Skip to content
Open Vertex Router
PricingBlogAboutDocs
English

Language

  • English
  • FrançaisFrench
  • EspañolSpanish
  • DeutschGerman
  • Português (BR)Portuguese
  • CatalàCatalan
  • Português (PT)Portuguese
  • Bahasa IndonesiaIndonesian
  • KiswahiliSwahili
  • РусскийRussian
Contact salesSign in
Menu
PricingBlogAboutDocsContact sales
EN/FR/ES/DE/PT-BR/CA/PT-PT/ID/SW/RU
Sign in

On this page

  1. Summary of key points
  2. Preamble
  3. 1. Our role: controller and processor
  4. 2. What we collect
  5. 3. Legal bases (EU / UK)
  6. 4. How we use personal data
  7. 5. Sharing and sub-processors
  8. 6. Retention
  9. 7. Security
  10. 8. Your rights
  11. 9. International transfers
  12. 10. Children
  13. 11. Changes to this Policy
  14. 12. Contact Us

Legal

Privacy Policy

Effective date: July 1, 2026

Last updated: August 18, 2026

On this page
  1. Summary of key points
  2. Preamble
  3. 1. Our role: controller and processor
  4. 2. What we collect
  5. 3. Legal bases (EU / UK)
  6. 4. How we use personal data
  7. 5. Sharing and sub-processors
  8. 6. Retention
  9. 7. Security
  10. 8. Your rights
  11. 9. International transfers
  12. 10. Children
  13. 11. Changes to this Policy
  14. 12. Contact Us

Summary of key points

This summary is provided for convenience. It is not part of this Policy and has no legal effect — only the full text below is binding.

We do not store the content of your requests. We record usage metadata only: which model you called, how many tokens, what it cost, how long it took. The text of your prompts and the responses returned to you are not retained by us.

Text only. The Service accepts text input. It does not handle images, audio, video, or biometric data of any kind.

We do not train on anything. We operate no models of our own and use nothing you send us to train, fine-tune, or evaluate any model.

Your requests are executed by the model provider you choose. Once a request leaves our gateway, that provider handles it under its own policies, which differ on retention and training. We tell you which providers we route to so you can choose.

We never sell your data. We share it only with the small set of infrastructure providers listed below, and with the model provider fulfilling your request.

We do not store your card details. Payments are handled by Stripe.

Billing records outlive your account. Tax and accounting law requires it. Everything else is deleted when you close your account.


Preamble

This Privacy Policy explains how Open Vertex Technologies LLC, a Wyoming limited liability company (“we”, “us”, “our”), collects, uses, shares, and protects personal data in connection with Open Vertex Router (the “Service”), our website, dashboard, and API.

It is incorporated into and subject to our Terms of Service. Capitalized terms not defined here have the meaning given there.

The Service is a business-to-business product intended for organizations. It is not directed to consumers or to individuals under 18.


1. Our role: controller and processor

Our role depends on which data is involved.

As a controller. For onboarding request data, account and user data, billing data, usage metadata, and website analytics, we determine the purposes and means of processing and act as the data controller.

As a processor. For the content you transmit through the Service to be routed to a model provider — your prompts, inputs, and the responses returned to you (“Customer Content”) — we act as a processor under the GDPR and a service provider under the CCPA/CPRA, on your behalf. You are the controller of that content and are responsible for having a lawful basis to submit it.

We do not use Customer Content to train, fine-tune, or evaluate any model. We operate no models of our own.

A separate Data Processing Agreement is available to all accounts: on request for Business, and as part of onboarding for Enterprise. Where a signed DPA exists, it governs our processing of Customer Content and prevails over this Policy on that subject. Request one at legal@openvertexrouter.com.


2. What we collect

2.1 Onboarding request data

Before an account exists, we collect information from organizations applying to use the Service, because accounts are opened only after a manual review. This includes: contact name, work email address, telephone number, company name and website, role, country, team size, intended use case, estimated volume, monthly budget, declared data-sensitivity and compliance requirements, and whether EU data residency is required.

This information is reviewed by our staff to decide whether to open an account and on what commercial terms. Retention is set out in Section 6.

