Privacy Policy
The least we can know about you.
Last updated: July 16, 2026
The short version: no email, no name, no phone, no KYC, no ad trackers. Your account is a username and an internal ID. Prompts and responses pass through to the model provider and are not written to our logs. You can delete everything by writing to support@wasd.digital.
What we refuse to collect
ShadowRouter (“we”) is built so that we hold as little about you as technically possible:
- No email, no phone, no real name. Registration is a username and a password. An email can be added voluntarily, only if you want password recovery.
- No identity verification (KYC). We never ask for documents.
- No advertising or analytics trackers. No third-party ad cookies, no fingerprinting, no selling of data — there is nothing to sell.
- No prompt or response contents in our logs. Our metering records token counts, model names, timestamps and latency — not what you said.
What we do store, and why
- Account: your username, a hash of your password, and an internal account ID. Kept by our identity provider (Logto) and used to map your balance and API keys.
- Balance and usage counters: your prepaid balance, per-request token counts, model names and timestamps — the minimum needed to meter a prepaid service.
- Payment records: amount, currency, payment ID and status of each top-up, coming from our payment processor. Crypto transactions are public on their blockchains by nature; we never see or store a card, bank account or billing address — there are none.
- Web chat history: conversations in the web chat are stored so you can come back to them, and you can delete any conversation yourself at any time. If you use the API instead, nothing conversational is stored at all.
- Support correspondence: if you write to us, we keep the thread for as long as it takes to help you.
Cookies
We use first-party session cookies to keep you signed in. That is all. No tracking cookies, no third-party advertising cookies.
Who touches your data (subprocessors)
Running the service involves a small set of vendors, each seeing only what their job requires:
- Model providers (OpenAI, Google, Anthropic, xAI, DeepSeek — depending on the model you pick): receive your prompts to generate responses, under their API terms. Major providers state that API data is not used to train their models. Requests are sent from our servers with our credentials — providers see our account, not yours.
- NOWPayments: processes crypto top-ups (non-custodial). Sees the transaction, not your identity.
- Logto: authentication (username, password hash, internal ID).
- Railway, Vercel, MongoDB Atlas, Supabase: infrastructure hosting our services and databases. Transient network logs (such as IP addresses in standard web-server logs) may exist at the infrastructure level; we do not build profiles from them.
When we would disclose anything
Only if legally compelled by a valid order applicable to us — and the honest answer to most requests would be that we hold no identifying information to give. We do not sell or share data with advertisers, ever.
Retention and deletion
- Account data lives for as long as your account does.
- Chat conversations you delete are removed from the live database immediately.
- Payment ledger records are kept for accounting.
- Full account deletion — keys, balance, chat history, identity, everywhere — is available on request: write to support@wasd.digital from a message that proves control of the account (a self-serve button is on the way).
Your rights
Wherever you are, we apply the same rule: you can ask what we hold about you (little), get a copy of it, or have it deleted. One email, no forms.
Changes
If this policy changes in a way that matters, we will say so on the site before it takes effect. The current version always lives at this address.
Contact
Questions, requests, deletions: support@wasd.digital.
Adapted from the Basecamp open-source policies / CC BY 4.0. This document is likewise shared under CC BY 4.0.