Privacy Policy
Version v0.1Last updated August 25, 2026Effective August 25, 2026
This policy explains how NovaSpan LLC ("Flatrouter", "we") collects, uses, stores, and protects information when you visit the Flatrouter website, register an account, sign in to the console, buy a plan, create an API key, or call the Flatrouter API.
01
Data controller
Flatrouter is an AI API routing and billing service operated by NovaSpan LLC, which is the controller of the personal data described here. Unless separately agreed in writing, Flatrouter has no agency, authorisation, partnership, or endorsement relationship with OpenAI or any other model provider.
Privacy questions go to hello@flatrouter.com. A subject line helps us route them:
- Privacy Request — exercising a privacy right;
- Security Report — reporting a security problem;
- Account Deletion — asking us to delete your account.
02
Information we collect
Account information
When you register or use Flatrouter we may collect:
- your email address;
- your display name;
- your sign-in verification status;
- a cryptographic hash of your password;
- when the account was created and when it last signed in;
- account status, plan status, and permissions.
Order and payment information
When you buy a Flatrouter plan we may collect:
- the order number;
- the plan bought;
- the amount and currency paid;
- the credit added;
- the transaction status;
- refund, chargeback, and risk-check outcomes;
- the billing email address and billing details.
Full payment credentials — card number, CVV, payment account password — are handled by the payment provider. Flatrouter does not store a full card number or a payment account password.
API usage information
When you call the Flatrouter API we may record:
- the time of the request;
- the model used;
- the endpoint type;
- input and output token counts;
- the amount charged;
- how long the request took;
- the HTTP status code and any error message;
- retry, routing, and failover outcomes;
- an identifier for the API key used;
- the request ID.
We do not write a full API key into our logs.
Technical and security information
We may collect:
- IP address;
- user agent;
- browser, operating system, and device details;
- sign-in and sign-out events;
- failed sign-in attempts;
- risk-control, rate-limit, and anomalous-access signals;
- security audit and system operation logs;
- approximate network region.
This is used for sign-in security, abuse prevention, troubleshooting, usage metering, and keeping the service running.
03
Data from Google Sign-In
If you choose to sign in with Google, we request the openid, email, and profile scopes and read only the following fields from your Google account:
- sub — your Google account identifier, stored as the stable key that links your Google account to your Flatrouter account.
- email and email_verified — used as your account email; an unverified address is rejected.
- name and given_name — used as your initial display name, which you can change afterwards.
- picture — the URL of your Google profile photo, used as your initial avatar.
We never request access to your Gmail, Drive, Calendar, or Contacts. Google user data is used solely to create and authenticate your account, is never sold, and is never used for advertising.
04
Prompts, files, and model responses
What you submit through the Flatrouter API may include prompts, message context, code, images, audio or files, tool-call arguments, and the model response.
Flatrouter does not store full prompts, model responses, or attachments as ordinary usage logs. That content is processed transiently while the request is in flight, in order to:
- forward the request to the chosen model channel;
- return the model response;
- run safety, anti-abuse, and risk checks;
- compute token usage and charges;
- handle request failures and technical faults.
Unless you turn on debugging, logging, or a support feature yourself, full prompts and model responses are not retained as ordinary usage logs.
If you do turn on full request logging, that content is kept for at most 30 days, and may be kept longer where a security investigation, a dispute, a legal obligation, or technical support requires it.
Please do not send passwords, private keys, full API keys, card details, or unnecessary sensitive personal data through the Flatrouter API.
05
How we use your information
We may use what we collect to:
- create and administer user accounts;
- verify who you are;
- provide API forwarding, model routing, and failover;
- compute token usage and service charges;
- manage plans, balances, top-ups, and refunds;
- produce usage logs and billing records;
- prevent fraud, abuse, attacks, and anomalous traffic;
- keep API keys and accounts secure;
- handle customer support, privacy, and security requests;
- improve the stability and performance of the service;
- meet tax, accounting, legal, and regulatory obligations;
- enforce the terms of service and the acceptable use policy.
06
Sharing and disclosure
To run Flatrouter we may disclose the information necessary to the following categories of provider.
Upstream model and API providers
Your API requests may be forwarded to the third-party providers that actually serve the model. How they handle, retain, and locate that data, and whether they train on it, is governed by their own terms and privacy policies. Different models, routes, and regions can mean different third parties.