2.2 Account and user data

Once an account is opened: the name and email address of each user, authentication credentials (stored hashed), two-factor authentication settings, session data, and the commercial terms agreed for the account.

For API keys, we store a short non-secret preview and an internal reference. We do not store the full key in a form we can read back to you; if you lose a key, you revoke it and create another.

2.3 Usage metadata

For each request routed through the Service we record: the model and provider used, input and output token counts, the provider cost and the amount charged to your account, response time, a unique request identifier, the API key alias used, the account the request belongs to, and the timestamp.

We do not record the content of your prompts or of the responses returned to you.

2.4 Customer Content

The Service accepts text input only. It does not accept images, audio, or video, and we do not process biometric identifiers of any kind.

The content of your request is transmitted to the model provider you selected in order to fulfil it. It passes through our gateway in memory and is not written to storage by us.

2.5 Payment data

Payments are processed by Stripe. We receive and store the invoice records, amounts, dates, and payment status. We do not receive or store card numbers or card details. We do not store any payment method for automatic charging; see our Refund & Cancellation Policy, Section 8.

2.6 Technical and website data

When you use our website or dashboard we collect IP address, browser and device type, pages viewed, and timestamps, in server and application logs. These logs are operational and are retained as set out in Section 6.

2.7 Cookies

We use strictly necessary cookies for authentication, session management, and security. We use no analytics or advertising cookies.

We do not use advertising cookies, behavioural tracking, cross-site tracking, or session replay.

2.8 Correspondence

Records of your correspondence with us, including support requests and abuse reports.

2.9 Newsletter

If you subscribe to our newsletter, we collect the email address you submit and use it only to send occasional product updates. Signups are delivered to our inbox by our transactional email provider and handled as correspondence. You can unsubscribe at any time by replying to any newsletter email or writing to contact@openvertexrouter.com, and we will remove you promptly.


3. Legal bases (EU / UK)

Where the GDPR or UK GDPR applies, we rely on:

  • Performance of a contract — providing the Service, managing your account, invoicing, and support.
  • Legitimate interests — securing the Service, preventing abuse and fraud, reconciling provider costs, and reviewing onboarding requests, balanced against your rights.
  • Legal obligation — retaining accounting records and responding to lawful requests.
  • Consent — non-essential cookies and any optional marketing, withdrawable at any time.

4. How we use personal data

  • To review onboarding requests and decide whether to open an account
  • To provide, secure, and operate the Service
  • To authenticate users and enforce account and key permissions
  • To meter usage, apply your agreed rates, and produce invoices
  • To enforce credit limits and notify you as you approach them
  • To reconcile our provider costs against usage
  • To detect, investigate, and prevent abuse, fraud, and violations of our Acceptable Use Policy
  • To send transactional and service messages, including expiry, invoice, and security notices
  • To comply with legal obligations

We do not sell personal data. We do not share it for cross-context behavioural advertising. We do not use it to train models.


5. Sharing and sub-processors

We share personal data only as follows.

5.1 Model providers

The content of your request is transmitted to the provider fulfilling it. Depending on the model you select, this may be OpenAI, Anthropic, Google, Mistral AI, or DeepSeek.

Each provider processes that content under its own terms, privacy policy, retention period, and training practices, which vary and which we do not control. Review each provider’s policies before selecting a model, and choose one appropriate to the sensitivity of what you are sending.

We route only to providers you are permitted to use under your account’s model allowlist. We do not route to undisclosed or unnamed providers.

5.2 Infrastructure sub-processors

Sub-processor Purpose Location
Hetzner Online GmbH Application and database hosting Ashburn, Virginia, USA
Cloudflare, Inc. DNS, CDN, TLS, WAF, DDoS protection Global
Stripe, Inc. Payment processing and invoicing USA
Zoho Corporation Business email USA
Resend, Inc. Transactional email (contact form and newsletter delivery) USA

Each is bound by contractual data protection obligations. We maintain this list and will update it here when it changes.

5.3 Other disclosures

  • Legal authorities — where required by law, or where necessary to protect our rights, our users, or the public.
  • Business transfer — in connection with a merger, acquisition, or sale of assets, subject to this Policy.

