Legal
Vulpy Gateway Privacy Policy
Effective date: September 3, 2026
This Privacy Policy describes how Vulpy, Inc. (Vulpy, we, us, or our) collects, uses, discloses, and otherwise processes personal information in connection with the Vulpy AI gateway and billing bridge, including model requests, usage metering, prepaid credits, payment flows, related APIs, and support (collectively, the Gateway).
Vulpy, Inc. is a Delaware corporation with its principal business address at 8 The Green, Ste D, Dover, DE 19901, United States. For the processing described in this policy, Vulpy is the controller of personal information we collect directly from Gateway users. This policy does not cover the privacy practices of third parties or services that we do not control.
1. Information we collect
The information we collect depends on how you use the Gateway and may include:
- Account and contact information — name, email address, account details, and communications with us.
- API keys and credentials — API keys you create or are issued, which are account-linked identifiers. You are responsible for keeping these secure.
- Billing and transaction information — payment status, billing email, transaction identifiers, prepaid credit balances, and limited card information made available by Stripe (such as the last four digits). Stripe processes payment-card information; Vulpy does not store full payment-card numbers on its systems.
- Gateway metadata — model or provider selected, request status, token and usage measurements, cache status, applicable pricing, timestamps, and technical diagnostics needed to route requests, meter usage, secure the Gateway, and resolve operational issues.
- Support, security, and operational information — support messages, security events, abuse reports, and service logs.
- Cookies and similar technologies — where used by a Gateway portal or related website, as described in the Cookie Policy.
Vulpy does not retain prompts or model outputs.
2. Requests sent to underlying providers
The Gateway forwards requests to third-party language-model providers according to the model or provider you select or configure. This necessarily involves sending the prompt, model parameters, and related technical information to the selected provider and receiving an output from that provider.
Vulpy seeks to use providers that do not retain prompt or output content. Some providers may retain prompts or outputs under their own policies. To Vulpy’s knowledge, no provider trains on prompts or outputs submitted through or processed by the Gateway. Provider practices may change, and Vulpy does not control third-party providers or their systems.
You should not submit payment-card data, access credentials, secrets, or sensitive personal information in a prompt unless the service expressly requires it and you have determined that doing so is lawful and appropriate.
3. How we use information
We use personal information and Gateway metadata to:
- create and administer accounts;
- route requests and return outputs;
- measure usage and apply prepaid credits;
- process payments;
- provide support;
- detect, prevent, and investigate fraud, abuse, security incidents, and technical problems;
- maintain and operate the Gateway using Gateway metadata and operational information — this does not include retained prompts or model outputs and does not include using your data to train language models;
- communicate with you about your account, transactions, and service changes;
- comply with law; and
- establish, exercise, or defend legal claims.
We do not use prompts or model outputs to train models.
4. How we disclose information
We disclose personal information and Gateway metadata to service providers that process information on our behalf to provide the Gateway, including payment processors, hosting and infrastructure providers, email providers, security and logging providers, support providers, and the third-party language-model provider selected or configured for a request.
Stripe processes payments made through the Gateway. Stripe’s processing of payment information is governed by its own privacy notice.
We may also disclose information where we reasonably believe disclosure is necessary to comply with law or legal process; protect the rights, property, or safety of Vulpy, our users, or the public; prevent fraud or abuse; enforce our agreements; or facilitate a merger, acquisition, financing, reorganisation, or sale of assets.
We do not sell personal information for money, and we do not share personal information for cross-context behavioural advertising.
5. Caching, usage, and credits
We process usage and billing metadata to measure and charge for Gateway requests. Provider-cached input is billed at the applicable cached-input rate. Cached input is billable; it is not free.
6. Retention
Vulpy does not retain prompts or model outputs. We retain other information only as long as reasonably necessary:
- Gateway metadata (request logs, usage records, billing records) — typically no longer than 3 years, or as required to resolve billing disputes, meet legal and accounting obligations, and maintain security.
- Account and billing information — retained for the life of the account and for a reasonable period after closure to meet legal, tax, and accounting obligations.
- Support and security information — retained as long as reasonably necessary to resolve the matter and related issues.
When information is no longer needed, we delete it, anonymise it, or aggregate it. We may retain information for longer where required or permitted by law.
7. Security
We use reasonable technical and organisational measures designed to protect personal information against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
8. International processing
Vulpy is based in the United States. We and our service providers, including underlying language-model providers, may process personal information in the United States and other countries where we or they operate. Those countries may have data-protection rules different from those in your jurisdiction. Where required, we use appropriate safeguards or lawful transfer mechanisms, including Standard Contractual Clauses for transfers from the EEA or UK.
9. Your privacy choices and rights
Depending on where you live, you may have rights to access, correct, delete, or port your personal information; to object to or restrict certain processing; to withdraw consent where processing is based on consent; or to complain to a privacy regulator.
To make a request, email privacy@vulpy.io. We may need to verify your identity before responding. We will respond within one month of receiving a verified request, or within any shorter period required by applicable law. We will not discriminate against you for exercising privacy rights available under applicable law.
If you receive marketing email from us, you may opt out by following the unsubscribe instructions in the email or by contacting us at privacy@vulpy.io.
If you are in the EEA, UK, or Switzerland and believe we have not handled your personal information in accordance with applicable law, you have the right to lodge a complaint with a supervisory authority in your jurisdiction.
10. Children
The Gateway is not directed to children under 13 (or a higher age where required by local law), and we do not knowingly collect personal information from children below that age. If you believe a child has provided personal information to us, contact us at privacy@vulpy.io and we will take appropriate steps to delete it.
11. Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will post the updated version and revise the effective date. For material changes, we will provide advance notice where required by law.
12. Contact
For privacy questions or requests, contact privacy@vulpy.io.
Postal address: Vulpy, Inc., 8 The Green, Ste D, Dover, DE 19901, United States.
Related: Gateway Terms of Use · Vulpy Privacy Policy · Vulpy Terms of Use