EnroutiaEU

Privacy policy

This explains what data we process, why, for how long and with whom. If you are looking for the technical explanation of why we cannot read your prompts, it is on the privacy architecture page.

Last updated: 2026-08-19

Who processes your data

The controller is the company operating this service, whose identifying and contact details appear in the legal notice. You can write to us about any data protection matter at the address given there.

What we process

Your email and, if you set one, your password (stored as a hash, never in the clear). API usage metadata: model, token counts, latency and cost. Billing data is handled by our payment provider; we never see or store your card number.

Your prompts and their responses

On the API path we do not store them. They live in memory for the duration of the request and are gone once we answer: no copy on disk, in logs, or in backups. One exception is not your choice and is worth naming — the response cache, in memory for up to an hour, which you can switch off entirely with Confidential Mode. The other exception is entirely your choice, and the next clause is about it.

Personal identifiers in your prompts

When a key asks for it, we replace personal identifiers in the prompt — email addresses, phone numbers, identity document numbers, bank account and card numbers, IP addresses and titled names — with placeholders before the prompt is sent to the model provider, and we put the originals back into the answer before returning it to you. The table that maps placeholders to originals exists only in the memory of that request and is discarded when we answer: it is not written to disk, to logs, to the usage record or to any backup. This is a control you switch on per key; it is off unless you do, and it does not change what we store, which for prompts and responses on the API path is nothing.

Content you choose to hand us

One feature works by holding on to content, and it never starts on its own: an audit, where you send us samples of your own traffic so we can re-run them against cheaper models and show you what would have changed. That content is encrypted before it is written, with a key kept apart from the one protecting your API keys, and it is never used to train a model — ours or anyone else's. It is deleted when you delete it, really deleted rather than hidden, and deleting your account takes it with you. Anything we add later that keeps content will work the same way: opt-in, encrypted, and yours to delete.

Legal basis

Performance of the contract, to provide and bill the service. Legitimate interest, to prevent abuse and fraud. Legal obligation, to retain accounting records.

For how long

The detail is in the retention table on the privacy architecture page — the same one we apply internally.

Who else is involved

Only the providers strictly needed to run the service: the inference provider that executes the models (in the European Union, with no retention and no training on your data), the payment provider, the transactional email provider and the infrastructure provider. Each under a data processing agreement.

Your rights

Access, rectification, erasure, objection, restriction and portability. From the panel you can export all your data and delete your account yourself, without asking us. You may also complain to your national supervisory authority.

Cookies

Only the ones strictly necessary to keep you signed in. No analytics or advertising cookies, which is why you will not see a banner asking for consent.

/privacy-architecture