Privacy Policy
Last updated: September 6, 2026
This policy explains what LokaRouter collects, why, and how your data is handled when you use the gateway and this website.
Data we collect
Account data: your email address, display name, country, and phone number (optional, editable) from the profile page, collected when you sign in with an email OTP or Google sign-in.
API keys: keys you create are stored only as irreversible hashes. The full key is shown once at creation and cannot be recovered by us.
Usage logs: for every gateway request we record the model, token counts, estimated cost, provider, and timestamp. Prompt and completion text is not stored by LokaRouter unless a provider error requires temporary diagnostics.
Billing data: top-ups are processed by our payment provider. We store the transaction reference and credit amount, never your card or bank credentials.
How we use data
To operate the gateway: authenticate requests, route them to providers, enforce rate limits and budgets, and record usage against your balance.
To communicate with you: sign-in codes, transactional receipts, and operational notices about your account. We do not send marketing email without your consent.
Third parties we rely on
Upstream AI providers: your prompts and completions are forwarded to the provider you (or our router) select so the request can be answered. Their handling of that content is governed by their own policies.
Infrastructure: Supabase (database), Vercel (hosting), Brevo (email delivery), Google (sign-in), and Midtrans (payments). Each only receives the data needed to perform its function.
Retention and deletion
Usage logs are kept while your account is active so invoices and per-key analytics remain accurate. Revoking an API key immediately stops new usage through it.
You can request account deletion at any time; we remove account data and delete keys, while keeping the minimum transaction records required by tax and accounting rules.
Security
API keys are hashed, traffic is encrypted in transit (TLS), and database access is restricted with row-level security. Bring-your-own-key secrets are encrypted at rest.
Changes and contact
When this policy changes materially we announce it on the site before it takes effect.
Questions about this document? Reach us at support@lokarouter.id.