Privacy policy

Effective September 24, 2026

This policy explains what OpenGray, operated by Samuel Baker, collects when you use the website and API, why we collect it, and how long we keep it.

1. What we collect

CategoryExamplesPurpose
Account dataName, email address, optional company, bcrypt password digestCreating and securing your account
CredentialsSHA-256 hashes of API keys, key prefix and last four charactersAuthenticating API requests
Billing dataCredit balance, purchases, Whop payment identifiers, amountsProcessing payments and reconciliation
Request metadataTimestamp, model, token counts, latency, HTTP status, credits charged, IP addressMetering, support and abuse prevention
Security logsSign-in attempts with IP address and outcomeRate limiting and intrusion detection
CorrespondenceMessages sent through the contact formAnswering your enquiry

2. Prompts and completions

We do not store the content of your prompts or the model's responses. Message bodies pass through our proxy in memory and are discarded once the response has been delivered. Only the metadata listed above is retained.

Message content is transmitted to the upstream provider selected by your chosen model in order to produce a response. Those providers process it under their own terms.

3. Processors we use

  • OpenRouter - routes requests to model providers.
  • Anthropic and OpenAI - generate responses for the models in the catalogue.
  • Supabase - hosts the Postgres database holding accounts, balances and usage metadata (EU Central region).
  • Whop - processes payments. Card details are entered on Whop's systems and never reach ours.

4. Cookies

We set one strictly necessary session cookie (og_session) to keep you signed in. Your colour theme preference is stored in your browser's local storage. We do not use advertising cookies or third-party analytics trackers.

5. Retention

  • Account and billing records: retained while the account is open and for 7 years afterwards, as required for financial records.
  • Request metadata: 24 months.
  • Sign-in attempt logs: 90 days.
  • Contact form messages: 24 months.

6. Your rights

You may request a copy of your data, correction of inaccurate data, or deletion of your account. Where you are covered by the GDPR or the CCPA you also have the right to object to processing and to data portability. Write to contact@open-gray.com and we will respond within 30 days. We do not sell personal information.

7. Security

Traffic is encrypted in transit. Passwords are hashed with bcrypt and API keys with SHA-256; neither can be recovered from our database. Database tables are protected by row-level security and are reachable only by the application backend. Sign-in endpoints are rate limited by address and by account.

8. Children

The service is not directed at children under 18 and we do not knowingly collect their data.

9. Contact

Data controller: Samuel Baker, 3113 Kildeer Drive, Crittenden, VA 23314, United States. Telephone 757-238-9262. Email contact@open-gray.com.