expiry. Account and billing records have separate retention needs and are not removed by those log settings.

Records may be retained as needed to operate your account, resolve disputes, investigate security issues, and satisfy legal or accounting obligations. Deleting a saved provider key does not revoke that key at the provider or delete information already processed by a provider. Contact us about deletion requests or the retention settings for the service you use.

8. Your choices and privacy rights

You can revoke account API keys and management tokens, remove saved provider credentials, and manage your virtual routers through available account tools. Only connect CLI and MCP clients you trust, and revoke their access when it is no longer needed.

Depending on your location and applicable law, you may have rights to access, correct, delete, or receive a copy of personal information, restrict or object to certain processing, or withdraw consent where processing relies on it. You may also have the right to complain to a data protection authority.

To request help with these rights or close your account, contact the NEXUS AI team and identify your request as a ZRouter privacy request. We may need to verify account ownership and may retain information where applicable law permits or requires it. Do not include passwords, API keys, card details, or sensitive request content in your message.

9. Children and international use

ZRouter is intended for developers and account owners, and is not directed to children under 13. Contact us if you believe a child has provided personal information so we can investigate and address it.

Service infrastructure and third-party providers may process information in countries other than your own. Available protections and legal requirements can differ by location. Where required, applicable safeguards must be used for international transfers.

10. Policy changes and contact

We may update this policy as the service or its data practices change. The date above identifies the latest revision. Where required, we will provide notice of material changes through the service or account communications.

For privacy questions, account deletion, or information about service providers and retention, use the NEXUS AI contact page. Include your account email and the subject of your request so the team can route it appropriately.