6. Retention

Data Retention
Onboarding requests — approved Retained for the life of the resulting account
Onboarding requests — rejected or abandoned 12 months, then deleted or anonymized
Account and user data While the account is active; deleted on closure, except where Section 6.1 applies
API key records While the key exists; revoked keys retained 12 months for audit
Usage metadata 24 months, then aggregated into non-identifying statistics
Customer Content Not retained
Invoices, payments, credit records 7 years, per tax and accounting law
Operational logs 30 days
Correspondence 24 months after the matter is closed

6.1 Limits on erasure

We will honour erasure requests except where we are legally obliged to retain data. Records of amounts invoiced, paid, and consumed are retained for the statutory accounting period and cannot be deleted on request during that time. During that period we restrict our processing of those records to what the law requires and remove personal identifiers not needed for the accounting record. Once the period ends, the data is deleted or anonymized.


7. Security

We apply technical and organizational measures appropriate to the risk, including:

  • TLS encryption in transit
  • Hashed credentials and scoped API keys, revocable by you at any time
  • Per-account isolation of data, keys, and budgets
  • Role-based access control within your organization
  • No public network exposure of application infrastructure
  • Secrets held in environment configuration, never in source code, with periodic rotation

No system is completely secure. You are responsible for safeguarding your credentials and API keys. Report a suspected compromise to security@openvertexrouter.com without undue delay.

If we become aware of a personal data breach affecting you, we will notify you and the relevant authorities as required by law.


8. Your rights

Depending on where you are, you may have the right to access, correct, delete, export, or restrict the processing of your personal data, to object to processing, and to withdraw consent.

Exercise these rights by writing to legal@openvertexrouter.com. We may need to verify your identity first. We will respond within the period required by applicable law. You will not be treated less favourably for exercising a right.

EU / UK. You may lodge a complaint with your local supervisory authority.

California. You have the right to know, access, delete, and correct your personal information, and to opt out of its sale or sharing. We do not sell or share personal information as those terms are defined under the CCPA/CPRA, and we do not use it for cross-context behavioural advertising. We act as a service provider in respect of Customer Content processed on our customers’ behalf. You may use an authorized agent.

Where we process Customer Content on your behalf and an individual contacts us directly about it, we will refer them to you as the controller and assist you in responding.


9. International transfers

Our infrastructure is located in the United States. Model providers and sub-processors may process data in other countries.

If you are in the EEA or the UK, transferring personal data to us is an international transfer. Where required, we rely on the Standard Contractual Clauses or another lawful transfer mechanism, together with appropriate supplementary measures.

You choose which model provider fulfils each request, and therefore where that request is processed. Provider locations are described in each provider’s own privacy policy.


10. Children

The Service is a business product and is not intended for or directed to anyone under 18. We do not knowingly collect personal data from anyone under 18. If you believe we have, contact us and we will delete it.

You must not submit personal data of children through the Service. See our Acceptable Use Policy, Section 4.


11. Changes to this Policy

We may update this Policy. The current version is always at this URL, with the effective date above. For material changes we will notify account administrators by email at least thirty (30) days in advance. Continued use after the change takes effect constitutes acceptance.


12. Contact Us

Open Vertex Technologies LLC
30 N Gould St Ste N
Sheridan, WY 82801
United States

Data protection and privacy requests: legal@openvertexrouter.com
Security: security@openvertexrouter.com

Open Vertex Router is a service of Open Vertex Technologies LLC, a Wyoming limited liability company.

Product

  • Features
  • Pricing
  • How it works
  • Quickstart
  • Blog
  • Product overview

Get access

  • Contact sales

Developers

  • Documentation
  • Quickstart guide
  • RSS feed

Company

  • About us
  • Contact

Compliance

  • Terms
  • Privacy Policy
  • GDPR
  • Status
All systems operational

© 2026 Open Vertex Technologies LLC. All rights reserved.

  • Terms of Service
  • Privacy Policy
  • Refund & Cancellation Policy
  • Acceptable Use Policy
English

Language

  • English
  • FrançaisFrench
  • EspañolSpanish
  • DeutschGerman
  • Português (BR)Portuguese
  • CatalàCatalan
  • Português (PT)Portuguese
  • Bahasa IndonesiaIndonesian
  • KiswahiliSwahili
  • РусскийRussian