Privacy Policy
Effective date: May 1, 2026 · Last reviewed: August 27, 2026
1. Information We Collect
We collect the following types of information:
- Account information: your email address and organization name provided during registration.
- Usage data: API request metadata including timestamps, provider selections, response latencies, token counts, and error rates.
- Device and access data: IP address, browser type, and access timestamps when you use the dashboard.
2. Information We Do Not Collect
Fairmeter does not persistently store the content of API request or response payloads. Prompt and completion text is processed transiently for routing purposes and is not logged unless you explicitly enable payload logging in your account settings.
3. How We Use Your Information
We use collected information to:
- Provide, operate, and maintain the Service.
- Generate analytics and insights visible in your dashboard.
- Monitor Service performance and detect abuse or security incidents.
- Communicate with you about your account, updates, and support requests.
- Improve the Service through aggregated, anonymized usage analysis.
4. Data Sharing
We do not sell your personal information. We may share information with:
- AI providers: request content, which can include your prompt text, is transmitted to the upstream provider that serves your chosen model to fulfill the request. In addition, a short, truncated excerpt of each routed request is sent to OpenAI for model-tier routing classification on Fairmeter’s own credentials, independent of the provider keys you configure. Provider-specific privacy policies apply to the data they receive; the full list is on our subprocessors page.
- Service providers: third-party services that assist in operating the platform (e.g., hosting, authentication, billing, email delivery), bound by confidentiality obligations. The current list is published on our subprocessors page.
- Legal requirements: when required by law, subpoena, or government request.
5. Data Retention
Retention windows differ by data class:
- Account information: retained for the duration of your account.
- Request metadata: timestamps, model and provider selections, token counts, latencies, cost, and routing decisions, retained for the windows configured in your account settings so the dashboard can surface usage, billing, budgets, and route history.
- Prompt and completion payloads: not retained unless your team explicitly enables payload logging. When enabled, payloads are visible only to authorized team members and are kept for your team’s configured retention period; payload logging can be disabled again at any time.
- Audit-log data: retained for 90 days or longer to support security, compliance, and chain-of-custody requirements.
Upon account deletion, we remove your personal information within 30 days, except where a longer retention period is required by law.
6. Data Security
We implement industry-standard security measures including encryption in transit (TLS 1.2+), encryption at rest for stored data, and access controls on internal systems. Provider API keys are encrypted at rest using authenticated encryption, and the key-vault reveal path uses AES-256-GCM envelope encryption. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
7. PII Redaction — Live, opt-in
A per-org PII redaction setting detects and masks common personally identifiable information, including email addresses, phone numbers, Social Security numbers and card numbers, in request payloads before they reach upstream providers. It is off by default and each org enables it for itself, so it protects nothing until you turn it on. It is not a HIPAA Safe Harbor de-identification control and it will not catch every identifier a prompt can carry. Treat upstream providers as recipients of whatever the setting does not mask. Do not route protected health information (PHI) or regulated sensitive personal data through Fairmeter unless your team has a signed agreement and confirmed controls in place.
7a. Sensitive Data
Several state privacy laws define a narrower category of sensitive data (for example, health information, precise geolocation, biometric data, and information about racial or ethnic origin, sexual orientation, or immigration status) that requires your opt-in consent before a controller processes it. Because request content is arbitrary text your team controls, Fairmeter does not itself screen for these categories unless you enable PII redaction under Section 7 above, which is off by default. If your use of the Service involves sending sensitive data to upstream providers, your organization is responsible for obtaining any consent required from the individuals whose data is included and for confirming that doing so is consistent with your own obligations. The one exception is the truncated routing-classification excerpt described in Section 4, which Fairmeter itself transmits to OpenAI on its own credentials for every request; that excerpt is not screened for sensitive data either.
8. Cookies and Local Storage
The dashboard relies on a small set of first-party identifiers to keep you signed in, remember your preferences, and surface in-app announcements only once. We do not use third-party tracking cookies or advertising pixels. The identifiers we set fall into two categories, both first-party and strictly functional:
Essential identifiers (required for the Service to function):
- Session and client cookies: first-party cookies set by our authentication provider to keep you signed in to the dashboard and protect sign-in against cross-site request forgery. Expire when your session ends or you sign out.
- Active-org cookie: HMAC-signed first-party cookie that records which organization you are currently viewing inside the dashboard. Required so the dashboard renders data for the right organization when you have access to more than one. Expires with your session.
