← Back to ROUTEXOR

Privacy Policy

Effective September 8, 2026

1. Overview

This Privacy Policy explains how ATERNA AI ("we", "us") collects, uses, and protects information when you use ROUTEXOR (the "Service"). We designed ROUTEXOR to hold as little of your data as possible: it is a bring-your-own-key router, so your AI usage runs on your own provider keys.

2. Information We Collect

Account information includes your email address, salted password hash, optional display name and profile image, account settings, and first-party signup attribution. We store the provider keys you add in encrypted form. Routing records include model and provider identifiers, timestamps, token counts, latency, estimated provider cost, status, task labels, routing decisions, and outcome feedback. Security records can include account and key identifiers, IP addresses, user-agent information, and administrative actions. Billing identifiers and subscription records are stored by ROUTEXOR; payment details are handled by Polar, and we do not store your card details.

3. Request Content and Optional Features

We do not sell your personal information or use your prompts and model outputs to train foundation models. Normal routing processes request and response content to deliver your result; ordinary usage records store metadata, not a transcript. Optional evaluation datasets persist the messages and expected answers you submit so they can be replayed. Outcome feedback can include any content you place in its metadata. Ensemble and opt-in shadow requests send content to multiple models; the ensemble judge also receives member answers. Their routing records include derived measurements rather than full answers. When you ask RUDY a question, its model-assisted mode sends that question and a compact account-usage summary to an available provider using your key. Do not submit content to these features that you are not permitted to share or retain.

4. How We Use Information

We use your information to operate the Service: authenticate you, route your requests using your keys, show you usage analytics, enforce plan limits, process subscriptions, provide support, maintain security, and comply with legal obligations.

5. Security

Provider keys are encrypted at rest using AES-256-GCM with per-user key derivation. The ROUTEXOR server can decrypt them to make authorized provider requests; this is not customer-only decryption or end-to-end encryption from ROUTEXOR. Passwords are stored as salted bcrypt hashes. We use HTTPS, account-scoped access controls, and revocable sessions. No system is perfectly secure, and these controls are not a compliance certification or a guarantee of security.

6. Third Parties

Requests are sent to AI providers eligible under the models and routing settings you use, with your provider keys and under the relevant provider terms. Those providers have their own retention and processing policies; ROUTEXOR does not guarantee zero retention by them. Polar provides billing and merchant-of-record services. Railway hosts the API, database, and cache; Vercel hosts the web application. Cloudflare Turnstile processes anti-abuse information if a Turnstile challenge is enabled and displayed. Support correspondence is processed to handle your request.

7. Cookies, Local Storage and Diagnostics

The essential HttpOnly rx_session cookie keeps you signed in. A temporary HttpOnly rx_admin_session cookie protects the original administrator session during read-only support impersonation. Local storage saves interface preferences, dismissed onboarding notices, and first-party campaign attribution; attribution is used to understand signups. ROUTEXOR does not load advertising pixels, including on login, signup, dashboard, or key-entry pages. Browser error reports contain an account identifier, report time, fixed error category, allowlisted view/page name, and browser family. They do not transmit free-form error text, stack traces, full URLs, URL queries, or fragments.

8. Data Retention and Deletion

Account, routing, security, and billing records are retained as needed to provide the Service and meet accounting, security, or legal requirements; there is not a single automatic deletion period for every category. Optional evaluation inputs and outcome metadata persist until removed through an applicable deletion process. Browser diagnostic reports are capped at 500, reports older than 30 days are excluded from operator queries and pruned on new reports, and the diagnostic store expires after 30 days without new reports. Operational logs and backups can retain historical data until their own retention or deletion processes complete. You can delete provider keys in the dashboard. Account deletion, export, and deletion of optional datasets or feedback can be requested at privacy@routexor.com; not all of these processes are self-service. Deleting data from ROUTEXOR does not itself delete copies held by your AI providers.

9. Your Rights

Depending on your location, you may have rights to access, correct, export, or delete your personal information, and to object to or restrict certain processing. To exercise these rights, contact us at privacy@routexor.com.

10. Children

The Service is not directed to individuals under 18, and we do not knowingly collect their information.

11. Changes

We may update this Policy from time to time. Material changes will be reflected by updating the effective date, and where appropriate we will provide notice.

12. Contact

Questions about this Policy or your data can be sent to privacy@routexor.com.