Skip to content
IQ Routing

Privacy Policy

Effective date: May 1, 2026

Last reviewed: September 17, 2026

1. Information We Collect

We collect the following types of information:

  • Account information: your email address and organization name provided during registration.
  • Usage data: API request metadata including timestamps, provider selections, response latencies, token counts and error rates, plus loop-detection metadata when enabled, as described in /docs/security.
  • Device and access data: IP address, browser type, and access timestamps when you use the dashboard.

2. Information We Do Not Collect

IQ Routing does not log the content of API requests or responses. Two short-term stores do hold content: the response cache keeps a copy of cacheable responses, with a numeric fingerprint (embedding) of the prompt used to match repeats, for up to seven days so a repeat request can be answered without calling the provider, and the stateful Responses API keeps conversation turns for up to 24 hours after the last turn. Payload logging, which would keep full prompts and completions, is off for every organization and is not an account setting today.

3. How We Use Your Information

We use collected information to:

  • Provide, operate, and maintain the Service.
  • Generate analytics and insights visible in your dashboard.
  • Monitor Service performance and detect abuse or security incidents.
  • Communicate with you about your account, updates, and support requests.
  • Improve the Service through aggregated, anonymized usage analysis.

4. Data Sharing

We do not sell your personal information. We may share information with:

  • AI providers: request content, which can include your prompt text, is transmitted to the upstream provider that serves your chosen model to fulfill the request. In addition, a short, truncated excerpt of each routed request is sent to OpenAI for model-tier routing classification on IQ Routing's own credentials, independent of the provider keys you configure. Provider-specific privacy policies apply to the data they receive; the full list is on our subprocessors page.
  • Service providers: third-party services that assist in operating the platform (e.g., hosting, authentication, billing, email delivery), bound by confidentiality obligations. The current list is published on our subprocessors page.
  • Legal requirements: when required by law, subpoena, or government request.

5. Data Retention

Retention windows differ by data class:

  • Account information: retained for the duration of your account.
  • Request metadata: timestamps, model and provider selections, token counts, latencies, and cost. These are kept for the life of your account rather than for a configurable window, because billing, budgets, and usage totals have to stay reconcilable long after the request they describe. Deleting your account, covered below, is what removes them.

    When loop detection is enabled, we also keep secret-key fingerprints, activity counts, loop flags and estimated wasted cost to detect agents stuck in repeated loops; our security page explains how long these are kept.

  • Routing detail: the free-text fields attached to a request, meaning provider error text, the list of routing attempts considered, and any reasoning recorded internally while routing the request. These are cleared once the retention window configured in your account settings passes. The numeric request record described above is not cleared with them.
  • Prompt and completion payloads: not logged. Cached responses, with a numeric fingerprint (embedding) of the prompt used to match repeats, are kept for up to seven days, and stateful conversation turns for up to 24 hours after the last turn, as described in Section 2.
  • Audit-log data: retained for 90 days or longer to support security, compliance, and chain-of-custody requirements.

Upon account deletion, we remove your personal information within 30 days, except where a longer retention period is required by law.

6. Data Security

We implement industry-standard security measures including encryption in transit (TLS 1.2+), encryption at rest for stored data, and access controls on internal systems. Provider API keys are encrypted at rest using authenticated encryption, and the key-vault reveal path uses AES-256-GCM envelope encryption. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.

7. PII Redaction
Pilot, by request

A per-org PII redaction setting can mask four kinds of identifier in message text before a request is sent to an upstream provider: email addresses, phone numbers, US Social Security numbers and payment card numbers. It is off for every organization by default, it cannot be switched on from the dashboard, and no customer has used it yet: if you need it, contact us and we will enable it for your organization and verify it with you. It does not scan tool-call arguments, attached documents or images, it is not a HIPAA Safe Harbor de-identification control, and it will not catch every identifier a prompt can carry. Treat upstream providers as recipients of whatever the setting does not mask. Do not send protected health information (PHI) through IQ Routing: IQ Routing is not a HIPAA business associate and does not sign a BAA. Send other regulated personal data only if your organization has a data processing addendum with us and its own controls in place.

7a. Sensitive Data

Several state privacy laws define a narrower category of sensitive data (for example, health information, precise geolocation, biometric data, and information about racial or ethnic origin, sexual orientation, or immigration status) that requires your opt-in consent before a controller processes it. Because request content is arbitrary text your team controls, IQ Routing does not screen it for these categories, and the PII redaction setting in Section 7 does not detect them either: it looks only for email addresses, phone numbers, Social Security numbers and card numbers. If your use of the Service involves sending sensitive data to upstream providers, your organization is responsible for obtaining any consent required from the individuals whose data is included and for confirming that doing so is consistent with your own obligations. The one exception is the truncated routing-classification excerpt described in Section 4, which IQ Routing itself transmits to OpenAI on its own credentials for every request; that excerpt is not screened for sensitive data either.

8. Cookies and Local Storage

The dashboard relies on a small set of first-party identifiers to keep you signed in, remember your preferences, and surface in-app announcements only once. We do not use third-party tracking cookies or advertising pixels. The identifiers we set fall into two categories, both first-party and strictly functional:

Essential identifiers (required for the Service to function):

  • Clerk session and client cookies (__session, __client, __client_uat, __clerk_db_jwt): first-party cookies set by Clerk, our authentication provider, to keep you signed in to the dashboard and protect sign-in against cross-site request forgery. Expire when your session ends or you sign out.
  • iq.active_org: HMAC-signed first-party cookie that records which organization you are currently viewing inside the dashboard. Required so the dashboard renders data for the right organization when you have access to more than one. Expires with your session.

