Skip to content
AppAIGateway
SecurityProvidersPricingFAQ
DocsLogin

Legal

Privacy Policy

What the hosted service stores, what it deliberately does not store, and how long it keeps it.

Last updated 12 September 2026

1. Scope

This policy covers the hosted service at console.appaigateway.com and this website. It does not cover a gateway you host yourself: that deployment runs in your own Cloudflare account, and none of its data reaches us.

App AI Gateway is the controller for the data described below. Contact: support@appaigateway.com.

2. What we hold

Account and organisation

Your name and email address, plus either a password hash or, if you sign in with Google, the identifier Google returns. Your organisation’s name and its members’ roles. Console sessions also record the IP address and browser user agent they were created from, so a session can be recognised and revoked.

Configuration

The applications you register, their authentication policy and limits, and the model-provider credentials you add. Credentials are encrypted before they are stored, under a key held in a separate key-management service, and are never shown again in the console or returned by the API.

Usage records

One record per proxied request: the time, the application, the opaque end-user identifier your app supplied, the model, route, provider and gateway used, token counts, computed cost, latency, outcome, and the app version. This is what the console’s usage, cost, and limit views are built from.

Authentication records

One record per sign-in or attestation attempt from your app: the outcome and its cause, the app version, the latency, and the opaque user identifier where one was established. These are diagnostics and are deleted automatically after 90 days.

Billing

Your plan, subscription status, and the Lemon Squeezy customer and subscription identifiers. Card details are handled entirely by Lemon Squeezy; we never receive or store them.

3. What we do not hold

  • No prompts or completions. Request bodies are forwarded to your provider and responses are streamed straight back. A response is read in passing only to count tokens, and nothing from either body is written down.
  • No end-user identities. We do not record your users’ names, email addresses, or IP addresses. The only user identifier we store is the opaque value your application supplies.
  • No selling, no training. We do not sell data and we do not use your traffic to train models.

4. Your end users

Where your application sends an end-user identifier, we process it on your behalf, as a processor acting on your instructions, in order to attribute usage, enforce limits, and render your console. You decide why that identifier exists, you are responsible for having a lawful basis, and you are responsible for telling your users.

5. Why we process it

  • To perform our contract with you — running your account, storing your configuration, proxying requests, metering usage, and billing.
  • Legitimate interests — security, abuse and fraud prevention, diagnosing failures, keeping the service reliable, and measuring how the website and console are used so we can improve them.
  • Legal obligation — keeping tax and accounting records for payments.

6. Who else processes it

  • Cloudflare — hosting, compute, database, and operational logs (privacy policy).
  • Lemon Squeezy — payment processing and merchant of record for subscriptions (privacy policy).
  • Google — only if you choose Google sign-in, in which case we receive your name, email address, and Google account identifier.
  • PostHog — website and console analytics, using its United States hosting region (privacy policy).

Your model providers receive the content of the requests you route to them. That happens on your instruction, under your own account with them, and subject to their terms and privacy policies; we are not a party to that relationship.

7. Where it is stored

Service data is held on Cloudflare’s network, with the primary database in the United States. Where personal data is transferred out of the UK or EEA, the transfer is covered by standard contractual clauses.

8. How long we keep it

  • Account, organisation, and configuration — for as long as the account exists.
  • Usage records — for as long as the account exists; they are your billing and usage history.
  • Authentication records — 90 days, then deleted automatically.
  • Operational logs — kept by our hosting for a short diagnostic window, measured in days.
  • Website analytics — retained in PostHog for up to one year.

When you close your account, we delete your account, configuration, and usage data within 30 days. Invoices and the records we must keep for tax purposes are retained for six years.

9. Security

All traffic is served over TLS. Provider credentials are encrypted at rest with envelope encryption, the root key living in a separate key-management service, and cannot be read back through the console or the API. Console passwords are stored hashed. Access to production data is limited to what operating the service requires.

10. Your rights

You can ask for a copy of your data, correct it, delete it, take it elsewhere, or object to or restrict how we use it. Write to support@appaigateway.com and we will respond within 30 days. If you are in the UK or the EEA and think we have handled your data badly, you can complain to your data protection authority — in the UK, the ICO.

11. Cookies and analytics

This website and the hosted console use PostHog to measure page visits, referring websites, campaign labels, browser and device information, clicks on signup, documentation, and self-hosting links, and — once you have an account — account creation, the steps you take to set the gateway up, the first request your gateway serves, and the start of a subscription. PostHog receives your IP address as part of the network connection and may use it to determine an approximate location. We do not send provider keys, the names you give your applications, prompts, responses, form contents, or anything from the requests your gateway proxies, and session recording is disabled.

Analytics cookies and local storage associate visits with a browser, with a 180-day expiry that may be renewed during use. They are set for appaigateway.com and its subdomains, so a visit to this website and a later visit to the console are recognized as the same browser. Once you sign in, the console also tells PostHog your account and organization identifiers, so that we can tell how many accounts get their gateway working. We do not send your name or email address to PostHog.

We honour the Do Not Track setting a browser may send, and collect nothing from a browser that sends it. You can also object to this analytics at any time by writing to support@appaigateway.com, as described in section 10, and we will stop. Your light/dark preference is saved in your browser’s local storage and never leaves it. The console additionally sets a strictly necessary session cookie to keep you signed in.

A self-hosted deployment of App AI Gateway runs none of this. The analytics described here belong to the hosted service on appaigateway.com and console.appaigateway.com.

12. Children

The Service is intended for developers and businesses. It is not directed at children, and we do not knowingly collect data from anyone under 16.

13. Changes

We publish updates to this policy on this page and email account owners about material changes. The date at the top always identifies the current version.

Questions about this document? Write to support@appaigateway.com.

Terms of Service ·Privacy Policy

AppAIGateway

Hosted service

  • Start for free
  • Login
  • Pricing
  • FAQ

Documentation

  • Quickstart
  • API reference
  • All docs

Open source

  • Source on GitHub
  • Deploy to Cloudflare

© 2026 App AI Gateway

TermsPrivacy