Flatrouter

Payment, Refund, Support and Security Policy

Version v0.1Last updated August 25, 2026Effective August 25, 2026

This policy explains how payment, plans, credit, refunds, support, and security work at Flatrouter, which is operated by NovaSpan LLC.

01

Prices and payment

Flatrouter plan prices are whatever the website and the console checkout page show. Pages may quote Chinese yuan, and Stripe or another checkout provider may take the equivalent amount in US dollars.

Your card issuer may use a different exchange rate and may add a cross-border transaction fee, a currency conversion fee, or other charges. Those are not under Flatrouter’s control.

A payment counts as successful when the payment provider returns success and the Flatrouter order status agrees. Creating an order, opening the checkout page, or submitting payment details does not by itself mean payment went through.

02

Billing credit

Plan credit is prepaid billing credit for Flatrouter API calls. It is:

  • not cash and not a bank deposit;
  • not withdrawable;
  • not transferable or resellable;
  • not exchangeable for another currency or for goods;
  • usable only for the Flatrouter services shown on the checkout page and in the console.

Usage is metered by model, endpoint, input and output tokens, cache hits, images, video, or whatever other unit applies. The usage and charge records in the console are the primary basis for billing.

03

Validity and stacking

Unless the checkout page says otherwise, plan credit runs on a 30-day billing period.

If you buy another plan before the current period ends, unused credit may be rolled into the new period and the validity clock restarted. Credit still unused once the period has ended may expire.

A plan does not by default produce a withdrawable balance, and does not automatically convert into another plan. Whether it auto-renews, whether it stacks, and how long it lasts are governed by what the purchase page actually shows.

04

Refunds

To the extent the law allows:

  1. A newly purchased plan can be refunded within 7 calendar days of purchase, provided it has produced no API calls and no usage records at all.
  2. A plan that has already produced API calls, charges, or credit usage is not, as a rule, eligible for a full refund.
  3. Disputes arising from duplicate charges, payment errors, system faults, or unauthorised transactions are handled case by case against the order, payment, and usage records.
  4. If Flatrouter is unable to provide a purchased service for an extended period for reasons of its own, we may offer a refund, a balance credit, or another reasonable remedy, based on the time affected and the unused credit.
  5. A refund does not restore model resources already consumed or third-party costs already incurred.
  6. Consumer refund rights granted by law are not limited by this policy.

To request a refund, email hello@flatrouter.com with:

  • the order number;
  • your registered email address;
  • the time of purchase;
  • the reason for the refund;
  • any payment details needed to reconcile the transaction.

Please do not send a full card number, a CVV, a payment password, or a full API key.

05

Chargebacks and payment disputes

If you think a transaction is wrong, contact us first. A bad-faith chargeback, a fabricated claim of an unauthorised transaction, or using a chargeback to bypass the normal refund process may lead to account suspension, a frozen balance, or termination of service.

We will give the payment provider the order, payment status, and service usage records needed to resolve the dispute.

06

Support scope and response

Support runs through hello@flatrouter.com. A subject line helps us route your message:

  • Billing — billing and payment questions;
  • Refund — refund requests;
  • Account — account problems;
  • Security Report — security problems;
  • Privacy Request — privacy requests.

Support may ask you to verify control of the account or the order. We will never ask you to email a password, a full API key, a private key, a card number, or a CVV.

Unless the law or a written SLA says otherwise, a support response time is not a commitment about service availability or about a refund.

07

Security measures

Flatrouter takes reasonable technical and organisational measures to protect accounts, orders, API keys, and service data, including:

  • HTTPS in transit;
  • hashed password storage;
  • masked display and revocation of API keys;
  • least privilege in production;
  • payment details handled by the payment provider;
  • monitoring for anomalous sign-ins, abuse, and risk;
  • security logging, backup, and recovery;
  • investigation and handling of security incidents.

No set of measures guarantees absolute security. Keep your credentials safe, and if one leaks, revoke the API key, change your password, and contact us immediately.

08

Reporting a security incident

If you find a leaked API key, a compromised account, an unexpected charge, an attack, or any other security problem, contact hello@flatrouter.com immediately with the subject Security Report.

Include only the minimum needed to locate the problem — never a full password, API key, private key, card number, or CVV.

We may respond by rate-limiting, revoking keys, suspending accounts, preserving investigation evidence, and notifying affected users.

09

Third-party payment and infrastructure

Payment, sign-in, hosting, network security, email, monitoring, and model services may be provided by third parties, who may handle the related information under their own terms and privacy policies and may operate in other countries or regions.

Flatrouter does not control the continued availability, processing location, fees, or policy changes of those third parties.

10

Changes to this policy

We may update this policy as prices, payment providers, product features, security measures, the law, or upstream services change. The updated version is published on this site with a new update date.