WindRouter Privacy Policy

Last updated: July 16, 2026

This Privacy Policy explains how WindRouter processes account data, request data, operational metadata, API credentials, and client-provided MCP/tool credentials. It reflects WindRouter’s current production configuration as of the date above and may be supplemented by a separate enterprise agreement or data processing agreement.

1. What WindRouter processes

WindRouter is an OpenAI-compatible AI routing service. To provide the service, WindRouter may process:

Account information, such as email address, login details, organization or user identifiers, account settings, and billing/quota records.

Authentication and authorization records, including WindRouter-issued API keys or token records required to authenticate requests and enforce limits.

Request data submitted to the API, including model name, messages, tool definitions, metadata, and other JSON fields required to route and complete the request.

Client-provided MCP or tool credentials submitted per request, if the client includes them in request JSON.

Operational metadata, such as timestamp, request ID, user ID, token ID/name, model used, token counts, status code, latency, quota usage, route/channel metadata, IP address, and user agent.

2. Credential zero-retention for per-request MCP/tool credentials

WindRouter does not intentionally persist client-provided MCP credentials, tool credentials, or other third-party API keys submitted only for a single request. Under the current production configuration, these per-request credentials are processed transiently for the active request and are not stored in WindRouter’s database, application request logs, or usage logs.

This credential zero-retention statement applies to client-provided credentials passed per request. It does not mean WindRouter retains no data at all. WindRouter retains account records, authentication records, billing/quota information, and operational metadata needed to operate, secure, and bill the service.

3. Request bodies and logs

WindRouter usage logs are designed to store operational metadata such as model, token counts, cost/quota consumption, status, route information, and timing. WindRouter does not intentionally log full request bodies or client MCP credentials in production.

WindRouter may retain error, security, and operational logs that are necessary for abuse prevention, debugging, reliability, and billing. These logs should not include full client request bodies or per-request MCP credentials by default.

4. Data sent to upstream providers and third-party services

WindRouter routes requests to selected upstream model providers and, when applicable, third-party services or MCP/tool endpoints designated by the client. Request content required to complete a request may be transmitted to those providers or endpoints. Their processing and retention practices are governed by their own terms and policies.

Clients should avoid submitting secrets as normal prompt text. Credentials that are needed for tools or MCP servers should be passed only through documented credential fields or enterprise-approved integration flows.

5. Security controls

WindRouter uses HTTPS in transit, access controls, API-token authentication, and operational safeguards to protect the service. No hosted service can guarantee that data is immune from every possible compromise. A database-only compromise should not expose historical per-request MCP credentials if they were submitted only transiently and not logged. A full runtime/server compromise during active traffic could potentially expose secrets submitted during or after the compromise window.

6. Client responsibilities

Clients are responsible for:

Keeping their own API keys, MCP credentials, and third-party tokens secure.

Limiting credential permissions to the minimum needed scope.

Rotating credentials after suspected compromise.

Avoiding submission of unnecessary secrets in prompts or request content.

Ensuring they have rights to submit data and credentials to WindRouter and any selected upstream provider.

7. Retention summary

Per-request MCP/tool credentials: processed transiently; not intentionally retained.

Prompt/request content: processed to complete routing and generation; not intentionally stored as full request-body logs by WindRouter in production.

Operational metadata: retained as needed for billing, abuse prevention, debugging, reliability, analytics, and compliance.

Account and billing data: retained while the account is active and as needed for legal, tax, fraud-prevention, and dispute-resolution purposes.

8. Enterprise agreements

Enterprise customers may request additional security terms, data processing terms, retention commitments, subprocessors information, audit documentation, or custom deployment options. If a separate written agreement conflicts with this Privacy Policy, the separate written agreement controls for that customer.

9. Contact

For privacy, security, or data-retention questions, contact WindRouter through the support channel provided in your account or enterprise agreement, or email alice.m@windrouter.space.