Skip to content

Legal

Privacy Policy

Last updated Oct 7, 2026

This policy explains how Avenro (“Avenro,” “we” or “us”) handles personal data when you use the Avenro website, dashboard and API (the “Service”). We are the controller of that data. For a technical summary, see Data handling.

What we never store

We do not store the content of your API requests or of the models' responses: prompts, messages, files, images, tool definitions, completions and reasoning pass through our systems in memory and are not written to our databases or logs, and we do not use them to train models. We store only a SHA-256 hash of each API key, never the key itself.

What we collect

  • Account data: your email address and sign-in identity, and your name or profile picture if your sign-in provider shares them.
  • Usage records: for each API request, its time, the API key and model used, which deployment served it, token counts, cost, the comparison with reference prices, latency and outcome. Billing and your usage dashboard are built from these records.
  • Payment data: for stablecoin payments, the paying wallet address, token, amount and transaction, which are public on Robinhood Chain.
  • Technical data: IP addresses, browser details and request logs kept by our hosting and security providers to run and protect the Service.
  • Communications: messages you send us and our replies.

Why we use it

  • To provide the Service: authenticating requests, routing them to models, metering usage and keeping your balance (performance of our contract with you).
  • To take payments, issue refunds and keep accounting records (contract and legal obligations).
  • To secure the Service and prevent fraud and abuse, including enforcing the Terms (legitimate interests).
  • To answer you and send service messages such as changes to these terms or to prices (contract and legitimate interests).
  • To understand and improve the Service from aggregated usage records (legitimate interests).

We do not sell personal data and do not use it for advertising.

Who processes it for us

We share personal data only with service providers that process it on our behalf and under our instructions, and when the law requires it:

  • Vercel: hosting of the website and the API, and their operational logs.
  • Neon: the database that holds accounts, API key hashes, credits and usage records.
  • Clerk: sign-in and account security.
  • Upstash: request rate limiting, which uses API key identifiers and counters only.
  • Model providers: the companies that serve the models you call (OpenAI, Anthropic, Google, xAI and DeepSeek, each named in the model's description), any partner inference provider we use to serve a model, and the GPU providers that host our own clusters receive request content in order to generate responses.

The x-avenro-execution-path header of each API response tells you whether a request was served by our own clusters (self-hosted) or by an outside provider (fallback). Stablecoin payments are recorded on a public blockchain, which nobody can alter or erase.

International transfers

Our providers may process data in the United States and other countries. Requests to DeepSeek models are processed by DeepSeek's API on servers in China. Where data protection law requires it, transfers rely on appropriate safeguards such as the European Commission's standard contractual clauses.

How long we keep it

We keep account data while your account is open. Usage and payment records are kept for as long as needed to provide the Service, to handle refunds and disputes, and to meet accounting and tax obligations, which can require several years. Operational logs are kept for a short period. When data is no longer needed, we delete or anonymize it. Blockchain records are permanent and outside our control.

Your rights

Depending on where you live, you may have the right to access, correct, delete or export your personal data, to object to or restrict its processing, and to withdraw consent where processing relies on it. To exercise them, contact @avenrotech on X; we will answer within the time the law allows. Some records, such as payment history, must be kept even if you close your account. You can also complain to your data protection authority.

Cookies

We use only cookies that are necessary for signing in and for security. We do not use advertising cookies or third-party analytics cookies.

Security

Data is encrypted in transit, access is limited to the people and systems that need it, and the API gateway connects to the database with a role that can only perform billing operations. No system is perfectly secure; if a breach affects your data, we will notify you as the law requires.

Children

The Service is not intended for anyone under 18, and we do not knowingly collect their data.

Changes

We will post any update to this policy with its date and, for significant changes, tell you by email or in the dashboard before they take effect.

Contact

Privacy questions and requests: @avenrotech on X.