Privacy policy
Effective September 24, 2026
This policy explains what OpenGray, operated by Samuel Baker, collects when you use the website and API, why we collect it, and how long we keep it.
1. What we collect
| Category | Examples | Purpose |
|---|---|---|
| Account data | Name, email address, optional company, bcrypt password digest | Creating and securing your account |
| Credentials | SHA-256 hashes of API keys, key prefix and last four characters | Authenticating API requests |
| Billing data | Credit balance, purchases, Whop payment identifiers, amounts | Processing payments and reconciliation |
| Request metadata | Timestamp, model, token counts, latency, HTTP status, credits charged, IP address | Metering, support and abuse prevention |
| Security logs | Sign-in attempts with IP address and outcome | Rate limiting and intrusion detection |
| Correspondence | Messages sent through the contact form | Answering your enquiry |
2. Prompts and completions
We do not store the content of your prompts or the model's responses. Message bodies pass through our proxy in memory and are discarded once the response has been delivered. Only the metadata listed above is retained.
Message content is transmitted to the upstream provider selected by your chosen model in order to produce a response. Those providers process it under their own terms.
3. Processors we use
- OpenRouter - routes requests to model providers.
- Anthropic and OpenAI - generate responses for the models in the catalogue.
- Supabase - hosts the Postgres database holding accounts, balances and usage metadata (EU Central region).
- Whop - processes payments. Card details are entered on Whop's systems and never reach ours.
4. Cookies
We set one strictly necessary session cookie (og_session) to keep you signed in.
Your colour theme preference is stored in your browser's local storage. We do not use
advertising cookies or third-party analytics trackers.
5. Retention
- Account and billing records: retained while the account is open and for 7 years afterwards, as required for financial records.
- Request metadata: 24 months.
- Sign-in attempt logs: 90 days.
- Contact form messages: 24 months.
6. Your rights
You may request a copy of your data, correction of inaccurate data, or deletion of your account. Where you are covered by the GDPR or the CCPA you also have the right to object to processing and to data portability. Write to contact@open-gray.com and we will respond within 30 days. We do not sell personal information.
7. Security
Traffic is encrypted in transit. Passwords are hashed with bcrypt and API keys with SHA-256; neither can be recovered from our database. Database tables are protected by row-level security and are reachable only by the application backend. Sign-in endpoints are rate limited by address and by account.
8. Children
The service is not directed at children under 18 and we do not knowingly collect their data.
9. Contact
Data controller: Samuel Baker, 3113 Kildeer Drive, Crittenden, VA 23314, United States. Telephone 757-238-9262. Email contact@open-gray.com.