Privacy Policy
Effective October 2, 2026 · Last updated October 2, 2026
AutoRouter is provided by Fractal Works, Inc. ("Fractal Works," "we," "us," or "our"). This Privacy Policy explains what information we collect when you use AutoRouter's websites (including autorouter.com and app.autorouter.com), desktop app, and API (together, the "Service"), how we use and share it, and the choices you have. It is part of our Terms of Service.
The short version
- AutoRouter sits between your agent app, such as Codex or Claude Code, and the AI models that answer it. Your prompts, code, and other request content pass through our servers so we can choose a model and deliver the request. We don't keep that content in our databases.
- To choose a model, we send your latest message and your routing settings to our routing provider. The model provider that handles the request receives the full request.
- When a request uses your ChatGPT or Claude plan, your sign-in for that plan passes through our servers to that provider. We don't store it.
- We keep account, settings, routing, usage, and billing records, not your conversations.
- Our desktop app reads some information on your Mac, such as your agent apps' local history and, if you allow it, window titles and visible terminal text. That information stays on your Mac.
- We don't sell your personal information, use it for advertising, or use your content to train AI models.
The rest of this policy explains each point in detail.
1. Information we collect
Information you provide
- Account information. Your name, email address, sign-in method, sign-in sessions, and the Macs where you've installed the desktop app. You can sign in with an emailed code or with a Google, GitHub, Apple, or Microsoft account. That provider shares your name, email address, an account identifier, and basic profile information with us through WorkOS, our authentication provider. We don't receive your password for those accounts.
- Invitations and referrals. Invite codes you redeem, who invited you, who redeemed your invite code, and any referral rewards.
- Routing settings. Your routing strategy, rules, and any instructions you write. Your instructions are sent to our routing provider when it chooses a model, so don't include personal or confidential information in them.
- Payment information. When you buy credits, Stripe collects your payment details. We receive the purchase amount, payment and refund status, and Stripe's transaction references. We don't receive or store your full card number.
- Communications. Messages, feedback, and support requests you send us, including in community channels such as our Slack.
Information created when you use the Service
- AI request content. Your agent app decides what each request contains. Requests typically include your prompts, instructions, conversation history, code, file contents, images, tool calls and their results, and the model's responses. Agent apps can read files in your workspace, so requests can include anything in those files, including secrets such as API keys. Don't put passwords or other unrelated secrets in prompts. This content passes through our servers while a request is processed. We don't store it in our databases, except as described under diagnostic logs below.
- Routing and usage records. For each request: which agent app sent it, session and turn identifiers, the model requested and the model chosen, a short category describing the type of work, timing, outcome, token counts, cost, and whether it used your subscription or your credits. These records power your history, usage, and billing.
- Subscription status. When AutoRouter chooses a model automatically, it may use your provider credential to check how much of your ChatGPT or Claude plan allowance remains, such as the percentage left and when it resets. We store these readings with your usage records.
- Credentials. Codex and Claude Code include your OpenAI or Anthropic sign-in credential with their requests. We pass it only to the provider that issued it, use it to check your plan allowance, and don't store it. AutoRouter also issues an installation credential that connects your agent apps to your account. We store only a one-way hash of it.
- Device and technical information. IP address and approximate location derived from it, browser and operating system, app version and build, installation and request identifiers, timestamps, performance measurements, error reports, and crash reports.
- Diagnostic logs. We log information about each request, such as identifiers, the model, token counts, timing, and outcome, without the request content. During our alpha, when a provider returns an error, we keep its complete error response in our logs. If a provider repeats part of your request in an error, such as your prompt, code, or personal information, that content will be in our logs, and we don't promise that it's redacted. Request headers and successful responses aren't added to these error logs. Our team and our infrastructure and monitoring providers can access these logs to troubleshoot problems.
2. Information processed on your Mac
The desktop app uses some information on your Mac to connect your agent apps and show your activity. Except where noted below, this information stays on your Mac.
-
Agent app settings. When you connect an agent app,
the desktop app updates its settings (for example, Codex's
config.tomland Claude Code'ssettings.json) so it sends requests to AutoRouter, and saves a copy of your previous settings. These settings include your installation credential. - Local activity. The app reads your agent apps' local session history and transcripts to show your sessions, prompts, responses, and routing decisions. Transcript contents aren't uploaded.
