1. Data user and contact details Under applicable data-protection law, StringRoute processes relevant data as the data user or controller. For personal-data access, correction, deletion, or complaints, contact [email protected].
Privacy Policy
Effective: June 20, 2026. Last updated: June 20, 2026. This policy applies to personal information and user data processed through StringRoute Webchat, the API, dashboard, payments, support, risk controls, security audits, and related services.
2. Information we collect Account information: email, username, login credentials, account status, and membership tier. Login and device information: IP address, device identifiers, browser, operating system, language, access time, cookies, and similar technologies. Payment and order information: order number, top-up records, subscription status, invoice details, and payment-channel confirmations. Webchat content: conversations, history, uploaded files and images, model selection, and feedback. API content: request and response content, API Key identifiers, request time, token usage, error logs, and rate-limit records. Security and risk information: unusual logins, proxy detection, abuse detection, prohibited-content flags, suspensions, and appeal records. Support information: questions, attachments, and communications submitted to [email protected].
3. How we use information Create accounts, verify logins, and provide Webchat and API services. Process AI requests, generate output, and retain conversation history and uploaded files. Calculate charges and balances, manage subscriptions, process orders, and review refunds. Monitor service stability, troubleshoot incidents, and improve performance and model routing. Detect abuse, fraud, attacks, prohibited content, and anomalous calls. Meet legal, regulatory, audit, dispute-resolution, and security obligations. Send service notices, billing reminders, product-change notices, security alerts, and necessary operational messages.
4. Third-party model providers and processing chain To provide AI output, user input, uploaded files and images, API requests, and related context may be transmitted to third-party model providers. The platform currently focuses on access to large language models such as the GPT family and may add more providers. The model list and dashboard are the source of current availability. We do not make commitments on behalf of third-party model providers beyond their public policies or our agreements with them. Providers may process data to deliver services, review security, detect abuse, meet compliance requirements, or as otherwise described in their policies.
5. Training, disclosure, and sensitive information We do not use customer data to train StringRoute's own models unless the user separately and expressly authorizes it. We do not sell, rent, or intentionally disclose user data to unrelated third parties. We may disclose necessary information to model, cloud, payment, security, or support providers, auditors, or legal advisers where needed to provide services, generate AI output, bill usage, manage security risk, troubleshoot, audit compliance, resolve disputes, or meet legal obligations. Users must mask sensitive information before uploading or submitting it. Sensitive information voluntarily submitted may still enter conversations, files, API requests, caches, logs, backups, or third-party processing chains.
6. Retention and deletion Account information: while the account exists and for 2 years after closure. Webchat history: while the account exists; after a conversation is deleted or an account is closed, related records are normally processed under system deletion rules within 30 days, unless needed for legal, audit, security, risk-control, or dispute purposes. Uploaded files and images: 30 days, or as processed by user deletion actions and system deletion rules. API request and response logs: 90 days. Billing, order, invoice, and financial records: at least 7 years, or as required by applicable legal, financial, or audit obligations. Risk-control, suspension, appeal, and security logs: 2 years. Backup deletion: rolling deletion from backups within 90 days after related data is deleted or an account is closed, unless needed for legal, audit, security, or dispute purposes.
7. Data security We use reasonable technical and organizational measures, including encrypted transport, access controls, permission isolation, log audits, automated masking, risk monitoring, and secure operations. Our internal management refers to ISO/IEC 27001 security-management methods; this does not mean that we hold that certification. Internet and AI services cannot be absolutely secure. Users must protect account passwords, API Keys, webhooks, server credentials, and payment credentials.
8. User rights Where permitted by applicable law, users may request access, correction, deletion, export, restriction of processing, or withdrawal of consent by emailing [email protected]. We may require identity verification and will process requests within 30 business days. If legal, billing, security, dispute, upstream-processing, or technical reasons prevent full compliance, we will explain why.
9. International transfers, minors, and updates StringRoute serves users globally. User data may be accessed, transferred, stored, or processed outside the user's location, including Hong Kong, upstream provider locations, cloud-provider locations, and other necessary regions. Our services are not directed to users under 18. A person under 18 must not register or use the services unless applicable law permits it, a guardian has consented, and the guardian accepts the related responsibility. We may update this policy when services, law, providers, or processing practices change. Material changes will be communicated through the website, dashboard, email, or another reasonable channel.