AI Gateway Privacy Policy

Last updated: September 2026

Note: This policy is pending legal review. Please check back before relying on it for compliance purposes.

1. Introduction

This AI Gateway Privacy Policy ("Gateway Privacy Policy") describes how BroadComms ("we", "us", "our") collects, uses, and shares data when you use the BroadComms AI Gateway ("Gateway"). This policy is a supplement to the BroadComms general Privacy Policy. In the event of conflict, this Gateway Privacy Policy prevails for Gateway-related data processing.

We are committed to protecting your privacy and complying with applicable data protection laws, including the Australian Privacy Act 1988 (Cth), the Australian Privacy Principles (APPs), and where applicable, the EU General Data Protection Regulation (GDPR).

2. Data We Collect

When you use the Gateway, we collect the following categories of data:

2.1 API Call Data

  • Prompt content: The text or messages you send to AI models via the Gateway.
  • Completion content: The responses returned by AI models (stored for up to 90 days).
  • Model used: The public model identifier (e.g. kimi-3).
  • Token counts: Input and output token usage per call for billing purposes.
  • Cost: The calculated cost of each call at our flat per-model price.
  • Timestamps: Date and time of each API call (UTC).
  • API key identifier: Which of your API keys was used.

2.2 Account & Billing Data

  • Account credentials, email address, and organisation membership.
  • Subscription plan, billing history, and credit ledger.
  • Referral code usage and referral credit unlock status.

2.3 Technical Data

  • IP address of API requests (retained for 90 days for security and abuse detection).
  • HTTP headers and request metadata for routing and debugging.
  • Redis rate-limiting counters associated with your API keys.

3. How We Use Your Data

We use your Gateway data for the following purposes:

  • Service delivery: Routing your API calls to inference providers and returning responses.
  • Billing: Calculating and charging your account for usage based on our flat per-model prices.
  • Dashboard & analytics: Displaying your usage, costs, and token counts in the BroadComms dashboard.
  • Rate limiting: Enforcing per-key and per-plan rate limits via Redis.
  • Security & fraud prevention: Detecting and blocking abuse, credential stuffing, or API key misuse.
  • Service improvement: Aggregated and anonymised usage analytics to improve routing, model availability, and pricing. We do not use the content of your prompts or completions for model training.
  • Compliance: Retaining data as required by law (e.g. billing records for tax purposes).

4. Data Shared with Inference Providers

To deliver AI responses, your prompt content and associated metadata is forwarded to the inference providers (e.g. Google, NVIDIA/OpenRouter) that power each model. This means your prompt data is processed under each provider's own privacy policy and terms of service.

Current inference providers used by the Gateway:

The specific provider used for a given request depends on the model selected and the routing policy in effect at the time. Provider selection is automatic and opaque to the user.

5. Data Retention

We retain different categories of Gateway data for different periods:

Data TypeRetention PeriodNotes
API call logs (prompts, completions, tokens, cost)90 daysUsed for dashboard display, billing disputes, and abuse detection. Automatically purged after 90 days.
IP addresses90 daysRetained for security and abuse detection.
Billing records7 yearsRequired for tax and financial compliance.
Account dataRetained while active + 30 daysDeleted within 30 days of account deletion request, subject to legal hold.
Managed Keys (encrypted)Until deleted by userEncrypted at rest; deleted within 30 days of user request.

For AI chat assistant conversations (separate from Gateway API calls), retention is governed by the general Privacy Policy — see the Chat Messages section.

6. Data Security

  • Encryption in transit: All API calls are served over HTTPS/TLS 1.2+.
  • Encryption at rest: Managed Keys (BYOK) are encrypted using Fernet (AES-128-CBC) with a key managed by BroadComms.
  • Access controls: Internal access to API logs and billing data is restricted to authorised personnel on a least-privilege basis.
  • Provider data: We cannot guarantee the security practices of third-party inference providers. Their data handling is governed by their own policies.
  • Data breaches: We will notify affected users and relevant authorities of any material data breach in accordance with applicable law.

7. Your Rights

Depending on your jurisdiction, you may have the right to:

  • Access: Request a copy of the personal data we hold about you (including API call logs).
  • Correction: Request correction of inaccurate personal data.
  • Deletion: Request deletion of your account and associated data, subject to billing record retention requirements.
  • Portability: Request your data in a machine-readable format.
  • Object: Object to certain processing activities, such as aggregated analytics use.
  • Withdraw consent: Where processing is based on consent, withdraw that consent at any time.

To exercise any of these rights, contact us at privacy@broadcomms.net. We will respond within the timeframes required by applicable law.

8. Managed Keys (BYOK)

When you register a Managed Key (your own provider API key) in the Gateway, we store:

  • The key name and base URL you provide (for display and routing purposes).
  • The encrypted API key value — we store only the encrypted form; the plaintext is never persisted.
  • Usage logs for requests routed through your Managed Key (for your dashboard analytics only).

We do not use your Managed Key data for any purpose other than routing your API requests and providing your dashboard analytics. The third-party provider receiving your requests will handle your data under their own privacy policy.

9. Cookies & Tracking

The Gateway uses the following cookies and tracking technologies:

CookiePurposeDuration
session_tokenAuthentication — JWT session for the dashboardSession / 7 days
csrf_tokenCSRF protection for dashboard form submissionsSession

For more information on broader website cookies, see our Cookie Policy.

10. Changes to This Policy

We may update this Gateway Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. We will post the updated policy on this page with an updated "Last updated" date. For material changes, we will provide prominent notice (e.g. via email or a banner in the dashboard) at least 30 days before the change takes effect.

11. Contact

For questions or requests regarding this Gateway Privacy Policy or our data handling practices, contact our Privacy Officer:

Email: privacy@broadcomms.net
BroadComms Privacy Officer
broadcomms.net