Privacy Policy
Last updated: 13 July 2026
This Privacy Policy explains how Sumplus, a company organized in the British Virgin Islands ("Sumplus", "we", "us", or "our"), handles personal data in connection with SafeRouter, a confidential-computing LLM API gateway available at https://router.sumplus.xyz (the "Service"). This Privacy Policy is incorporated into and should be read together with the SafeRouter Terms of Service. Where the Service processes personal data on behalf of a Customer, the SafeRouter Data Processing Addendum also applies. Capitalized terms not defined here have the meanings given in the Terms of Service.
1. Overview of Our Approach
The Service runs inside a hardware Trusted Execution Environment (AMD SEV-SNP) with remote attestation, and Customers can cryptographically verify which build is running. The Service records a cryptographic hash of each API call into an append-only transparency log and periodically anchors a Merkle-tree root to a public transparency log (Sigstore Rekor). The transparency records contain hashes and call metadata and do not contain the plaintext content of prompts or completions.
2. Categories of Data We Process
We process the following categories of data:
Account data. Information used to create and authenticate your account, which may include your email address, an OAuth identifier (such as a Google or GitHub identifier), or a cryptocurrency wallet address used as a login credential. Passwords, where used, are stored only in hashed form.
Usage metadata. Records generated when you use the Service, including timestamps, model name, token or unit counts, computed cost, the Upstream Provider, and latency.
Payment metadata. Information related to Credit top-ups. Cryptocurrency payments are handled by a third-party payment processor, and we receive confirmation and reconciliation information rather than full payment instrument details.
Prompt and completion content. The transient prompt and completion content needed to route a request to an Upstream Provider and return the result to you. This content passes through the Service to fulfill your request. The transparency log stores only cryptographic hashes and call metadata for such calls, not the plaintext content.
3. How We Use Data
We use the categories of data described above to:
- (a) provide, operate, secure, and maintain the Service;
- (b) route requests to Upstream Providers and return results to you;
- (c) meter usage, compute costs, and manage Credits and billing;
- (d) authenticate accounts and prevent fraud, abuse, and unauthorized access;
- (e) generate and anchor the append-only transparency log and support cryptographic verification; and
- (f) communicate with you about your account and the Service, and comply with legal obligations.
4. Prompt and Completion Content
To fulfill a request, your prompt is transmitted to the selected Upstream Provider, and the Upstream Provider's output is returned to you. Prompt and completion content is processed transiently for routing. The Service records only a cryptographic hash of each call together with call metadata in the transparency log. The plaintext content of prompts and completions is not recorded in the transparency log. Your Content may be subject to the data handling practices of the applicable Upstream Provider once transmitted to fulfill your request.
5. Sub-Processors and Third Parties
We engage service providers, described here by role, to help provide the Service:
- third-party AI model providers, which fulfill inference requests (Upstream Providers);
- a cloud hosting provider located in the United States (AWS, region us-east-2);
- a cryptocurrency payment processor, which handles Credit top-ups; and
- a transactional email provider, which delivers account-related email.
A current list of sub-processors by role is maintained in the Data Processing Addendum.
6. International Transfers
The Service is operated by an entity organized in the British Virgin Islands and hosted with a cloud provider located in the United States. Upstream Providers and other sub-processors may process data in various locations. By using the Service, you understand that your data may be transferred to and processed in jurisdictions other than your own. We take steps to ensure that such processing is subject to appropriate protections consistent with this Privacy Policy and the Data Processing Addendum.
7. Data Retention
We retain account data and usage metadata for as long as your account is active and as needed to provide the Service, meter usage, maintain billing and Credit records, comply with legal obligations, and resolve disputes. Transparency log records consist of hashes and call metadata and are retained as part of the append-only log, including roots anchored to the public transparency log. Prompt and completion content is processed transiently to route requests and is not retained by the Service as plaintext in the transparency log.
8. Your Rights
You may request access to, deletion of, or export of your account data by contacting us at support@sumplus.xyz. We will respond consistent with applicable law. Please note that certain records, including hashed transparency log entries and anchored roots, are part of an append-only, cryptographically verifiable log and, by design, cannot be altered or removed. Deletion of account data does not require or result in alteration of previously recorded hashes, which do not contain plaintext content.
9. Security
We use technical and organizational measures designed to protect data, including hardware Trusted Execution Environment isolation with remote attestation, hashing of call records, argon2 password hashing, Secure session cookies, and encryption of data in transit. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
10. Children
The Service is not directed to children and is intended for developers and businesses. We do not knowingly collect personal data from children.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will post the updated version and revise the "Last updated" reference. Where changes are material, we will provide reasonable notice through the Service or by email.
12. Contact
For privacy questions and requests, including access, deletion, or export of your account data, contact us at support@sumplus.xyz.