Privacy Policy
RouterLane ("we") runs the RouterLane API, Smart+, the console and routerlane.com. This policy explains what we collect, why, and what you can do about it. Questions: privacy@routerlane.com.
The short version
- We collect what we need to run the API, bill for it and support you.
- Transcripts are kept for 30 days by default, then the bodies are deleted. Enterprise deployments set their own retention, or turn transcripts off.
- Your raw API key is never stored, and credentials are stripped from logged headers.
- The website has no analytics, no tracking cookies and no third-party requests.
- We do not sell your data and we do not use your content to train models.
What we collect
Account information
When you request access: your name, work email, company, and what you tell us about your use. For each key, a SHA-256 hash and its first characters for display.
API request data
- Metadata, for every request: time, account and key, tier, model, effort, the routing decision and its reasons, token counts, timing, status and cost.
- Transcripts, when transcript logging is on: prompts, responses, reasoning, tool calls and tool results, and the request headers with credentials removed.
- Raw parameters, when raw logging is on: the parameters the router sent to the model.
Anything you put in a prompt or a file is part of the request. If it includes personal data, we process it as part of the request.
Smart+ uploads
The repository files your agent uploads for a Smart+ job, the commands run against them, their output, and the resulting patch.
Contact form
Your name, email, company, topic and message, plus the IP address and browser user agent the message came from, which we use to stop abuse.
Website and server logs
Our servers record standard request data, such as IP address, time, the page or endpoint requested, and user agent, to operate and secure the Service. The website uses no analytics.
How we use it
- To provide the Service: route requests, forward them to model providers, stream answers, cache, and run Smart+ jobs.
- To meter usage, enforce plan limits and bill you.
- To support you, including investigating a request when you send us its id.
- To keep the Service secure and enforce the Acceptable Use Policy, including content filters on Enterprise deployments.
- To improve routing, using request metadata such as decisions, latency and errors.
- To answer messages you send us.
We do not sell personal data, use it for advertising, or use your content to train models.
Who we share it with
- Model providers. To answer a request, we forward it to the infrastructure provider that runs the chosen model. Inputs blocked by a content filter are never forwarded.
- Service providers that host and operate our infrastructure, only to provide services to us.
- Authorities, when the law requires it.
- A successor, if RouterLane is involved in a merger, acquisition or sale of assets, under the protections of this policy.
How long we keep it
| Data | Kept for |
|---|---|
| Request metadata | As long as needed for billing, support and legal obligations |
| Transcript bodies | 30 days by default, or the window your Enterprise deployment sets |
| Response cache | 10 minutes, in memory only |
| Decision cache | 24 hours |
| Smart+ workspaces | Deleted 48 hours after the job |
| Contact messages | As long as needed to answer and keep a record of the conversation |
| Account information | While you have an account, and as long as needed for legal obligations after |
Cookies
The website sets no cookies and loads nothing from third parties. It remembers the code language you last picked in the docs in your browser's local storage, which never leaves your browser. The only cookie RouterLane sets is the console session cookie on Enterprise consoles: it keeps you signed in, is not readable by scripts, and expires after 7 days.
Security
Keys are stored as hashes, credentials are stripped from logs, traffic is HTTPS only, and Smart+ jobs run in an isolated account. Details are on the security page.
Your choices and rights
You can ask us to access, correct, export or delete your personal data, or object to how we use it, by writing to privacy@routerlane.com. We may need to confirm your identity first. If you live where data protection laws give you further rights, such as the European Economic Area, the United Kingdom or California, you have those rights too, including the right to complain to your data protection authority.
If your organization uses an Enterprise deployment, it controls the transcripts there. Send requests about that data to your organization as well.
International transfers
We and the providers we use may process data in countries other than yours. Where the law requires it, we use appropriate safeguards for those transfers.
Children
The Service is for developers and businesses. It is not directed at children under 16, and we do not knowingly collect their data.
Changes
We will post changes here with a new date, and email account holders about material changes before they take effect.