Privacy Policy
How ElevenRouter handles personal data: what we collect when you use the website, the dashboard and the API, what happens to the prompts you send, who else receives data, how long we keep it, and the choices you have. The technical companion to this policy is the privacy & data handling documentation.
Last updated September 25, 2026
1. Scope
This policy covers the ElevenRouter website, dashboard, API gateway and dedicated services (such as the Cursor service), operated by ElevenRouter (“we”, “us”). It applies to account holders and their organization members, to people whose data is contained in requests our customers send (“end users”), and to visitors of this site. Where you use ElevenRouter to process your own users' data, you are the controller of that data and we process it on your instructions as described in the Terms of Service.
2. What we collect
- Account data
- E-mail address, name, password hash or sign-in provider identity, organization name, and the legal name, address and tax id you enter for invoices.
- Request metadata
- For every API request: a generation id, timestamps, the model and vendor, token counts, exact cost, latency, finish reason, status and error code, the API key and workspace used, optional session and end-user ids your app attaches, app attribution headers, the routing decision and a pipeline summary (variant, preset, transforms, cache, guardrail counts). This powers your Activity and Logs pages, billing and receipts.
- Prompts and completions
- Only when your organization turns on “Store prompts and completions”. Off by default — see section 3.
- Billing data
- Purchases, credit grants, refunds, invoices and the ledger of every charge. Card details are entered on our payment processor’s pages and never reach us; we receive a payment reference, the card brand and last four digits.
- Security and audit data
- Sign-in events, IP addresses, user agents, and an audit log of who changed keys, budgets, members, policies and settings.
- Support communication
- E-mails you send us and the details you include in them.
- Website usage
- Standard server logs (IP address, requested page, user agent, timestamp) kept briefly for security and capacity. We run no advertising or third-party analytics trackers on this site.
3. Prompts and completions
Your prompts are sent to the vendor of the model you called in order to generate the answer, and the answer is returned to you. Unless you enable storage, the text is held in memory only for the duration of the request and is not written to our databases. When you enable “Store prompts and completions” (Settings → Privacy & controls) bodies are stored encrypted for 30 days so you can review them in Logs; you can turn storage off at any time and request purging. Guardrail policies record only which detector fired and how often, never the matched text. Optional redaction can strip e-mail addresses, phone numbers, card numbers, IP addresses, secrets and custom patterns from prompts before they leave ElevenRouter. We never use prompts or completions to train models.
4. Why we process it and on what basis
- To provide the service you asked for (performance of a contract): routing requests, metering usage, billing, showing you logs and analytics, delivering alerts.
- To keep the service secure and fair (legitimate interest): detecting abuse, rate limiting, protecting our upstream capacity, auditing administrative changes, preventing fraud.
- To meet legal obligations: keeping invoices and tax records, responding to lawful requests.
- To communicate with you: transactional e-mail about your account, balance, budgets, plans and incidents. We do not send marketing e-mail without your consent.
6. How long we keep it
- Account data
- For the life of the account, then deleted within 30 days of deletion, except what invoices require.
- Request metadata
- 13 months, for billing reconciliation, analytics and exports; daily aggregates without identifiers are kept longer.
- Stored prompts and completions
- 30 days when storage is on; purged early on request.
- Response cache
- Up to the TTL you set (at most 7 days), scoped to one API key, dropped when the key is deleted.
- Audit log
- 24 months.
- Guardrail policy events
- 90 days (detector names and counts only).
- Billing records and invoices
- As long as tax and accounting law requires, typically 7–10 years.
- Server logs
- Up to 30 days.
8. Security
All traffic uses TLS. API keys are stored as SHA-256 hashes and shown once. Your own vendor keys (BYOK) are encrypted with AES-256-GCM under a key held outside the database and are decrypted only in memory to sign upstream calls. Access to production is limited to the platform operators, every administrative action is audit-logged, and management keys are rate-limited. Read more on the Security page; report vulnerabilities to hello@elevenrouter.com.
9. Your rights and controls
Depending on where you live you may have the right to access, correct, export, restrict or delete your personal data, to object to processing based on legitimate interest, and to complain to a supervisory authority. Most of this is self-service:
- Export generation metadata as CSV or JSON from Logs, or through the analytics API.
- Turn prompt storage on or off, set retention, and purge stored bodies in Settings → Privacy & controls.
- Delete API keys (also drops their cached responses) or the whole organization from Settings.
- Update your name, e-mail, legal details and notification preferences in Settings.
- For anything else — including erasure requests, data-processing agreements or questions about end-user data — write to hello@elevenrouter.com. We answer within 30 days.
10. International transfers
Model vendors and infrastructure providers operate in several countries, including the United States. When personal data leaves your region we rely on the providers' standard contractual clauses or equivalent safeguards. The vendor allow-list lets you restrict which vendors, and therefore which jurisdictions, may receive your prompts.
11. Children
The service is for developers and businesses and is not directed at anyone under 18. We do not knowingly collect personal data from children; if you believe a child has created an account, contact us and we will delete it.
12. Changes
When this policy changes materially we notify organization owners by e-mail and in the dashboard before the change takes effect, and update the date at the top of this page.
13. Contact
Privacy questions and requests: hello@elevenrouter.com. Details of what is recorded per request and the controls available to your organization are in the privacy & data handling documentation.
Questions about this policy
Write to hello@elevenrouter.com and we will answer in plain language. Related documents: Terms of Service, Refund & Cancellation Policy, Acceptable Use Policy.