Data we collect

We collect account email, OAuth profile metadata, API keys, API usage records, request metadata, billing events, usage ledger entries, billing eligibility signals, device and network signals, abuse-control signals, and support messages needed to operate CPEN usage billing, Data Safety enforcement, and routing.

Prompt, output, and Data Safety handling

API requests may contain prompts, files, schemas, messages, and outputs you submit or receive. CPEN processes this data to apply the selected Data Safety behavior, dispatch the request, return the response, settle usage, detect abuse, and maintain reliability. Optional request-payload trace storage is off by default. When account trace storage is enabled, CPEN retains raw request and response traces, including request policy metadata, for up to 30 days; DS1 does not inspect the request payload, but enabled trace storage can still retain the model response. Do not submit secrets, regulated data, or data you are not permitted to send to third-party AI services.

How we use data

Data is used to authenticate accounts, issue API keys, settle usage, manage usage billing, verify payment eligibility, screen abuse and sanctions risk, enforce terms, answer support requests, and improve route reliability.

Subprocessors and payments

We do not sell personal data. Requests may be sent to third-party AI services, infrastructure vendors, analytics or logging tools, and payment processors when needed to provide the service. Payment data is handled by the configured payment processor and is subject to that processor's own terms and policies.

Retention and deletion

Optional request traces expire after 30 days. Usage, ledger, risk, security, support, and payment records may be retained longer where reasonably necessary for billing, fraud prevention, tax, accounting, dispute handling, sanctions compliance, or legal obligations. When no longer required, records are deleted or de-identified. Account closure does not require deletion of records that CPEN must retain for those purposes.

Your responsibilities

You are responsible for obtaining the permissions, notices, consents, and legal basis needed to submit data to CPEN and third-party AI services. You must not submit personal data, confidential data, or regulated data unless your use case and service path permit it.

Access, correction, and deletion requests

You may request access to, correction of, or deletion of personal data associated with your account by contacting support@cpenrouter.space from the account email. CPEN may verify the request, refuse requests that would expose another user or security controls, and retain records where required for billing, fraud prevention, disputes, security, or law.

International processing and service providers

CPEN and the service providers needed to operate authentication, infrastructure, AI request processing, logging, support, and payments may process data in countries other than yours. You are responsible for confirming that your use permits those transfers. CPEN limits service-provider access to the operational purpose for which the provider is engaged.

Security and contact

CPEN uses access controls, scoped credentials, request identifiers, and operational monitoring to protect service data, but no Internet service can guarantee absolute security. Report privacy or security concerns to support@cpenrouter.space.