Privacy Policy
Last updated July 23, 2026.
1. Plain-English summary
We believe in privacy by default. You will have to opt into data collection for yourself. We never read your logs, distill them, sell them, or train AI models on them.
ProxyLLM is paid for by subscriptions. The money comes from you renewing, not from your data. By default, your prompts and responses are not stored at all. Request logging is off until you turn it on.
What we keep by default is the billing record of each request: the model, token counts, cost, speed, and whether it succeeded or failed.
2. What we collect
- Account: email, OAuth identity (Google), display name, password hash (via Supabase Auth).
- API keys: encrypted at rest with AES-256-GCM. Never logged in plaintext.
- Requests: by default, only the numbers: model, provider, routing decision, token counts, latency, cost, and success or failure. Prompt text (up to 20,000 characters) and response text (up to 100,000 characters) are stored only when you turn request logging on.
- Routing configs: the visual graphs and classifier settings you create.
- Codex sessions: you run the Codex login on your own machine and upload the sign-in file. We store that file encrypted at rest with AES-256-GCM, along with the account email and usage meters.
- Operational telemetry: request timing, error logs, usage counters. No third-party trackers or advertising cookies.
3. What we use it for
- Operate the service (proxy your calls, meter costs, show the dashboard).
- Improve routing accuracy and cache detection using aggregated usage numbers only, never the content of prompts or responses.
- We never read stored logs. Our admin tools cannot display prompt or response content at all.
- Detect abuse, billing fraud, and provider TOS violations.
- Send you product and billing emails (account-related, not marketing, unless you opt in).
4. Who we share with
- AI providers (OpenAI, OpenRouter, and whichever provider your routing picks). Each receives only what is needed to serve your request, using your own key.
- Supabase (database + auth).
- Vercel (serverless compute hosting).
- Hetzner (servers for the Codex Hosted service, paid feature).
- Whop Inc. (300 Kent Ave #401, Brooklyn, NY 11249), the merchant of record for paid plans. Whop handles checkout, billing, and tax remittance. We receive your subscription status from Whop.
- Government or law enforcement when required by a valid legal request.
Nothing is sold to anyone. No data broker, advertiser, or AI lab receives your data.
5. Retention
Request records auto-delete after 30 days by default. You can set retention to 7, 30, or 90 days, or keep records forever. Stored prompt and response content (when request logging is on) follows the same setting. Daily aggregate totals (counts and costs, no content) are kept indefinitely.
Deletion is real deletion: rows are removed from the database, not hidden. Tightening a privacy setting deletes the stored data it covers. Turn request logging off and any stored prompts and responses are deleted; shorten the retention window and records older than it are deleted. You can also delete stored prompts and responses at any time with one click in Settings.
Encrypted API keys are kept until you delete them. Account data is kept while the account exists; deleting your account permanently deletes every row of your data.
6. Your choices
- Turn request logging on or off in Settings. It is off by default, and turning it off deletes any stored prompts and responses.
- Choose how long request records are kept: 7, 30, or 90 days, or forever.
- Delete stored prompts and responses with one click in Settings.
- Delete individual API keys from Settings.
- Delete your account at any time from Settings, or by emailing support@proxyllm.ai. This permanently deletes every row of your data.
- Request export of your data in JSON at support@proxyllm.ai.
- EU/UK/California residents: you have the rights granted by GDPR, UK GDPR, and CCPA, including access, deletion, and objection. Email the same address to exercise them.
7. Security
API keys and Codex sign-in files are encrypted at rest with AES-256-GCM. Auth flows through Supabase. All traffic is TLS. We do not promise the service is unhackable; we promise to disclose material breaches affecting your data within 72 hours of confirmation.
8. Children
ProxyLLM is for users 18 and older. We do not knowingly collect data from minors. If we learn a minor has an account, we will delete it.
9. Changes
Material updates to this policy will be posted here with a new "Last updated" date and announced in-app or by email for material changes.
10. Contact
Questions, privacy or data-rights requests: support@proxyllm.ai. Billing privacy questions also go to Whop at support@whop.com.