Privacy Policy
Last updated: March 25, 2026
GateCtr is committed to protecting your privacy. This policy explains what data we collect, why we collect it, how we use it, and your rights. We built GateCtr on a simple principle: your API keys and your prompts are yours. We never sell your data, never train models on your content, and never share your keys with third parties.
1. Who We Are
GateCtr is an LLM middleware gateway. We sit between your application and LLM providers (OpenAI, Anthropic, Mistral, Gemini) to optimize, route, and enforce budgets on your API calls. GateCtr is operated by GateCtr SAS. For privacy inquiries, contact us at privacy@gatectr.com.
- Service β LLM middleware gateway β routing, budget enforcement, prompt optimization, analytics.
- Data controller β GateCtr SAS, reachable at privacy@gatectr.com.
- Scope β This policy applies to all users of gatectr.com, app.gatectr.com, and the GateCtr API.
2. Data We Collect
We collect only what is necessary to operate the service. We do not collect the content of your prompts or LLM responses.
- Account data β Email address, name, and authentication data provided when you sign up via Clerk (Google OAuth or email).
- Usage metadata β Token counts, request counts, model used, provider, latency, cost estimates, and timestamps. Never the content of prompts or responses.
- Provider keys β Your LLM API keys, stored AES-256 encrypted at rest. We never log, display, or transmit them in plaintext.
- Technical data β IP address, user agent, browser type, and request timestamps β used for security, abuse prevention, and analytics.
3. How We Use Your Data
We use your data exclusively to:
- Provide the service: route API calls, enforce budgets, compress prompts, and display analytics.
- Send transactional emails: account creation, budget alerts, onboarding completion, and billing events.
- Improve reliability: monitor errors, latency, and system health via Sentry and Vercel Analytics.
- Comply with legal obligations: respond to lawful requests from authorities when required.
4. Data Retention
We retain data for the minimum period necessary to provide the service.
| Data type | What it includes | Retention |
|---|---|---|
| Usage logs | Token counts, request counts, cost | 30 days (Free/Pro) Β· 90 days (Team) |
| Account data | Email, name, plan | Duration of account |
| Provider keys | Encrypted API keys | Until revoked by user |
| Audit logs | Security events, admin actions | 90 days (Team) Β· Unlimited (Enterprise) |
5. Third-Party Services
We use the following sub-processors to operate GateCtr. Each processes data under their own privacy policy and DPA.
- Clerk β Authentication and session management. Processes email and OAuth data.
- Stripe β Payment processing. Processes billing information and invoices.
- Neon β PostgreSQL database hosting (AWS us-east-1). Stores account and usage data.
- Upstash β Redis caching. Stores temporary session and rate-limit data.
- Sentry β Error monitoring. Receives anonymized stack traces and performance data.
- Vercel β Hosting and edge network. Processes all HTTP requests.
We do not share your data with LLM providers. Your API key is used directly from your infrastructure β GateCtr acts as a transparent proxy.
6. Your Rights
Depending on your jurisdiction, you have the following rights regarding your personal data:
- Right of access β request a copy of all data we hold about you.
- Right to rectification β correct inaccurate or incomplete data.
- Right to erasure β request deletion of your account and associated data.
- Right to portability β export your usage data in CSV format from the dashboard.
- Right to object β opt out of non-essential data processing.
To exercise any of these rights, email privacy@gatectr.com. We will respond within 30 days. Account deletion can also be initiated directly from Settings β Account.
7. Security
We implement industry-standard security measures: AES-256 encryption for API keys at rest, TLS 1.3 for all data in transit, multi-tenant isolation at the database level, role-based access control (RBAC) for team accounts, and regular security audits. We do not store LLM prompt content. In the event of a data breach affecting your personal data, we will notify you within 72 hours as required by applicable law.
8. International Transfers
GateCtr is hosted on Vercel and Neon infrastructure primarily in the United States (AWS us-east-1). If you are located in the European Economic Area (EEA), your data may be transferred to and processed in the United States. We rely on Standard Contractual Clauses (SCCs) approved by the European Commission for such transfers.
9. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email or by displaying a notice in the dashboard. The date at the top of this page reflects the most recent update. Continued use of GateCtr after changes constitutes acceptance of the updated policy.
Contact
Privacy inquiries
For questions, requests, or concerns about your personal data:
privacy@gatectr.com