Functional identifiers (improve the experience; persist in your browser local storage):
- Theme preference: remembers whether you selected the light or dark theme. Holds no personally identifiable information and is never transmitted to us.
- Saved filters: per-org saved filter sets you choose to save on the requests, audit, and alerts surfaces. Stored only in your browser; never transmitted to us.
- Onboarding-tour completion flags: boolean markers that prevent the dashboard from re-showing onboarding overlays after you have completed them. Stored only in your browser.
- Banner-dismiss flags: boolean markers per org that record which one-time banners you have dismissed. Stored only in your browser.
Error monitoring: a third-party error-monitoring service is loaded across the site, including pages you are not signed in to, to capture unhandled errors and performance diagnostics. It does not set advertising or cross-site tracking cookies, and it is configured with personal-data forwarding turned off and session replay disabled. It is listed as a subprocessor on our subprocessors page.
All identifiers above are first-party and either strictly essential to the Service or functional preferences you control through the dashboard. Beyond the error-monitoring service disclosed above, we do not load third-party advertising or cross-site tracking on the dashboard.
9. Your Rights
The data controller for the personal information described in this policy is Fairmeter. Depending on your jurisdiction, you may have the right to:
- Access the personal information we hold about you.
- Request correction of inaccurate information.
- Request deletion of your personal information (right to erasure). Once your request is confirmed, the gateway emits a recorded erasure event and removes your personal information within 30 days, except where a longer retention period is required by law.
- Object to or restrict certain processing of your information.
- Export your data in a portable format.
- Withdraw consent at any time, where processing is based on your consent.
- Lodge a complaint with a supervisory authority (for individuals in the European Economic Area or the United Kingdom).
To exercise any of these rights, contact us at the address below. We will respond to a request within 45 days of receipt, or notify you if we need an additional 45 days given the complexity or volume of the request. If we decline to act on your request, in whole or in part, you may appeal that decision by replying to our response with “Appeal” in the subject line; we will respond to an appeal within 60 days. If we deny your appeal, we will provide a way to contact the relevant state attorney general or other supervisory authority to submit a complaint.
You may designate an authorized agent to submit a request on your behalf. We will require the agent to provide proof of your written permission (or, where applicable, a power of attorney) to act for you, and we may separately verify your identity directly with you before completing the request.
9a. Legal Bases for Processing (GDPR)
Where the EU or UK General Data Protection Regulation applies, we rely on the following Article 6 legal bases, by purpose:
- Performance of a contract (Art. 6(1)(b)) to provide, operate, and maintain the Service and to route your API requests.
- Legitimate interests (Art. 6(1)(f)) to monitor Service performance, detect abuse and security incidents, and improve the Service through aggregated, anonymized analysis.
- Legal obligation (Art. 6(1)(c)) to retain audit-log and billing records as required by law.
- Consent (Art. 6(1)(a)) for any processing you opt into, such as enabling payload logging.
9b. California Privacy Rights (CCPA/CPRA)
In the past twelve months we have collected the following categories of personal information, as defined by the California Consumer Privacy Act: identifiers (such as your email address and IP address), commercial information (such as your subscription and billing records), internet or network activity (such as API request metadata and dashboard access logs), and inferences drawn from the foregoing to create a profile (such as the dashboard analytics and per-request routing classification described in Sections 3 and 4).
We do not sell or share your personal information as those terms are defined under California law, and we have not done so in the preceding twelve months. California residents may exercise their rights to know, delete, correct, and opt out without discriminatory treatment by contacting us at the address below.
Because we do not sell or share personal information, an opt-out-preference signal (such as Global Privacy Control) has no additional operative effect on our processing today. If that changes, we will detect and honor such signals as required by California, Colorado, and Connecticut regulations.
10. International Data Transfers
Your information may be processed in the United States or other countries where our service providers operate. We ensure appropriate safeguards are in place for any cross-border data transfers.
10a. Data Processing Addendum
A Data Processing Addendum (DPA) governing our processor obligations under GDPR Article 28 is available on request. Contact privacy@fairmeter.in to request a copy. A DPA is a different instrument from a data protection impact assessment; if your organization requires one for its own compliance before sending us data, contact the same address to discuss it.
11. Children’s Privacy
The Service is not directed to individuals under the age of 16, and in the United States we do not knowingly collect personal information from children under 13 (COPPA). If we learn that we have collected information from a child below the applicable age, we will delete it promptly.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page with a revised effective date. Continued use of the Service after changes constitutes acceptance of the revised policy.
13. Contact
For privacy-related inquiries, contact us at privacy@fairmeter.in.