Privacy Policy

Last updated 2026-08-04. This is a plain-English summary of what we collect, why, and how to control it.

This document is a working draft. It accurately describes our current data practices but is not legal advice. Consult counsel before relying on it.

Who we are

ModelGates is operated by ModelGates LLC ("we", "us"). Reach us at privacy@modelgates.ai for any data-related question.

What we collect

  • Account info: email, name, hashed password, OAuth IDs (Google / GitHub if you sign in that way).
  • Billing info: Stripe customer ID, payment intent IDs, top-up history. Card numbers are never stored on our servers — Stripe holds them.
  • Phone verification: if you choose to verify a phone for a promotion, we store the verified number encrypted and a protected, deterministic phone fingerprint used to prevent duplicate claims. One-time passcodes are verified by Twilio and are never stored by ModelGates.
  • API usage data: per-request metadata (model, token counts, cost, latency, status). The first 500 characters of prompt and response are stored for support / abuse review (configurable).
  • Affiliate data: referral code you generated, who you referred, selected partner markup, USDT TRC20 wallet address, payout amounts and status, and transaction hashes recorded for completed payouts. Current affiliate payouts use USDT on the TRC20 network. The optional Stripe Express onboarding flow remains available for compatibility. If you choose it, we send your email and internal user ID to Stripe and store the Stripe Connect account ID, onboarding status, and onboarding completion time.
  • Operational logs: IP address, user agent, request timestamps for rate limiting, fraud detection, and incident response.

What we DON'T collect

  • Card numbers, CVCs, bank credentials.
  • Full prompt / response bodies (only first 500 chars by default).
  • Browser fingerprints. Google Ads and Microsoft Advertising UET measurement tags load only if you accept advertising measurement in the cookie banner.
  • Data from API requests routed to providers — we proxy, we don't archive.

How we use it

  • To provide the API service and bill you accurately.
  • To respond to support requests, including reading your prompt preview if you ask us about a specific call.
  • To detect abuse, fraud, and runaway billing.
  • To verify promotional eligibility and prevent duplicate promotion claims.
  • To send transactional email (receipts, low-balance alerts, security notifications).
  • If you explicitly opt in through onboarding, to send product updates and occasional ModelGates offers by email. You can withdraw this optional consent at any time.

Who we share with

We share data only with service providers necessary to operate ModelGates:

  • Upstream model providers(via OpenRouter): your prompts and the model's responses, in real time, to fulfill API requests.
  • Stripe — payment processing and optional Stripe Express onboarding. The legacy-compatible onboarding flow receives your email and internal user ID when you choose to start it.
  • TRON network — the payout wallet address and transaction data required to complete and verify USDT TRC20 affiliate payouts.
  • Resend — transactional email delivery.
  • Twilio — optional phone verification. Twilio receives the destination number and verification metadata needed to deliver and check an OTP. We use those messages only for verification, not SMS marketing.
  • Sentry (if enabled) — error monitoring; payloads are scrubbed of API keys and prompt content before transmission.
  • Google Ads and Microsoft Advertising — limited page-load, campaign-attribution, sign-up, and first-purchase measurement after you explicitly accept advertising measurement. Microsoft UET is governed by the Microsoft Privacy Statement.

We do not sell or rent user data. We share only the limited advertising measurement data described above, and only after consent.

How long we keep it

  • Account info: while your account is active + 30 days after deletion.
  • API request metadata: 180 days.
  • Billing records: 7 years (tax / accounting).
  • Stripe webhook event log: 30 days.
  • Operational logs: 90 days.
  • Promotion claim fingerprints may be retained after account deletion solely to prevent duplicate or abusive claims. They are protected deterministic values, not plaintext phone numbers, and are not included in analytics.

Your rights

Subject to applicable law (GDPR, CCPA, etc.), you can:

  • Request a copy of your data.
  • Request deletion of your account and associated data.
  • Export your transaction history at any time from /settings/credits.
  • Withdraw optional email marketing consent from your account. Withdrawal does not affect transactional email. Phone verification and delivery or checking of an OTP does not authorize SMS marketing.

Email privacy@modelgates.ai for any of the above. We respond within 30 days.

Cookies

Essential cookies: an Auth.js session cookie, your theme preference, the affiliate referral cookie (mg_ref) when you arrive via a referral link, and a campaign-attribution cookie (mg_utm) when you arrive via an ad link — used only to apply promo pricing to your account at sign-up. Advertising measurement (Google Ads and Microsoft Advertising UET) is off by default and activates only after you choose "Accept" in the cookie banner; choosing "Essential only" keeps it off. We never sell data or use it for third-party ad targeting.

International transfers

Our infrastructure is hosted in the United States. By using ModelGates from outside the US, you consent to your data being processed in the US under standard contractual safeguards.

Changes

We'll update the "Last updated" date at the top when this policy changes. Material changes (e.g., new categories of shared data) will be emailed to active users 30 days in advance.