Functional identifiers (improve the experience; persist in your browser):

  • iq-theme: remembers whether you selected the light or dark theme. Holds no personally identifiable information and is never transmitted to us.
  • iq-saved-filters-*: per-org saved filter sets you choose to save on the requests, audit, and alerts surfaces. Stored only in your browser; never transmitted to us.
  • Welcome-tour and developer-panels-tour completion flags: boolean markers that prevent the dashboard from re-showing onboarding overlays after you have completed them. Stored only in your browser.
  • Banner-dismiss flags (whats-new and seed-traffic-*): boolean markers per org that record which one-time banners you have dismissed. Stored only in your browser.
  • Setup-card and first-visit flags (iq.start_here_hidden and iq.first_access_seen): per-account and per-organization markers that record that you hid the setup steps or have already seen the first-visit introduction. First-party cookies sent only to our site; not used for tracking.

Error monitoring:

  • Sentry: a third-party error-monitoring service is loaded across the site, including pages you are not signed in to, to capture unhandled errors and performance diagnostics. It does not set advertising or cross-site tracking cookies, and it is configured with personal-data forwarding turned off (sendDefaultPii: false) and session replay disabled. It is listed as a subprocessor on our subprocessors page.

All identifiers above are first-party and either strictly essential to the Service or functional preferences you control through the dashboard. Beyond the error-monitoring service disclosed above, we do not load third-party advertising or cross-site tracking on the dashboard.

9. Your Rights

The data controller for the personal information described in this policy is George Avila, an individual doing business as IQ Routing. Depending on your jurisdiction, you may have the right to:

  • Access the personal information we hold about you.
  • Request correction of inaccurate information.
  • Request deletion of your personal information (right to erasure). Once your request is confirmed, the gateway emits a recorded erasure event and removes your personal information within 30 days, except where a longer retention period is required by law.
  • Object to or restrict certain processing of your information.
  • Export your data in a portable format.
  • Withdraw consent at any time, where processing is based on your consent.
  • Lodge a complaint with a supervisory authority (for individuals in the European Economic Area or the United Kingdom).

To exercise any of these rights, contact us at the address below.

We will respond to a request within 45 days of receipt, or notify you if we need an additional 45 days given the complexity or volume of the request. If we decline to act on your request, in whole or in part, you may appeal that decision by replying to our response with "Appeal" in the subject line; we will respond to an appeal within 60 days. If we deny your appeal, we will provide a way to contact the relevant state attorney general or other supervisory authority to submit a complaint.

You may designate an authorized agent to submit a request on your behalf. We will require the agent to provide proof of your written permission (or, where applicable, a power of attorney) to act for you, and we may separately verify your identity directly with you before completing the request.

9a. Legal Bases for Processing (GDPR)

Where the EU or UK General Data Protection Regulation applies, we rely on the following Article 6 legal bases, by purpose:

  • Performance of a contract (Art. 6(1)(b)) to provide, operate, and maintain the Service and to route your API requests.
  • Legitimate interests (Art. 6(1)(f)) to monitor Service performance, detect abuse and security incidents, and improve the Service through aggregated, anonymized analysis.
  • Legal obligation (Art. 6(1)(c)) to retain audit-log and billing records as required by law.
  • Consent (Art. 6(1)(a)) for any processing you opt into, such as enabling payload logging.

9b. California Privacy Rights (CCPA/CPRA)

In the past twelve months we have collected the following categories of personal information, as defined by the California Consumer Privacy Act: identifiers (such as your email address and IP address), commercial information (such as your subscription and billing records), internet or network activity (such as API request metadata and dashboard access logs), and inferences drawn from the foregoing to create a profile (such as the dashboard analytics and per-request routing classification described in Sections 3 and 4).

We do not sell or share your personal information as those terms are defined under California law, and we have not done so in the preceding twelve months. California residents may exercise their rights to know, delete, correct, and opt out without discriminatory treatment by contacting us at the address below.

Because we do not sell or share personal information, an opt-out-preference signal (such as Global Privacy Control) has no additional operative effect on our processing today. If that changes, we will detect and honor such signals as required by California, Colorado, and Connecticut regulations.

10. International Data Transfers

Your information may be processed in the United States or other countries where our service providers operate. We ensure appropriate safeguards are in place for any cross-border data transfers.

10a. Data Processing Addendum

A Data Processing Addendum (DPA) governing our processor obligations under GDPR Article 28 is available on request. Contact privacy@iq-routing.com to request a copy. A DPA is a different instrument from a data protection impact assessment; if your organization requires one for its own compliance before sending us data, contact the same address to discuss it.

11. Children's Privacy

The Service is not directed to individuals under the age of 16, and in the United States we do not knowingly collect personal information from children under 13 (COPPA). If we learn that we have collected information from a child below the applicable age, we will delete it promptly.

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page with a revised effective date. Continued use of the Service after changes constitutes acceptance of the revised policy.

13. Contact

For privacy-related inquiries, contact us at privacy@iq-routing.com.

George Avila, an individual doing business as IQ Routing
Contact us at privacy@iq-routing.com for privacy-related requests.