Legal

Privacy Policy

Last updated: July 20, 2026

Your privacy matters to us. This Privacy Policy describes what information Openrind Gateway collects, how we use and share it, how we keep it secure, and the choices and rights you have. It applies to your use of our platform, websites, and services.

1. Overview

This Privacy Policy explains how Openrind, Inc. (“Openrind,” “we,” “us,” or “our”) collects, uses, discloses, and safeguards information when you use the Openrind Gateway platform, websites, and related services (the “Service”).

We act as a data controller for account and website information, and as a data processor for the request and usage data you and your end customers route through the gateway. By using the Service, you agree to the practices described here.

2. Information We Collect

We collect the following categories of information:

  • Account information — name, email address, organization details, and authentication identifiers when you register or sign in (including via Google).
  • Billing information — billing contact details and payment records. Card details are handled by our payment processor (Stripe); we do not store full card numbers.
  • Usage and metering data — API request metadata, token counts, model and provider used, cost and revenue figures, timestamps, and session identifiers used for tracking and billing.
  • Provider credentials — third-party provider API keys you choose to store, which are encrypted at rest.
  • Technical data — IP address, browser type, device information, and log data collected automatically when you use the Service.

3. How We Use Information

We use the information we collect to:

  • provide, operate, secure, and maintain the Service;
  • meter usage, calculate costs and margins, and process billing and payments;
  • authenticate users, prevent fraud and abuse, and enforce our terms;
  • provide support, respond to inquiries, and send service-related communications;
  • analyze and improve the performance, features, and reliability of the Service; and
  • comply with legal obligations.

5. How We Share Information

We do not sell your personal information. We share information only in the following circumstances:

  • Service providers — vendors who help us operate the Service (e.g., cloud hosting, payment processing, email delivery) under contractual confidentiality obligations.
  • AI providers — requests you route through the gateway are forwarded to the third-party AI provider you select, per your configuration.
  • Legal and safety — when required by law, legal process, or to protect the rights, property, or safety of Openrind, our users, or the public.
  • Business transfers — in connection with a merger, acquisition, or sale of assets, subject to this Policy.

6. Data Security

We implement technical and organizational measures designed to protect your information, including encryption in transit (TLS) and at rest, encrypted storage of provider credentials, signed and time-limited access URLs with replay protection, and access controls. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

7. Data Retention

We retain personal information for as long as necessary to provide the Service, comply with our legal obligations, resolve disputes, and enforce our agreements. Stored provider credentials are retained only for their configured lifetime and are automatically deleted when they expire or on account closure. Usage and ledger records may be retained longer for billing, audit, and accounting purposes.

8. Your Privacy Rights

Depending on your location, you may have the right to access, correct, delete, or port your personal information, to object to or restrict certain processing, and to opt out of certain disclosures. Residents of the EEA/UK (GDPR) and California (CCPA/CPRA), among others, have specific rights under applicable law.

To exercise these rights, please reach out through your account or our support channels. We will respond within the timeframe required by applicable law. You also have the right to lodge a complaint with your local data protection authority.

9. Cookies and Tracking

We use cookies and similar technologies to keep you signed in, remember your preferences, and understand how the Service is used. You can control cookies through your browser settings; disabling some cookies may affect functionality such as staying logged in.

10. International Data Transfers

We may process and store information in countries other than your own, including the United States. Where required, we rely on appropriate safeguards, such as Standard Contractual Clauses, to protect information transferred across borders.

11. Children's Privacy

The Service is not directed to individuals under the age of 16, and we do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us and we will take steps to delete it.

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will post the updated Policy with a revised “Last updated” date and, where appropriate, provide additional notice. Your continued use of the Service after changes take effect constitutes acceptance of the updated Policy.