Privacy Policy
This Policy explains what LLMRegistry processes, why it is processed, and how account, operational, billing, and model-request data are handled.
1. Scope and roles
This Policy applies to LLMRegistry websites, accounts, APIs, and control-plane services. For model requests submitted by an organization, that organization generally controls the request content and LLMRegistry acts as its service provider or processor. Separate enterprise agreements may define those roles more specifically.
2. Data we collect
- Account data: name, email, organization, role, authentication and verification state.
- Operational metadata: request ID, model and provider, token counts, cost, latency, outcome, region, cache state, and timestamps.
- Security data: session, IP and user-agent hashes, audit actions, key prefixes, and policy events.
- Billing data: checkout and invoice identifiers, funding amounts, fees, tax, settlement status, and wallet ledger entries. Payment credentials are handled by the payment provider.
- Support data: communications and information you choose to provide.
3. Prompt and completion boundary
Prompt and completion payloads are not stored to disk by the current gateway. They are processed in memory to route requests and deliver responses. Semantic caching is a separate, explicit feature that stores encrypted response content for reuse under the configured cache policy. Upstream providers receive request data needed to serve the selected model and apply their own terms and policies.
4. How we use data
We use data to authenticate users, provide and secure the Service, route model requests, enforce budgets, calculate usage and fees, settle payments, detect abuse, support customers, maintain audit records, comply with law, and improve reliability. We do not sell personal information or use customer prompts to train public models.
6. Retention and deletion
Retention depends on data type and legal need. Active account and configuration data remain while the account is in use. Operational, security, audit, and billing records are retained for legitimate service, dispute, compliance, and accounting purposes. Secret API values are not recoverable after issuance; only secured digests or encrypted provider credentials are retained.
7. Security
Controls include TLS in transit, encryption for sensitive stored provider credentials, hashed session and API secrets, role and organization boundaries, CSRF protection, audit trails, and restricted production access. No system is perfectly secure; report suspected incidents to support@llmregistry.com.
8. Privacy rights and choices
Depending on location, individuals may have rights to access, correct, delete, restrict, object, or receive a copy of personal data. Submit requests to support@llmregistry.com. We may verify identity and coordinate with the organization controlling the account before acting.
9. International transfers and children
Service providers may process data in countries other than yours, subject to applicable transfer safeguards and enterprise terms. The Service is intended for business users and is not directed to children under 16.
10. Changes and contact
We may update this Policy as the Service or law changes. Material updates may require renewed acceptance before using authenticated organization features. Contact support@llmregistry.com with questions or requests.