- Accessibility (optional). If you grant Accessibility access, the app detects which agent session is in front so it can stay attached to it. It reads the window title and address of supported agent apps and, in supported terminals (Terminal, iTerm2, and Ghostty), a limited amount of visible text to find the session identifier. This happens on your Mac, and the text isn't stored or uploaded.
- Screen Recording (optional). If you turn on the "Match app" appearance for an app that requires it, the desktop app samples a small strip of that window's title bar to match its colors. The sample is processed in memory and isn't stored or uploaded.
- Claude Code prompts. AutoRouter adds a hook to Claude Code that notifies our servers when you submit a prompt, so the next request is routed as a new turn. The notification includes the prompt and session details, such as the project folder. We use it only to identify the turn and don't store the prompt text.
You can turn off Accessibility or Screen Recording access at any time in macOS System Settings under Privacy & Security.
3. Cookies, local storage, and analytics
- Essential cookies. app.autorouter.com uses cookies to keep you signed in. Sign-in doesn't work without them.
- Landing page analytics. autorouter.com uses PostHog to measure visits, sign-up steps, download clicks, and page performance, using an anonymous identifier stored in your browser. This identifier isn't linked to your account. Session recording and automatic capture of page content are off, and we don't collect these analytics when your browser sends a Do Not Track signal.
- Account website monitoring. app.autorouter.com uses Datadog to record page views, interactions, errors, and performance, linked to your account identifier. Session replay is off.
- Desktop app telemetry. The desktop app sends product analytics (PostHog) and diagnostics (Datadog) linked to your account and installation identifiers, such as features you use, models selected, routing notifications shown, errors, crashes, and performance. Telemetry doesn't include the contents of your prompts or responses.
We don't use advertising cookies or let third parties track you across other websites for advertising.
4. How we use information
- Provide the Service: sign you in, connect your agent apps, route and deliver requests, and show your history, usage, and balance.
- Choose models: apply your routing settings and consider your request, plan allowance, model prices and availability, and published benchmark results.
- Handle payments and credits: process purchases, track your balance, charge paid usage, and issue rewards.
- Support and communicate with you, including about security, billing, and changes to the Service or our policies.
- Keep the Service secure: prevent fraud and abuse, including misuse of invitations and promotional credits, and enforce our Terms.
- Understand and improve the Service: fix problems, measure performance, and evaluate routing quality using routing and usage records rather than request content.
- Meet legal obligations and protect rights and safety.
We don't use your AI request content to train AI models. If we send you marketing emails, you can unsubscribe at any time. We may create aggregated or de-identified information that can't reasonably identify you and use it for any lawful purpose.
5. How we share information
Routing and model providers
Delivering your requests requires sending content to the companies that choose and run models:
- Routing provider. When AutoRouter chooses a model automatically, it sends Jev, a routing service provided by TypeSafe, the text of your latest message (up to a size limit), your routing settings and instructions, your plan's eligible models and remaining allowance, and information about candidate models. We don't send your name, email address, or account identifier. Choosing a specific model in your agent app skips this step.
- Your subscription providers. When a request uses your ChatGPT plan, we send it to OpenAI. When it uses your Claude plan, we send it to Anthropic. These requests are handled under your agreement with that provider. ChatGPT requests pass through our website hosting provider on their way to OpenAI.
- Ramp Router. Requests for other models, and requests paid with credits, go to Ramp Router, Ramp's model gateway. Ramp sends each request to the model's developer or to a company that hosts the model. These can include model developers such as OpenAI, Anthropic, and xAI, and cloud companies that host models.
Your routing settings and model choices determine which of these providers receive your content. To keep requests on your subscriptions, set Paid models to Never and choose only models included in your plan. Each provider handles content under its own terms and privacy policy, including its own retention practices.
Service providers
Companies that process information on our behalf help us run the Service: WorkOS (sign-in and email codes), Stripe (payments), Cloudflare (hosting, our API, and downloads), Vercel (website hosting and relaying ChatGPT requests), a managed database provider (account records), Datadog (monitoring and logs), and PostHog (product analytics). They may use the information only to provide services to us. If you join our Slack community, Slack handles your messages under its own policies.
Other sharing
- Legal and safety. To comply with law or valid legal process, enforce our Terms, or protect the rights, property, or safety of you, us, or others.
