Privacy Policy
This Privacy Policy describes how Routero Intelligence Pte. Ltd. ("Provider", "we", "us") processes personal data when Customer and Customer's end users use the Routero AI service ("Service"). Please read this Privacy Policy carefully before accessing or using the Service. By accessing or using the Service, Customer acknowledges that it has read, understood, and agreed to this Privacy Policy, and that Provider may collect, use, disclose, transfer, retain, and otherwise process personal data as described in this Privacy Policy. If Customer does not agree, Customer must stop accessing and using the Service. Customer is responsible for ensuring that it has provided all required notices, obtained all required consents where applicable, and established a valid legal basis for any personal data submitted to or processed through the Service.
This policy is written for the Routero AI product specifically. It does not cover the Routero AI marketing website or other products and services offered by Provider, which are described separately where applicable.
1. What this Service does (relevant for privacy)
Routero AI accepts inference requests over an OpenAI-compatible HTTP API and forwards each request to an upstream large-language-model ("LLM") provider selected by Customer's configuration. It also runs a management UI/API for administering keys, users, organizations, budgets, rate limits, and usage analytics.
The Service is built on the open-source LiteLLM project under the MIT License.
2. Data we process
We process data in three categories:
2.1 Account data (collected from Customer)
When Customer creates a user, team, or organization in Routero AI, the Service stores in its PostgreSQL database:
- User identifier, optional email, optional alias, role
- Hashed password and salt (where password authentication is used)
- SSO subject identifier (where SSO is used; supports Google, Microsoft, Okta, generic OIDC)
- Team and organization membership
- Per-user, per-team, per-organization budgets, rate limits, and model-access lists
- Pending invitations (until accepted or revoked)
- Hashed virtual API keys, key aliases, key permissions, key budgets
API keys are stored hashed (one-way). The Service cannot recover the plaintext after creation.
2.2 Inference traffic (Customer Content)
Each inference request to the Service may include:
- Prompts, messages, embeddings inputs, image/audio/video inputs, model parameters
- A user identifier (per OpenAI spec — Customer's identifier for the end user)
- The HTTP request headers, including the source IP address
- Custom metadata fields and tags Customer attaches
The response from the upstream LLM provider (text completions, embeddings, images, audio, etc.) is returned to Customer. A copy of the request and response is also persisted in the Service's LiteLLM_SpendLogs PostgreSQL table when the operator's deployment has the store_prompts_in_spend_logs option enabled. As shipped, the active configuration does enable this — Customer should treat prompts and responses as stored.
The persisted record includes (per schema.prisma):
- messages (the request body)
- response (the upstream response body)
- requester_ip_address
- user, end_user, team_id, organization_id, hashed api_key
- model, model_group, custom_llm_provider, api_base
- Token counts, costs, timestamps, cache hit info, request tags, custom metadata
If Customer's configuration sets cache_llm = true, prompt + response pairs may also be temporarily cached in Redis for response acceleration. The active default in current deployments is cache_llm = false.
Customer is responsible for ensuring that any personal data, regulated data, or confidential information included in prompts has been collected and disclosed to the data subject in compliance with applicable law (including GDPR, CCPA/CPRA, HIPAA, PIPL, PDPA, and any sector-specific rules).
2.3 Operational data
We collect operational and security data to run the Service:
- Audit logs of management-plane mutations (LiteLLM_AuditLog): who did what, when, with before/after values
- Error logs (LiteLLM_ErrorLogs)
- Aggregated daily spend metrics per user/key/model/provider (LiteLLM_DailyUserSpend and related daily-rollup tables)
- Container logs (CloudWatch Logs in our deployment)
- Email-alerting events delivered via AWS SES
3. How we use the data
We process data to:
- Operate the Service — authenticate requests, enforce rate limits and budgets, route traffic to the upstream LLM provider Customer selected, and return the response.
- Maintain audit trails — record management-plane changes for security, compliance, and Customer's own audit needs.
- Bill / track usage — aggregate token and cost metrics per key/user/team/organization.
- Support and troubleshoot — investigate Customer-reported incidents using the spend log and error log records.
- Secure the Service — detect abuse, rate-limit anomalies, and unauthorized access attempts.
- Communicate with Customer — operational alerts, security notices, and (where Customer has opted in) product updates.
We do not use Customer Content to train Provider's own models. Customer Content is forwarded to upstream LLM providers, whose handling is governed by the providers' own terms and any contractual arrangement Customer has with the provider directly. Some providers may use submitted content to train their own models unless explicitly opted out. Customer must verify each provider's training-on-data position and exercise any available opt-outs.
