Privacy at 1routers
Privacy Policy
This policy explains what information 1routers processes when you create an account, sign in with Google or GitHub, and route model requests through the service.
Effective and last updated
How 1routers collects, uses, shares, and protects account, OAuth, and service usage data.
Scope and operator
This Privacy Policy applies to the 1routers website, account dashboard, APIs, and model-routing services available through 1routers.com. In this policy, “1routers,” “we,” and “us” refer to the operator of those services.
By using the service, you acknowledge the practices described here. If you use 1routers for an organization, your organization may also have its own policies governing the information you submit.
Information we collect
We collect information that you provide, information supplied by an identity provider when you choose social sign-in, and technical information produced while operating the service.
- Account information: email address, password hash for password-based accounts, account settings, balance, routing preferences, and service credentials such as your 1routers API key.
- Social sign-in information: the provider name, the provider’s stable account identifier (Google sub or GitHub user ID), verification status, and the latest verified email address supplied by that provider.
- Service usage information: internal user and request identifiers, selected model and route, token or image usage, timing, status, pricing and charge records, and diagnostic identifiers returned by an upstream service.
- Technical information: IP address, browser or client user agent, request time, security events, and operational logs needed to protect and run the service.
- Browser storage: the website stores your signed-in session and language preference in your browser’s local storage. We do not currently use advertising cookies.
Google and GitHub sign-in
When you sign in with Google, we request basic OpenID identity information and profile/email access. We use the Google sub value as the stable external identity and use a verified email address to create or locate your 1routers account. When you sign in with GitHub, we use your GitHub numeric user ID and primary verified email address for the same purpose.
We do not store Google or GitHub OAuth access tokens or refresh tokens after the sign-in exchange. We store only the provider identity mapping and verified email snapshot needed to recognize the account on later sign-ins. Other profile fields, such as a profile image or display name, are not currently stored by 1routers.
We do not use information received from Google or GitHub for advertising, and we do not sell it. Our use of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements.
Model requests and content
To provide model routing, the prompts, files, tool data, and other content you submit must be transmitted to the model provider or route selected for the request. Responses from that provider are transmitted back to your client. Those providers process content under their own terms and privacy policies.
The ordinary 1routers usage ledger stores metering and routing facts, not complete prompt or response bodies. A diagnostic capture mode can be deliberately enabled by an operator while investigating a technical problem; when used, captured content must be limited to what is necessary, protected as sensitive data, and removed when the investigation is complete.
How we use information
We process information to provide and improve the service, authenticate users, maintain account security, route requests, calculate usage and charges, provide support, prevent abuse, troubleshoot failures, comply with legal obligations, and communicate important service or security information.
Verified email can be used to associate a new social identity with an existing account. After a social identity is linked, later sign-ins are recognized by the provider’s stable identifier rather than by email alone.
How we share information
We disclose information only as needed to operate the service, fulfill your request, protect users and the service, or comply with law. We do not sell personal information.
- Identity providers such as Google and GitHub, when you initiate or complete social sign-in.
- Model providers and routing channels, when they are needed to process a request you send.
- Infrastructure, database, cache, hosting, security, and email-delivery providers acting on our behalf.
- Authorities or other parties when reasonably necessary to comply with law, enforce our terms, or protect rights, safety, and service integrity.
- A successor in connection with a merger, financing, reorganization, or transfer of the service, subject to appropriate confidentiality protections.
Retention and deletion
We retain account and authentication records while your account remains active or as needed to provide the service. The normal detailed usage ledger is designed for a 30-day retention period. Security, financial, backup, and operational records may be retained longer when reasonably necessary for fraud prevention, accounting, dispute resolution, or legal compliance.
You may request access, correction, or deletion through the contact channel below. We may need to verify that you control the account before acting. Deletion may not immediately remove records that must be retained by law, are required to resolve a dispute, or remain temporarily in protected backups.
Security and international processing
We use technical and organizational safeguards intended to protect information, including restricted credentials, signed sessions, transport encryption for production endpoints, and separation between internal account IDs and external identity IDs. No storage or transmission system is completely secure.
Our service providers and model providers may process information in countries other than your own. Where required, we rely on lawful transfer mechanisms and provider contractual protections.
Your choices and rights
You may use password-based login where available instead of social sign-in, revoke 1routers access from your Google or GitHub account settings, clear the local browser session by signing out, and ask us to update or delete eligible account information.
Depending on where you live, you may have additional rights to access, correct, delete, restrict, object to, or receive a copy of personal information, and to appeal or complain to a data protection authority.
Children and policy changes
1routers is not directed to children and should not be used by anyone who cannot legally consent to the processing described in this policy. If you believe a child has provided personal information, contact us so we can investigate.
We may update this policy as the service or applicable requirements change. We will publish the revised version here and update the effective date. Material changes may also be communicated through the website or account contact information.