1. Introduction
AltLLM ("we", "our", "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our services.
By using AltLLM, you consent to the data practices described in this policy.
2. Data Collection
2.1 Information You Provide
- Account Information: Email address and name from Google OAuth authentication
- Payment Information: Processed securely by Stripe; we do not store full card numbers
- API Keys: Names and metadata (keys are hashed)
2.2 Information Collected Automatically
- Usage Data: API request counts, token usage, model selections, timestamps
- Technical Data: IP address, browser type, device information
- Cookies: Session management and authentication tokens
2.3 Information We Do NOT Collect
- Prompts and Completions: We do not log or store the content of your API requests or AI responses
- Conversation History: Chat conversations are not stored on our servers (Open WebUI may store locally)
3. Data Usage
We use your information to:
- Provide and maintain the AltLLM service
- Process payments and manage billing
- Authenticate users and secure accounts
- Track usage for billing and rate limiting
- Monitor and improve service performance
- Send transactional emails (receipts, alerts)
- Detect and prevent fraud or abuse
- Comply with legal obligations
4. Data Retention
- Account Data: Retained while your account is active, deleted within 30 days of account closure
- Usage Data: Aggregated usage statistics retained for 90 days
- Billing Records: Retained for 7 years for legal and tax compliance
- Audit Logs: Administrative action logs retained for 1 year
5. Data Sharing
We share data only with:
- Service Providers: Stripe (payments), Google (authentication), OpenRouter (LLM providers)
- Legal Requirements: When required by law, subpoena, or court order
- Business Transfers: In connection with a merger, acquisition, or asset sale
We do not sell your personal information to third parties.
6. Your Rights (GDPR)
If you are in the European Economic Area (EEA), you have the following rights:
- Right to Access: Request a copy of your personal data
- Right to Rectification: Request correction of inaccurate data
- Right to Erasure: Request deletion of your data ("right to be forgotten")
- Right to Restriction: Request limitation of data processing
- Right to Portability: Receive your data in a structured, machine-readable format
- Right to Object: Object to processing based on legitimate interests
- Right to Withdraw Consent: Withdraw consent at any time
To exercise these rights, contact us at privacy@altllm.ai
7. Legal Basis for Processing
We process your data based on:
- Contract Performance: To provide services you requested
- Legitimate Interests: To improve our services, prevent fraud, and ensure security
- Legal Obligations: To comply with tax and accounting requirements
- Consent: For optional features like marketing communications
8. Data Security
We implement appropriate security measures including:
- HTTPS encryption for all communications
- Bcrypt hashing for API keys
- Secure, httpOnly cookies for sessions
- Regular security audits and updates
- Access controls and authentication
- Database encryption at rest
9. Google OAuth
When you sign in with Google:
- We receive your email address and basic profile information
- We do not access your Google Drive, contacts, or other data
- You can revoke access at any time through Google Account settings
- Our use of Google data complies with Google API Services User Data Policy
10. Cookies
We use cookies for:
- Essential Cookies: Authentication and session management (required)
- Preference Cookies: Theme settings and UI preferences
We do not use tracking or advertising cookies.
11. International Data Transfers
Your data may be processed in countries outside your residence. When we transfer data internationally, we ensure appropriate safeguards are in place, including Standard Contractual Clauses where required.
12. Children's Privacy
AltLLM is not intended for users under 18 years of age. We do not knowingly collect personal information from children. If we learn we have collected data from a child, we will delete it promptly.
13. Changes to This Policy
We may update this Privacy Policy periodically. We will notify you of material changes via email or through the portal. Your continued use of the service after changes constitutes acceptance.
14. Contact Us
For privacy-related questions or to exercise your rights:
- Email: privacy@altllm.ai
- Data Protection Officer: dpo@altllm.ai