- Business transfers. As part of a merger, acquisition, financing, or sale of assets, with this policy continuing to protect your information.
- With your consent or at your direction.
We don't sell your personal information or share it for cross-context behavioral advertising.
6. How long we keep information
- Account, settings, routing, and usage records: while your account is open. After you ask us to delete your account, we delete or de-identify these records within 30 days, except as described below.
- Payment and credit records: as long as tax, accounting, and legal requirements demand, generally up to seven years.
- AI request content: held only in memory while a request is processed, not stored in our databases.
- Diagnostic logs and telemetry: generally up to 90 days, or longer when needed to investigate a security incident or abuse.
- Information on your Mac: stays until you remove it. Turning off an agent app connection removes AutoRouter's changes from that app's settings.
We may keep information longer when the law requires it or to resolve disputes. Deleted information may remain in backups for a limited time.
7. Security
We protect information with measures such as encryption in transit, one-way hashing of installation credentials, access controls, and monitoring. The desktop app stores its credentials on your Mac in files only your user account can read.
Your installation credential is also saved in your agent apps' settings files, so anyone with access to those files could make requests using your account and credits. Keep your Mac secure, and contact us if you think a credential has been exposed so we can revoke it. No method of transmission or storage is completely secure. We'll notify you of a security incident affecting your information as the law requires.
8. Your choices and rights
Choices
- Change your routing strategy, rules, and Paid models setting in the desktop app or at app.autorouter.com.
- Turn off an agent app connection in the desktop app to stop routing its requests and remove AutoRouter's changes from its settings. Signing out of the desktop app doesn't disconnect your agent apps.
- Turn off optional macOS permissions in System Settings, and turn off Open at login in the desktop app's settings.
- Clear or block browser storage, or turn on Do Not Track, to limit landing page analytics.
Privacy rights
Depending on where you live, you may have the right to access, correct, or delete your personal information, receive a portable copy of it, object to or restrict certain processing, withdraw consent, and appeal our decision about your request. We won't discriminate against you for exercising these rights.
To make a request, email support@autorouter.com from the email address on your account. We'll verify your identity before acting and respond within the time the law requires. Where the law allows, you may use an authorized agent, and we may ask for proof of their authority. If we deny your request, you can appeal by replying to our decision. You can also contact your local data protection authority.
9. Additional information for some regions
United States
In the past 12 months, we have collected these categories of personal information, from the sources and for the purposes described above: identifiers (such as name, email address, account and installation identifiers, and IP address); commercial information (credit purchases and usage); internet or network activity (interactions, logs, and diagnostics); approximate location derived from IP address; the contents of requests and communications; and account credentials (provider sign-in credentials, which we use only to deliver your requests). We disclose these categories for business purposes to the service providers and AI providers described in Section 5. We don't sell or share personal information, and we don't use sensitive personal information to infer characteristics about you.
European Economic Area, United Kingdom, and Switzerland
Fractal Works, Inc. is the controller of your personal information. We process it to perform our contract with you (providing the Service, routing requests, and handling payments); for our legitimate interests in security, fraud prevention, diagnostics, analytics, and improving the Service, balanced against your rights; with your consent where required, which you can withdraw at any time; and to comply with legal obligations.
International transfers
We process information in the United States and other countries where we and our providers operate. When we transfer personal information internationally, we use appropriate safeguards, such as the European Commission's Standard Contractual Clauses.
10. Google user data
If you sign in with Google, we receive your email address and basic profile information, such as your name and profile picture, to authenticate you and maintain your account. We don't request access to Gmail, Google Drive, contacts, or calendars. AutoRouter's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements. We don't sell Google sign-in information, use it for advertising, use it to train AI models, or give AI providers access to your Google account. You can remove AutoRouter's access in your Google Account settings. This stops future sign-ins through Google but doesn't delete information we already hold; to delete it, contact us.
11. Children
AutoRouter is for adults. It isn't directed to anyone under 18, and we don't knowingly collect personal information from them. If you believe a minor has given us personal information, contact us and we'll delete it.
12. Changes to this policy
We may update this policy as the Service changes. We'll post the updated policy with a new date. If we make material changes, we'll notify you by email or in the Service before they take effect.
13. Contact us
Fractal Works, Inc.
support@autorouter.com