Privacy Policy
This Privacy Policy explains what personal data SwitchLLM ("we") collects when you use the Service, why we collect it, and what rights you have.
1. What we collect
Data you give us
- Account data: email address, password (stored only as a salted hash), and any display name you set.
- Billing data: top-up amounts, payment provider references, credit balance and transaction history.
- Support correspondence: the content of emails you send us.
Data generated by your use
- Request metadata: timestamp, model name, prompt tokens, completion tokens, reasoning tokens, latency, HTTP status, IP address, and the API key used.
- Error logs: stack traces and diagnostic data when a request fails.
What we do NOT store
We do not store the content of your prompts or the models' completions. Prompts and responses pass through our gateway in memory to be forwarded to the Upstream Provider, and are not written to disk or logs.
2. Why we use it
- To authenticate you and provide the Service.
- To meter usage and calculate charges.
- To detect abuse, fraud and security incidents.
- To respond to support requests.
- To send service notices (outages, policy changes, billing). We do not send marketing email unless you opt in.
3. Legal bases
Where GDPR applies, we rely on: performance of a contract (providing the Service), legitimate interests (security, abuse prevention, service integrity) and legal obligation (tax and accounting records).
4. Who we share it with
- Upstream Providers (DeepSeek, Zhipu AI, Moonshot AI): your prompts are transmitted to them to generate completions. Their handling is governed by their own privacy policies.
- Infrastructure providers: our servers and CDN (Cloudflare) process traffic on our behalf.
- Payment processors: when you top up, the payment provider receives the data needed to process the transaction. We never see your full card number.
- Authorities: where we are legally compelled to disclose.
We do not sell personal data. We do not share it for advertising.
5. Retention
- Request metadata: 90 days, then aggregated or deleted.
- Billing and transaction records: 7 years, as required for tax purposes.
- Account data: for the life of the account, then deleted within 30 days of closure.
- Error logs: 30 days.
6. Security
We use TLS for all traffic, hash passwords with a per-user salt, restrict database access, and keep our systems patched. API keys are stored in a form that allows verification without exposing the key itself. No system is perfectly secure; if you believe your account has been compromised, contact us immediately.
7. International transfers
Our servers are located in Hong Kong, and we use a global CDN. Your data may be processed outside your country of residence. Where required, we rely on appropriate safeguards for such transfers.
8. Your rights
Depending on your jurisdiction you may have the right to access, correct, delete, restrict or object to processing of your personal data, and to receive it in a portable format. Contact [email protected] to exercise these rights. We respond within 30 days.
9. Cookies
Our marketing site sets no tracking cookies. The console uses a single session cookie required for authentication. We do not use third-party analytics or advertising cookies.
10. Children
The Service is not directed at anyone under 18. We do not knowingly collect data from children.
11. Changes
We will post any changes here and update the date above. Material changes will be notified by email.
12. Contact
Data protection enquiries: [email protected]