Privacy Policy
Last updated: July 9, 2026
WRouter (a service operated by WORLD ROUTER PTE. LTD., a Singapore-registered company) (“we”, the “Service”) takes your privacy seriously. This Privacy Policy explains how we collect, use, share, store, and protect your information when you use the Service.
See also the Terms of Service.
1. Information We Collect
1.1 Information you provide
- Account info: email, third-party OAuth identifiers (GitHub user ID, Google sub), display name, avatar
- Payment info: top-up orders and receipts; card number and CVV never touch WRouter — they are handled directly by third-party payment processors
- API tokens: stored only as hashes; the plaintext is shown once at creation
- Support submissions: feedback and tickets
1.2 Automatically collected
Each API call records the following metadata:
- Timestamp, upstream model, HTTP status, upstream latency
- Input tokens, output tokens, billed amount
- Source IP (for anti-abuse and IP allowlist enforcement)
- User-Agent
1.3 Request and response bodies
By default we do not store the request body (prompt) or response body (completion).
If you opt in via Console → Settings → Log Retention, we will store bodies for the retention window you choose, for your own debugging. Such data:
- Is visible only to you and authorized administrators
- Is encrypted at rest with AES-256
- Is deleted at the end of the retention window
1.4 What we do not collect
- We do not collect biometric data
- We do not access local files on your device that you have not explicitly uploaded
- We do not run cookies / tracking SDKs for advertising profiles on the server side
2. How We Use Information
- Service delivery: route requests to upstream models, billing, rate limiting, security
- Account operations: sign-in verification, payment reconciliation, customer support
- Service improvement: aggregated, anonymized metrics for performance and error analysis
- Legal compliance: response to valid judicial or regulatory requests
We do not:
- Use your inputs or outputs to train our own models
- Sell personal information or content to third parties
- Use undisclosed data for ad targeting
3. How Information Is Shared
3.1 Upstream model providers
To fulfill your request, your inputs and possibly relevant metadata are forwarded to the corresponding Upstream Provider (OpenAI, Anthropic, Google, Alibaba, ByteDance, DeepSeek, etc.) per their policies. These providers may process the data per their own terms. Review their privacy policies directly:
- OpenAI Privacy Policy
- Anthropic Privacy Policy
- Google Privacy Policy
- And policies of Qwen, Doubao, DeepSeek, etc.
3.2 Service providers
- Payments: third-party payment processors (only the order/receipt info needed)
- Infrastructure: cloud (compute, storage, CDN), email delivery (account notifications)
All service providers operate under data-processing agreements (DPAs) and act only on our instructions.
3.3 Legal disclosures
Upon receipt of a lawful, valid, and specific judicial or administrative request, we may disclose relevant information. We will notify affected users where permitted by law.
3.4 Business transfers
In the event of a merger, acquisition, or asset transfer, user data may be transferred as part of the assets. We will notify users via in-console message and email.
4. Storage and Security
- In transit: all API calls enforce TLS 1.2+
- At rest: account info and billing data are stored under access controls
- Encryption: detailed logs (when enabled) are encrypted at rest with AES-256
- Access: only SRE and necessary support staff access data on a least-privilege basis, with audit logs
- We implement and maintain physical, technical, and administrative security measures designed to protect your data from accidental loss and unauthorized access, use, alteration, and disclosure. All Personal Data you provide to us is stored on secure servers behind firewalls.
- The security of your information also depends on you. If you have been given (or you choose) a password to access certain parts of our Website, you are responsible for keeping that password confidential. You should not share your password with anyone.
- Unfortunately, transmission of information via the internet is not completely secure. Although we do our best to protect your Personal Data, we cannot guarantee the security of your Personal Data transmitted to the Website. Any transmission of Personal Data is at your own risk. We are not responsible for circumvention of any privacy settings or security measures of the Website.
- In the event of a security incident involving your personal data (a data breach), we will assess under applicable laws (including data breach notification obligations under Singapore’s Personal Data Protection Act) whether the incident is likely to cause significant harm to the affected individuals or meets the notification threshold in terms of scope. If the incident is assessed as notifiable, we will notify the Personal Data Protection Commission (PDPC) of Singapore and affected individuals as soon as practicable and within the statutory time limit, specifying the nature of the incident, the types of data potentially affected, as well as the response and remedial measures we have taken or intend to implement.
5. Retention
| Type | Period |
|---|---|
| Account info | Lifetime of the account + 30 days after closure |
| Billing / call logs (metadata) | 24 months |
| Detailed logs (request / response bodies, if enabled) | User-configurable (default 7 days) |
| Payment receipts | Per applicable tax law (typically 10 years) |
| Security audit logs | 12 months |
6. Your Rights
Subject to applicable data-protection law (including the Personal Data Protection Act (PDPA) of Singapore and GDPR), you may:
- Access: export your account info and call logs (CSV export available in console)
- Correct: edit email, display name, etc. under Profile
- Delete: self-service under Profile → Security → Delete account, which permanently removes the account and all data; request a refund of unspent balance in the Wallet first. Associated data is removed at the end of retention
- Restrict processing: control detailed log retention via the toggle in Settings
- Data portability: CSV export
- Withdrawal of Consent: You may withdraw your consent to specific data processing activities at any time via support@wrouter.ai. Withdrawal of consent shall not affect the lawfulness of processing carried out prior to such withdrawal, but may result in us being unable to continue providing part or all of the services reliant on such consent. We will inform you of the functionalities that may be impacted before the withdrawal takes effect.
To exercise these rights, contact support@wrouter.ai. We respond within 15 business days.
If you believe our processing of your personal data fails to comply with Singapore’s Personal Data Protection Act 2012 (“PDPA”), you may file a complaint directly with the Personal Data Protection Commission (PDPC) of Singapore via its official website: https://www.pdpc.gov.sg.
7. Cookies and Similar Technologies
The console uses necessary same-site cookies for session continuity. We do not use third-party tracking cookies.
8. Minors
The Service is intended for users 18+. If we learn a minor has registered, we will close the account and refund the balance.
9. Cross-Border Transfers
If you and your chosen upstream provider are in different jurisdictions, cross-border data transfers may occur during a request. Continued use of the Service indicates your understanding and consent to such transfers.
10. Changes to This Policy
This Policy may change with business or legal developments. Material changes will be announced at least 7 days in advance via in-console message, email, or on this page.
11. Contact
Email: support@wrouter.ai
DPO Email: DPO@wrouter.ai