Privacy Policy

Last updated: August 21, 2026

1. Scope

This notice explains what personal information we collect when you use the Rhodes API and portal, why, who we share it with, and how long we keep it.

It covers our customers — the developers and companies who hold an account. For data about your own end users, you are the controller and we are a processor.

2. What We Collect

Account Information

  • Your email address
  • Authentication identifiers from our identity provider
  • Stripe customer ID (we do not store card numbers)
  • Account status (active or suspended)
  • Signup IP address (to enforce trial credit limits)
  • Account creation and activity timestamps

Credit Records

One record per credit movement: the amount, the type (purchase, trial, refund, adjustment), the Stripe event identifier, and a timestamp. This table is append-only for money integrity.

Usage Metadata

Per-request records containing: timestamp, model name, token counts, cost, and your customer identifier. These records do not contain your prompts or the model's responses.

What We Do Not Store

  • Card numbers or payment instrument data (Stripe holds these)
  • Passwords (authentication is handled by our identity provider)
  • API key secrets in cleartext (shown once at creation, never stored)
  • Prompt or response content (see section 4)

3. Who We Share It With

Category Purpose Data Shared
Identity provider (Auth0) Authentication Email, login metadata
Payment processor (Stripe) Card payments Email, payment details, account ID
Cloud hosting (AWS) Infrastructure All data as hosting layer
Email provider (Resend) Service emails Email address, message content
Model providers Generate output Prompt content, responses

Important Note

Model providers are described as a category rather than individually. This is deliberate: our model names are brand-neutral and we do not disclose which provider serves a request. A named sub-processor list is available on request under confidentiality agreement.

We may disclose information where required by law, to enforce our terms, to investigate fraud or abuse, or in connection with a corporate transaction. We do not sell personal information and we do not share it for advertising.

4. Prompts and Responses — The Precise Position

We do not retain the content of your requests or the model's responses. The gateway's per-request log records metadata only — timestamp, model, token counts, cost, and customer identifier. Storing prompt and response content is not enabled in our configuration.

Your prompts are transmitted. To serve a request, the full content is sent to the third-party model-hosting provider that fulfills it, and the response comes back through us to you. This is unavoidable — it is how the product works.

The providers have their own retention. What a provider does with a request it receives is governed by that provider's own terms and retention practices, not by ours.

What This Means

Your prompts pass through us and are not kept by us. They are sent to whichever model host serves the request, and that host has its own policy. Do not send data through the API that you would not be willing to send to a third-party model provider — and do not send regulated data at all.

5. Why We Use Your Data

  • Providing the Service: Account management, API keys, usage tracking
  • Billing and metering: Credit tracking, usage records, payment processing
  • Fraud prevention: Signup IP tracking, trial credit limits, rate limiting
  • Communications: Low credit warnings, service notifications
  • Security and compliance: Logs, metrics, incident response

6. How Long We Keep It

Data Type Retention Period
Account records Life of account + 12 months
Credit records 7 years (financial records)
Usage metadata 13 months
Server logs 30 days
Signup IP address 12 months
Prompt/response content Not retained

7. Security

We implement the following security measures:

  • TLS encryption in transit (TLS 1.2/1.3)
  • Database and cache encryption at rest
  • API key secrets never stored in cleartext
  • Secret redaction in logs
  • Hard prepaid spend cap enforced before dispatch
  • Per-key and per-IP rate limits
  • Token-based authentication with RS256 verification
  • Encrypted backups with point-in-time recovery
  • Server-side only portal (no secrets in browser)

We are not SOC 2 audited, not ISO 27001 certified, and not HIPAA compliant. No system is perfectly secure. We cannot guarantee the security of information you transmit to us.

8. Your Choices and Rights

You can view your account details, balance, credit history, usage, and keys in the portal at any time, and you can revoke a key yourself.

Service emails (low credit, credit exhausted, credit added) cannot be switched off while the account is active. We send no marketing email.

Depending on where you live, you may have rights to access, correct, delete, or port your personal information, and to appeal a refusal. Contact us at privacy@rhodes.ai to exercise these rights.

9. Data You Should Not Send Us

Do not send us, or send through the API, special-category or regulated data — including protected health information, payment card data, government identifiers, or children's data. We are not built or certified for it, and prompts are transmitted to third-party providers.

10. Changes to This Policy

We may update this policy from time to time. We will notify you of material changes by email or through the Service. Continued use after changes constitutes acceptance.

Questions or Concerns?

If you have questions about this Privacy Policy or want to exercise your rights, contact us: