OpenModex
Legal

Privacy Policy

Last updated: March 1, 2026

At OpenModex ("we," "us," or "our"), we are committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our unified AI API gateway platform, website, and related services (collectively, the "Service").

By accessing or using the Service, you agree to the collection and use of information in accordance with this policy. If you do not agree with the terms of this Privacy Policy, please do not access the Service.

1. Information We Collect

1.1 Account Information

When you create an account, we collect your name, email address, company name (if applicable), and authentication credentials. If you sign up using a third-party provider (e.g., Google, GitHub), we receive basic profile information from that provider.

1.2 Billing Information

When you subscribe to a paid plan, we collect billing details such as your payment method, billing address, and transaction history. Payment processing is handled by our third-party payment processor, and we do not store full credit card numbers on our servers.

1.3 API Usage Data

We collect metadata about your API usage, including request timestamps, model selections, token counts, response latency, error rates, and endpoint usage patterns. This data is used for billing, analytics, rate limiting, and service optimization.

1.4 Technical Data

We automatically collect certain technical information when you access our Service, including your IP address, browser type, operating system, device information, referring URLs, and pages viewed on our website.

2. How We Use Your Information

We use the information we collect to:

  • Provide, maintain, and improve the Service
  • Process transactions and send billing-related communications
  • Monitor API usage for rate limiting, abuse prevention, and capacity planning
  • Power our smart routing and cost optimization features
  • Provide analytics dashboards and usage insights
  • Send service-related announcements, security alerts, and support messages
  • Respond to your requests, comments, and questions
  • Detect, prevent, and address fraud, abuse, and technical issues
  • Comply with legal obligations and enforce our Terms of Service

3. Data Processing and Storage

We process and store your data on secure servers located in the United States and the European Union. We use industry-standard security measures, including encryption at rest and in transit, to protect your data.

Account data and usage metadata are retained for as long as your account is active and for a reasonable period after account closure for legal, business, and compliance purposes.

4. Third-Party AI Providers

As a unified AI API gateway, OpenModex routes your API requests to third-party AI model providers (e.g., OpenAI, Anthropic, Google, DeepSeek, Mistral). When we route your requests:

  • Your prompt and input data are transmitted to the selected AI provider for processing
  • Each provider processes the data according to their own privacy policies and data handling practices
  • We do not control how third-party providers handle the content of your API requests
  • If you use Bring Your Own Key (BYOK), your requests are sent directly using your provider credentials

We recommend reviewing the privacy policies of the AI providers you use through our platform. We select providers that maintain strong data protection standards, but we encourage you to evaluate each provider's policies independently.

5. API Request Data Retention

By default, we do not persistently store the content of your API requests (prompts and responses). Request content may be temporarily held in memory for processing and, if you have semantic caching enabled, cached responses may be stored for the duration specified in your caching configuration.

API usage metadata (timestamps, token counts, model used, latency, status codes) is retained for billing and analytics purposes. You can configure data retention settings from your dashboard.

6. Cookies and Tracking

We use cookies and similar tracking technologies on our website and dashboard to:

  • Essential cookies: Required for authentication, security, and basic site functionality
  • Analytics cookies: Help us understand how visitors interact with our website to improve user experience
  • Preference cookies: Remember your settings such as language and theme preferences

You can control cookie preferences through your browser settings. Disabling certain cookies may affect the functionality of the Service.

7. Your Rights

7.1 GDPR Rights (EEA/UK Residents)

If you are a resident of the European Economic Area or the United Kingdom, you have the following rights under the General Data Protection Regulation (GDPR):

  • Right of access: Request a copy of the personal data we hold about you
  • Right to rectification: Request correction of inaccurate personal data
  • Right to erasure: Request deletion of your personal data
  • Right to restrict processing: Request limitation of processing of your personal data
  • Right to data portability: Receive your data in a structured, machine-readable format
  • Right to object: Object to the processing of your personal data

7.2 CCPA Rights (California Residents)

If you are a California resident, you have rights under the California Consumer Privacy Act (CCPA), including the right to know what personal information we collect, the right to request deletion, the right to opt out of the sale of personal information, and the right to non-discrimination for exercising your privacy rights.

We do not sell your personal information. To exercise any of your rights, please contact us at privacy@openmodex.com.

8. Data Security

We implement robust security measures to protect your information, including:

  • Encryption of data in transit (TLS 1.3) and at rest (AES-256)
  • SOC 2 Type II certified infrastructure
  • Regular security audits and penetration testing
  • Role-based access control and least-privilege principles
  • Comprehensive audit logging and monitoring
  • Incident response procedures and breach notification protocols

While we strive to use commercially acceptable means to protect your personal data, no method of transmission over the Internet or method of electronic storage is 100% secure. We cannot guarantee absolute security.

9. International Data Transfers

Your information may be transferred to and processed in countries other than your country of residence. When we transfer data internationally, we ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) approved by the European Commission, and compliance with applicable data protection frameworks.

10. Children's Privacy

The Service is not intended for use by individuals under the age of 16. We do not knowingly collect personal information from children. If you become aware that a child has provided us with personal data, please contact us, and we will take steps to delete such information.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new Privacy Policy on this page, updating the "Last updated" date, and sending an email notification if the changes are significant. Your continued use of the Service after changes are posted constitutes your acceptance of the revised policy.

12. Contact Us

If you have any questions about this Privacy Policy or our data practices, please contact us:

  • Email: privacy@openmodex.com
  • General inquiries: hello@openmodex.com
  • Data Protection Officer: dpo@openmodex.com

For EU-related inquiries, you also have the right to lodge a complaint with your local data protection supervisory authority.