4. Where data is stored
In Provider's reference deployment:
- Region: AWS Asia Pacific (Singapore), ap-southeast-1
- Database: Amazon RDS PostgreSQL (Single-AZ during beta; Multi-AZ at GA)
- Cache: Amazon ElastiCache Redis (single node during beta)
- Object storage: none currently for Customer Content; AWS S3 used only for Terraform state and (optionally) container artefacts
- Logs: AWS CloudWatch Logs
- Email: Amazon SES, ap-southeast-1, transactional only
When Customer's traffic is routed to an upstream LLM provider, the prompt and any included context are transmitted to that provider's infrastructure, which may be in a different region or country. Each provider's privacy notice describes how it handles data in transit and at rest. The active provider list in this deployment includes providers that may operate in the United States, the European Union, China, the United Kingdom, and elsewhere.
For self-hosted deployments, the operator chooses the storage region. The privacy obligations fall on the operator in that case.
5. Retention
We retain personal data only as long as necessary for the purposes set out in this Privacy Policy:
- Spend logs (including stored prompts and responses): 30 days
- Audit logs: 1 year
- Aggregated daily spend metrics: 13 months
- Account data: for the lifetime of the account, plus 90 days following termination to allow for data export and transition
- Container logs: 30 days
- Email delivery records (bounces, complaints): 30 days
After the retention window, records are deleted from production stores. Backups follow a separate retention rotation (see § 7). Where applicable law requires longer retention (for example for billing, tax, or dispute records), we retain the relevant records for the period required by law.
6. Disclosures to third parties
We share data with third parties only as needed to provide the Service. The current subprocessor and Upstream LLM Providers list is on the Subprocessors page. It includes:
- Upstream LLM providers — receive the prompt + parameters at request time
- AWS — hosts compute, database, cache, logs, email, DNS in the operator's deployment
- Cloudflare — hosts the apex DNS for routero.ai (no Customer Content traverses Cloudflare in the current deployment, but DNS metadata is observable)
We will give Customer prior notice of any new subprocessor. Customer may object to new subprocessors as set out in the Data Processing Addendum.
International data transfers
When the Service forwards Customer Content to an upstream LLM provider, the data may cross borders. The Service does not currently apply automated data-residency constraints — Customer's choice of provider determines the destination region.
For Customer-selected upstream model providers, Customer is responsible for reviewing the relevant provider terms, privacy policy, data-processing terms, retention practices, training-on-data practices, and cross-border transfer mechanisms.
For EU/UK personal data transferred to a jurisdiction that is not subject to an adequacy decision, the relevant parties should rely on an applicable transfer mechanism, such as Standard Contractual Clauses, the UK Addendum or UK International Data Transfer Agreement, or another lawful transfer mechanism.
7. Security
In the operator's reference deployment:
- TLS terminates at AWS ALB; backplane traffic between the ALB and the proxy uses internal VPC networking
- API keys are stored hashed in the database
- Provider API keys are stored encrypted at rest using AWS Key Management Service (KMS)
- The database, cache, and tasks run in private subnets; only the ALB is public
- Audit logs record management-plane mutations
- Optional: prompt-injection detection, Azure Content Safety, Presidio PII redaction (off by default)
- Backups: RDS automated backups retained for 7 days in production (1 day in sandbox and UAT environments)
For full detail see the Security Overview.
8. Data subject rights (GDPR, CCPA/CPRA, PDPA, etc.)
Where applicable law gives data subjects rights of access, rectification, deletion, restriction, portability, objection, or non-discrimination, Customer (as the controller of end-user data submitted to the Service) is the primary point of contact for end-user requests. Provider acts as a processor.
To exercise rights with Provider as a controller (for Customer's own account data), contact privacy@routero.ai or dpo@routero.ai. We respond within 30 days.
We do not currently expose automated subject-access endpoints; requests are handled manually.
9. Children's data
The Service is not directed at children under 18. We do not knowingly collect personal data from children. If Customer believes a child has submitted personal data through the Service, contact privacy@routero.ai for deletion.
10. Changes
We may update this Privacy Policy. Material changes will be communicated by email and/or in-product notice at least 10 days before they take effect.
11. Contact
Privacy questions: privacy@routero.ai
Data Protection Officer (where required): dpo@routero.ai
Legal entity: Routero Intelligence Pte. Ltd., Singapore
Legal enquiries: legal@routero.ai