Skip to content

Last updated: July 2026

1. Roles

When customers send traffic through the gateway, Smouter acts as a processor on behalf of the customer (controller). Upstream model providers — selected by your routing configuration — act as sub-processors.

2. Categories of data

  • Prompts and completions. Forwarded to the chosen provider to fulfill the request. Held only as long as needed to serve the response and (where enabled) to satisfy a cache hit on a later identical request.
  • Usage metadata. Model name, token counts, latency, routing decision, customer key. Retained for billing, savings reporting, and abuse detection.
  • Account data. Email, organization name, and billing details for the account holder.

3. Retention

  • Prompt/response bodies: short-lived by default — sufficient to serve the request and a configurable cache window. Customers can disable caching per-key or per-request.
  • Usage metadata: retained for the life of the account plus a standard tail for tax and audit purposes.
  • Account data: retained while the account is active, then deleted on request.

4. Sub-processors

The current shortlist (subject to change as the gateway opens up):

  • Model providers — OpenAI, Anthropic, Google, and others as added. Each call routes to exactly one provider.
  • Hosting & CDN — Vercel.
  • Payments — to be confirmed before the first paid invoice; we will publish the choice here.

5. International transfers

Requests are routed to the upstream provider's region of choice. Where applicable, standard contractual clauses will govern transfers out of the EEA / UK. The full agreement will be available before the gateway opens to paid customers.

6. Contact

For a DPA, sub-processor list, or anything else, privacy@smouter.ai.