Payment providers
We may give Stripe or the payment provider shown at checkout what is needed to take payment, issue refunds, handle chargebacks, and run risk checks.
Sign-in, hosting, and security providers
We may use third parties for:
- Google Sign-In;
- cloud hosting;
- CDN and network security;
- databases and object storage;
- sending email;
- monitoring, logging, and troubleshooting;
- fraud detection and abuse prevention.
Legal and safety disclosure
We may disclose what is necessary in order to:
- comply with the law, a court order, or a regulator;
- protect the safety of Flatrouter, our users, or the public;
- investigate fraud, attacks, abuse, or breaches of the terms of service;
- handle a merger, acquisition, financing, or transfer of assets.
We do not sell personal information, and we do not use it for cross-site targeted advertising.
07
Storage and international transfers
Flatrouter account, billing, and service operation data is stored primarily in the United States.
Because model providers, payment providers, cloud providers, and security providers run global infrastructure, your information may be transferred to or processed outside your own country or region.
Where that happens depends on:
- the model you chose;
- the channel your request was routed to;
- the upstream provider;
- the cloud region;
- the infrastructure of the payment and security providers.
08
How long we keep information
We keep information only for as long as we need it to run the service, take payment, maintain security, meet a legal obligation, resolve a dispute, or prevent fraud. In practice:
- Account information: for the life of the account; normally removed from live systems within 30 days of the account being closed.
- Per-request API usage records — model, token counts, charge, request metadata: 90 days, after which the rows are deleted.
- Aggregated usage statistics that contain no per-request detail: hourly totals for 180 days, daily totals for 730 days.
- System operation, error, and metrics logs: 30 days.
- Sign-in records: we store only the time of your most recent sign-in on the account itself, for as long as the account exists.
- Full prompts, model responses, and attachments: not retained by default; at most 30 days when you turn logging on yourself.
- Order, payment, tax, and accounting records: normally 7 years, or longer where the law requires it.
- Support, complaint, and privacy request records: 3 years after the request is closed.
- Security incident records: 3 years after the incident is closed.
- Backups: deleted as the normal backup rotation overwrites them.
Where a legal dispute, security investigation, chargeback, fraud investigation, or legal hold applies, we may keep information for longer, to the extent necessary.
09
Cookies and local storage
Flatrouter may use strictly necessary cookies or local storage for:
- your sign-in session;
- authentication;
- security protection;
- language and theme preferences;
- the basic operation of the site.
We do not use cross-site advertising cookies. Blocking the necessary ones may stop sign-in or parts of the site from working.
10
Security
We take reasonable technical and organisational measures to protect user information, including:
- HTTPS in transit;
- hashed password storage;
- access control over API keys;
- least privilege;
- separated permissions on production systems;
- security logging and anomaly monitoring;
- backup and recovery;
- API key rotation and revocation.
No internet service can promise absolute security. For your part, please:
- use a unique, strong password;
- never share an API key;
- rotate API keys regularly;
- revoke a key the moment it leaks;
- never put a password, private key, or full payment credential in a ticket, an email, or a prompt.
11
Your privacy rights
Depending on the law that applies to you, you may have the right to:
- ask for access to your personal information;
- ask us to correct information that is wrong;
- ask us to delete your personal information;
- ask us to restrict or object to some processing;
- ask for an export of your personal information;
- withdraw consent you previously gave;
- understand how your personal information is used;
- complain to the relevant data protection authority.
Email hello@flatrouter.com with the subject Privacy Request. We normally respond within 30 days of a valid request. To protect your account, we may ask you to verify your identity or your control of the account.
Some data cannot be deleted immediately where tax, payment, legal, security, fraud investigation, or dispute requirements apply.
12
Children
Flatrouter is not offered to anyone under 18.
If we find that a minor has created an account without proper authorisation, we may suspend or delete it and delete the information within scope.
13
Changes to this policy
We may update this policy as product features, model channels, legal requirements, providers, or security measures change.
After an update, this page shows the new update date. Where a change materially affects your rights or how your data is handled, we will make a reasonable effort to tell you through the website, the console, or your registered email address.
14
Contact us
Privacy, account, and security questions go to hello@flatrouter.com.
Please do not email us a full API key, a password, a private key, a card number, or a CVV.