Skip to content

Legal resources

Privacy Policy

What the Platform collects, why it collects it, and where it goes when a request is served.

STATUS
Draft
EFFECTIVE
To be confirmed
SECTIONS
13
CONTENTS13 sections

Scope

This policy covers personal information handled through the Routehook website, dashboard and API. It does not cover how a third-party model provider handles a request once it reaches them, which is governed by their own policy.

What we collect

Four kinds of information, distinguished because they are handled differently:

  • Account information. What you give us to create and hold an account, such as name, email address and authentication details.
  • Billing information. The record of credits added and drawn down. Card details are handled by a payment processor.
  • Usage information. Request metadata such as the model called, timestamps, cost, request identifiers, and technical data such as IP address and user agent.
  • Content. The prompts, files and other inputs you send, and the outputs returned for them.
TO BE FINALISED

The specifics of collection are not confirmed.

  • Which payment processor is used and what it stores on our behalf
  • Whether authentication is first-party, federated, or both
  • Exactly which technical fields are logged, and at what granularity

How we use it

  • To operate the Platform. Routing requests, returning results, and keeping accounts working.
  • To bill accurately. Deducting the cost of completed requests and showing usage back to you.
  • To keep the Platform secure. Detecting abuse, compromised keys and activity that degrades service for others.
  • To support you. Investigating issues you report, which is why every response carries a request identifier.
  • To meet legal obligations that apply to us.
TO BE FINALISED

Legal bases have not been mapped.

  • The lawful basis relied on for each purpose, per applicable regime
  • Whether any processing is based on consent, and how it is withdrawn

Prompts, inputs and outputs

Serving a request means sending your input to the model provider that runs the model you selected. What that provider does with it is governed by their policy, not this one.

Avoid sending personal or confidential information in a prompt unless you have established that doing so is appropriate for your use and for the provider serving it.

TO BE FINALISED

This is the most consequential gap in this document. Nothing here should be assumed either way until it is filled.

  • Whether prompt and output content is stored, and if so for how long
  • Whether content is ever used to train or improve any model, by us or by a provider
  • Whether staff can access content, under what controls, and for what reasons
  • Whether a zero-retention or no-training option exists

Who we share it with

Information is shared with the model provider serving a request, and with the service providers needed to run the Platform. Hosting, payments, and support tooling among them.

TO BE FINALISED

The subprocessor position needs to be written down before this is published.

  • A published subprocessor list and where it lives
  • How changes to that list are notified, and whether objection is possible
  • Whether data is shared for any purpose beyond running the Platform
  • What happens to data in a sale, merger or insolvency

Retention

TO BE FINALISED

No retention period is stated here, because none has been set. A period published before it can be honoured is worse than an acknowledged gap.

  • How long account records are kept after closure
  • How long usage and billing records are kept, and any legal minimum
  • How long prompt and output content is kept, if at all
  • How long security and access logs are kept
  • Whether deletion is immediate or on a cycle, and how backups are handled

Security

Keys are shown in full once and stored in masked form afterwards, and can be revoked without a redeploy. Access to production systems is restricted to the people who need it.

No system is perfectly secure, and nothing in this section is a guarantee against compromise.

TO BE FINALISED

No certification or audit is claimed on this site, and none should be added here until it exists and can be evidenced.

  • Any security certification or audit actually held
  • Encryption in transit and at rest, stated only once confirmed
  • Breach notification process and timeframes

International transfers

Requests are routed to the nearest available region, and model providers operate their own infrastructure, so information may be processed outside the country you are in.

TO BE FINALISED

Transfer mechanics are undecided.

  • Regions where data is processed and stored
  • Transfer mechanism relied on for each region
  • Whether regional pinning or data residency is offered

Your choices and rights

You can update account information from the dashboard, and closing an account stops further collection through it.

TO BE FINALISED

No statutory regime is named here, because which ones apply depends on the contracting entity and the regions served, both of which are still open in the Terms.

  • Which privacy regimes apply, and the rights each grants
  • How to make a request, and how identity is verified
  • Response timeframes and any appeal route
  • Contact point for privacy requests, and a data protection officer if one is appointed

Cookies and analytics

Some cookies are set because the Platform cannot work without them: a session cookie once you sign in, a cookie recording which sign-in you last used, and a cookie recording your answer to the question below. None of these are read by anyone but us, and none are used for advertising.

Beyond those, two things are optional and are asked about rather than assumed. Analytics measures which pages are read, in aggregate. Advertising records which ad or link brought you here — a click identifier from the ad network, stored so that a later sign-up can be credited to the campaign that paid for it — and loads the measurement tags belonging to the networks we advertise on.

Where a cookie banner is shown, nothing optional is loaded until you answer it, and the answer is honoured across the marketing site and the dashboard alike. You can change it at any time from “Cookie settings” at the foot of any page; withdrawing advertising consent also deletes the click identifier already stored.

TO BE FINALISED

The legal framing around the above has not been settled, and the list of destinations depends on which ad networks are connected in a given deployment.

  • The lawful basis relied on for each category, per region
  • Which advertising and analytics providers receive data, and where they process it
  • How long each cookie is kept, stated per cookie
  • Whether a jurisdiction requires the banner to be shown at all times, rather than only where configured

Children

The Platform is intended for developers building software, not for children.

TO BE FINALISED

Age handling is not defined.

  • Minimum age for an account, per region
  • What happens if an underage account is identified

Changes to this policy

This policy will change as the Platform does. The current version is always the one on this page.

TO BE FINALISED

Notification approach undecided.

  • How material changes are notified
  • Whether prior versions are kept available

Contact

TO BE FINALISED

No privacy contact route has been set up.

  • Email address for privacy enquiries
  • Postal address of the controlling entity
  • Escalation or supervisory authority details, where applicable