Privacy Policy

How ElevenRouter handles personal data: what we collect when you use the website, the dashboard and the API, what happens to the prompts you send, who else receives data, how long we keep it, and the choices you have. The technical companion to this policy is the privacy & data handling documentation.

Last updated September 25, 2026

1. Scope

This policy covers the ElevenRouter website, dashboard, API gateway and dedicated services (such as the Cursor service), operated by ElevenRouter (“we”, “us”). It applies to account holders and their organization members, to people whose data is contained in requests our customers send (“end users”), and to visitors of this site. Where you use ElevenRouter to process your own users' data, you are the controller of that data and we process it on your instructions as described in the Terms of Service.

2. What we collect

Account data
E-mail address, name, password hash or sign-in provider identity, organization name, and the legal name, address and tax id you enter for invoices.
Request metadata
For every API request: a generation id, timestamps, the model and vendor, token counts, exact cost, latency, finish reason, status and error code, the API key and workspace used, optional session and end-user ids your app attaches, app attribution headers, the routing decision and a pipeline summary (variant, preset, transforms, cache, guardrail counts). This powers your Activity and Logs pages, billing and receipts.
Prompts and completions
Only when your organization turns on “Store prompts and completions”. Off by default — see section 3.
Billing data
Purchases, credit grants, refunds, invoices and the ledger of every charge. Card details are entered on our payment processor’s pages and never reach us; we receive a payment reference, the card brand and last four digits.
Security and audit data
Sign-in events, IP addresses, user agents, and an audit log of who changed keys, budgets, members, policies and settings.
Support communication
E-mails you send us and the details you include in them.
Website usage
Standard server logs (IP address, requested page, user agent, timestamp) kept briefly for security and capacity. We run no advertising or third-party analytics trackers on this site.

3. Prompts and completions

Your prompts are sent to the vendor of the model you called in order to generate the answer, and the answer is returned to you. Unless you enable storage, the text is held in memory only for the duration of the request and is not written to our databases. When you enable “Store prompts and completions” (Settings → Privacy & controls) bodies are stored encrypted for 30 days so you can review them in Logs; you can turn storage off at any time and request purging. Guardrail policies record only which detector fired and how often, never the matched text. Optional redaction can strip e-mail addresses, phone numbers, card numbers, IP addresses, secrets and custom patterns from prompts before they leave ElevenRouter. We never use prompts or completions to train models.

Each model vendor processes the prompt under its own privacy and retention terms. Use the vendor allow-list in Settings to keep traffic away from vendors you have not approved.

4. Why we process it and on what basis

  • To provide the service you asked for (performance of a contract): routing requests, metering usage, billing, showing you logs and analytics, delivering alerts.
  • To keep the service secure and fair (legitimate interest): detecting abuse, rate limiting, protecting our upstream capacity, auditing administrative changes, preventing fraud.
  • To meet legal obligations: keeping invoices and tax records, responding to lawful requests.
  • To communicate with you: transactional e-mail about your account, balance, budgets, plans and incidents. We do not send marketing e-mail without your consent.

5. Who receives data

We share personal data only with the parties needed to run the service:

Model vendors and capacity providers
Receive the content of the requests you send (prompts, tools, attachments) to produce the answer. Which vendor a request went to is shown in the response headers and logs. Vendors do not receive your account details.
Payment processor
Handles card payments and issues the payment references on your receipts; subject to its own privacy policy.
Infrastructure and e-mail delivery
Hosting, storage and transactional e-mail providers acting on our instructions under data-processing terms.
Destinations you configure
Webhooks, Slack, OTLP collectors or object storage you connect for alerts or request broadcasting receive exactly what you configured.
Authorities
Where the law requires it, after checking the request is valid, and telling you unless we are prohibited.

We do not sell personal data and do not share it with advertisers or data brokers.

6. How long we keep it

Account data
For the life of the account, then deleted within 30 days of deletion, except what invoices require.
Request metadata
13 months, for billing reconciliation, analytics and exports; daily aggregates without identifiers are kept longer.
Stored prompts and completions
30 days when storage is on; purged early on request.
Response cache
Up to the TTL you set (at most 7 days), scoped to one API key, dropped when the key is deleted.
Audit log
24 months.
Guardrail policy events
90 days (detector names and counts only).
Billing records and invoices
As long as tax and accounting law requires, typically 7–10 years.
Server logs
Up to 30 days.

7. Cookies and local storage

This site and the dashboard set one strictly necessary cookie: the session that keeps you signed in. It is required for the service to work and needs no consent. Preferences such as the colour theme and whether you dismissed the cookie notice are kept in your browser's local storage and never sent to us. We use no analytics, advertising or cross-site tracking cookies. Third-party content embedded on this site (for example a YouTube video) is loaded only when you open it and is governed by that provider's policy.

8. Security

All traffic uses TLS. API keys are stored as SHA-256 hashes and shown once. Your own vendor keys (BYOK) are encrypted with AES-256-GCM under a key held outside the database and are decrypted only in memory to sign upstream calls. Access to production is limited to the platform operators, every administrative action is audit-logged, and management keys are rate-limited. Read more on the Security page; report vulnerabilities to hello@elevenrouter.com.

9. Your rights and controls

Depending on where you live you may have the right to access, correct, export, restrict or delete your personal data, to object to processing based on legitimate interest, and to complain to a supervisory authority. Most of this is self-service:

  • Export generation metadata as CSV or JSON from Logs, or through the analytics API.
  • Turn prompt storage on or off, set retention, and purge stored bodies in Settings → Privacy & controls.
  • Delete API keys (also drops their cached responses) or the whole organization from Settings.
  • Update your name, e-mail, legal details and notification preferences in Settings.
  • For anything else — including erasure requests, data-processing agreements or questions about end-user data — write to hello@elevenrouter.com. We answer within 30 days.

10. International transfers

Model vendors and infrastructure providers operate in several countries, including the United States. When personal data leaves your region we rely on the providers' standard contractual clauses or equivalent safeguards. The vendor allow-list lets you restrict which vendors, and therefore which jurisdictions, may receive your prompts.

11. Children

The service is for developers and businesses and is not directed at anyone under 18. We do not knowingly collect personal data from children; if you believe a child has created an account, contact us and we will delete it.

12. Changes

When this policy changes materially we notify organization owners by e-mail and in the dashboard before the change takes effect, and update the date at the top of this page.

13. Contact

Privacy questions and requests: hello@elevenrouter.com. Details of what is recorded per request and the controls available to your organization are in the privacy & data handling documentation.

Questions about this policy

Write to hello@elevenrouter.com and we will answer in plain language. Related documents: Terms of Service, Refund & Cancellation Policy, Acceptable Use Policy.