AI Mux Privacy Policy
Last updated September 20, 2026
How AI Mux processes account information, usage records and content retained for security auditing, risk handling and troubleshooting.
Scope and privacy contact
This policy covers AI Mux website, account, API gateway and support data processing. Contact [email protected] for privacy questions and requests. It describes AI Mux processing; external services also have their own policies. This page does not claim that every listed future safety feature is already available.
Request metadata
We record operational metadata needed to meter and protect the service, including model, service tier, token counts, latency, cost, timestamp and request status. Request content is sent to the selected upstream provider to fulfill the call. Some content may also be retained for the purposes described below; our records are not limited to metadata.
Security auditing and risk prevention
To identify misuse and security risks and investigate failures, AI Mux may retain portions of requests, model responses and related technical records. Depending on the request and audit scope, this may include conversation text, tool-call data and attachments actually received by the gateway. These records may contain personal or other sensitive information you submit. Their use is limited to necessary security auditing, risk handling and troubleshooting, with access restricted to authorized personnel. Do not submit passwords, API keys or sensitive personal information unrelated to the service.
Audit scope and access
Content recording depends on the applicable audit configuration and may be reduced or disabled by the operator. Disabling future recording does not automatically delete existing audit records or stop the processing of content needed to fulfill a request. Content recording is distinct from automated safety blocking, which is not yet fully deployed. To ask about your audit data or request its deletion, contact [email protected]. We may need to verify your identity before acting on a request.
Account data
We keep the minimum needed to run your account: your email for sign-in and recovery, an optional display name, invite relationships, prepaid balance and usage totals. We do not sell your data or share it for advertising.
Support and payment records
We process messages you send to support and the account, balance and transaction information needed to resolve them. Do not send passwords or payment-card secrets in support messages. For purchases through Waffo Pancake, payment details submitted at checkout are processed by Waffo and its payment service providers under their policies. AI Mux receives the order and payment-status information needed to credit your account, reconcile payments and assist with refunds. Waffo acts as an independent controller for the payment, billing, tax, fraud-prevention, refund and transaction data it processes as Merchant of Record; AI Mux remains responsible for account and service data it processes independently. See Waffo’s privacy policy at https://www.waffo.ai/en/privacy.
Processing purposes
We process data to provide requested services, authenticate accounts, meter usage, answer support requests and resolve billing issues. Security auditing is used to identify misuse and investigate incidents. Depending on applicable law, the basis is performance of our agreement with you, a legal obligation, or a legitimate interest balanced against your rights; where consent is required, we must obtain it. Merely using the service is not blanket consent to unrelated processing. We do not use retained audit content to train our own AI models.
Google Sign-In
When you choose to sign in with Google, AI Mux may receive your Google account identifier, email address, name, and profile picture through the openid, email, and profile permissions. We use this information only to create and authenticate your AI Mux account, maintain account security, display basic profile information, and provide customer support. AI Mux does not access your Gmail messages, Google Drive files, Google Calendar, contacts, or Google account password. We do not sell Google user data or use it for advertising.
Technical and security data
We may process IP address, session identifiers, basic device or browser information, and security events to authenticate requests, prevent abuse, investigate incidents and keep the service reliable.
Upstream and infrastructure providers
Your requests are fulfilled by third-party AI model providers. Their handling of request content is governed by their own policies. We send only what is needed to complete the call. Hosting, email and infrastructure providers may process the minimum account or technical data needed to provide their services.
Cookies and local storage
We use a session cookie to keep you signed in and local storage for preferences such as theme and language. We do not use third-party advertising or tracking cookies.
Website analytics and international processing
The website includes Cloudflare Web Analytics for website performance and visit statistics, subject to its own privacy policy at https://www.cloudflare.com/privacypolicy/. AI requests may be routed to third-party model providers or compatible API intermediaries. Infrastructure and providers may process data in countries different from yours. This does not imply that every provider has identical retention practices. Contact [email protected] for information about applicable providers and transfer safeguards; we do not claim a certification or specific cross-border agreement that has not been established.
Retention
Account data is kept while your account is active and for up to 90 days after closure. Usage and security metadata may be retained for up to 12 months for accounting, reliability and abuse prevention, then deleted or anonymised unless a longer period is required to resolve an incident or comply with law.
Content audit retention
Conversation audit content is distinct from usage metadata. We limit its retention to what is necessary for security auditing, risk handling and troubleshooting, subject to applicable legal preservation requirements. Contact [email protected] for the retention period applicable to your records or to request deletion. We do not represent that disabling auditing immediately erases existing records or that a fixed automatic deletion period has been implemented for all audit content.
Requests and contact
You may ask to access, correct or delete your account data by contacting [email protected]. We may retain limited records where reasonably necessary for security, fraud prevention, dispute resolution or legal compliance.
Additional rights, security and minors
Where applicable law provides these rights, you may request access, correction, deletion, portability or restriction of processing, object to processing, withdraw consent, or complain to a data protection authority. We handle requests within the applicable legal period and may verify identity without requesting unnecessary sensitive information. No online system can promise absolute security; we will respond to personal-data incidents and provide legally required notifications. The service is intended for adults aged 18 or over. Contact [email protected] if you believe a minor has supplied personal data so we can investigate and take appropriate action.
Changes
This policy may be updated from time to time. The date above will change when a new version is published.