Privacy Policy
Last updated: September 2026
RouterBus is a service of VellyGood Network LLC, operated from the State of Wyoming, United States. This policy says what we collect, why, who else sees it, and how long we keep it. It is part of the Terms of Service.
1. The part most people are asking about
We do not store the content of your requests or the model's responses. What we record for a request is metadata: the model, token counts, what it cost, how long it took, the request id, and which of your API keys made it. Not the prompt, not the completion.
Your prompt is, necessarily, transmitted to the upstream model provider — that is the service you are buying. What they retain is governed by their policy, not ours (§4).
We do not use your requests, responses or usage patterns to train any model, and we do not sell personal information or share it for cross-context behavioural advertising.
2. What we collect
Account. Email address, username, display name, a password stored only as a hash (bcrypt or Argon2id — we never hold the password itself), the time the account was created and the time it was last used. Registration requires a verification code sent to the email address, so the address has to be one you control.
Authentication and security. For each login session: the IP address and user agent our servers see, when it started, when it was last active, and how you signed in. Also two-factor enrolment state (never the codes), and an audit record of sensitive account actions — a password change, a 2FA change, an account closure. These exist so that you can review your own sessions and so that we can investigate a compromise.
Usage. Per request: timestamp, model, input/output/cached token counts, the charge, latency, whether it was streamed, the request id, the API key and the user group. No request or response body, and no client IP on these records.
Payments. Top-up amount, currency, time, status, and the on-chain transaction identifier of a crypto payment. We never see a card number or a private key.
Support. Whatever you write to us, for as long as needed to deal with it and to keep a record of what was agreed.
Cookies and local storage. Only what the product needs; there is no advertising or analytics cookie:
| name | purpose | lifetime |
|---|---|---|
| refresh cookie | keeps you signed in; HttpOnly, SameSite=Strict, scoped to /api/user/auth | 30 days |
new_api_has_session | a flag saying a session exists — carries no credential, readable by the page so it can skip a pointless request | 30 days |
vite-ui-theme | your light/dark choice | 1 year |
sidebar_state | whether the sidebar is collapsed | 7 days |
i18nextLng (local storage) | your interface language | until cleared |
Cloudflare sets its own cookie when it runs the anti-bot check on the sign-in page; see §4.
3. Why we hold it
- To run the service and bill it correctly — the account and usage records.
- To keep accounts safe and investigate abuse — the authentication and audit records.
- To meet accounting and tax obligations — the payment records.
- To answer you — support correspondence.
If you are in the EEA or the UK: the legal bases are performance of a contract (running and billing the service), our legitimate interests (security, fraud prevention, keeping the service working), and legal obligation (accounting). Data is processed in the United States and by the subprocessors in §4.
4. Who else sees it
We keep the list short, and every entry is a service the product could not run without.
- The upstream model provider. Your prompt and the parameters of the request are sent there to be served, along with the model name. This is the core of the service.
- Cloudflare — sits in front of the site as CDN and WAF, and runs the anti-bot challenge on the sign-in page. It therefore sees the IP address and the request metadata of anything you send us.
- A cryptocurrency payment processor — receives the payment and tells us it arrived. It sees the on-chain transaction, not your account.
- An email provider — delivers verification and notification messages, and so sees your address.
We do not share personal information with anyone else, except where the law requires it, and we will tell you about such a request unless we are forbidden from doing so.
5. How long we keep it
- While your account is open, we keep the account, usage and payment records.
- After you close it, the account record is marked closed and retained rather than erased immediately, and payment and usage records are kept for as long as accounting and tax rules require. Closing does end access at once and invalidates every session.
- Usage records are kept until we delete them. We will say so plainly: there is no fixed automatic deletion schedule today. If we adopt one, it will be published here.
6. What you can do
- See it. Your usage log, top-up history and active login sessions are all in the console. You do not need to ask us for them.
- Correct it. Email, display name and password are editable in the console.
- Close the account. Security & Access → close. Access ends immediately and every session is invalidated.
- Ask for erasure. Write to us. We will delete what we are not required to keep and tell you what we kept and why — a billing record we must retain for accounting is the usual exception.
- Ask for a copy. Write to us and we will export what is on your account.
- Depending on where you live you may have further rights — to object, to restrict processing, to complain to a supervisory authority. Using them costs nothing and we will not degrade your service for it.
7. How it is protected
- Passwords are hashed, never stored or logged in the clear; we cannot tell you your password because we do not have it.
- Optional two-factor authentication (TOTP, with single-use backup codes).
- Session tokens are short-lived and held in memory; the long-lived credential is an
HttpOnlycookie that rotates on use, so a stolen copy stops working. - API keys are scoped — you can limit a key to particular models and give it its own quota — and can be revoked immediately.
- Traffic to the site and to the upstream provider runs over TLS.
No system is perfect. If we discover a breach affecting your data, we will tell affected account holders and say what happened, what we know, and what to do.
8. Children
The service is not for anyone under 18. We do not knowingly collect data from children; if we learn we have, we will delete it.
9. Changes
We may revise this policy. A material change is announced in the console, by email, or both, before it takes effect, and the date at the top changes. The version in force is the one published here.
10. Contact
Privacy requests, including access, erasure and complaints: [email protected].
The data controller is VellyGood Network LLC, State of Wyoming, United States.