LEGAL

Privacy Policy

The short version: we keep what accounting and security genuinely need, we do not keep the content of what you route through the exchange, and we do not train on any of it.

Beta draftLast updated 2 August 2026Under legal review

What we collect

  • Account data: your email, authentication identifiers, and the role your account has.
  • Financial data: wallet balance, ledger movements, deposits, payouts and the details you give us for a payout rail.
  • Usage metadata: per-job model, token counts, cost, timing, and whether it succeeded — the record behind every figure you can see.
  • Seller seat data: which provider a seat is on, its declared plan, and the token-count digests you choose to report with the CLI.
  • Technical data: IP address, user agent and request logs, kept for security and abuse investigation.

What we deliberately do not collect

  • The content of routed requests and responses. It is relayed, metered and forgotten.
  • Seller prompts or files. Usage reporting sends counts, and the CLI has a command that prints exactly what would be sent so the claim is checkable.
  • Any identity link between the two sides. A buyer is never told whose seat served them, and a seller is never told who consumed their capacity.
  • Training data. Nothing that passes through the exchange is used to train a model, ours or anyone else's.

Response headers that would describe the serving account — rate-limit and request-id headers — are stripped before a response reaches a buyer, because they leak the seller.

Why we hold it

  • To run the service you asked for: routing, metering, billing and payouts.
  • To keep the books correct and to satisfy accounting and tax obligations.
  • To detect fraud, abuse and chargeback misuse, which is a legitimate interest and also protects other users.
  • To communicate about your account — incidents, payouts, and material changes to the terms.

Who else sees it

  • AI providers, who receive the request being served. That is the point of the exchange, and it is governed by their own terms.
  • Payment processors and merchants of record, who handle collection and receive what a payment needs — not your usage history.
  • Infrastructure providers that host the service and its database.
  • Authorities, where we are legally required to and only to the extent required.

We do not sell personal data, and we do not share it for advertising.

How long we keep it

  • Financial records: for as long as accounting and tax law require, which is longer than your account may exist.
  • Usage metadata: for the life of the account, because it is the evidence behind every figure you were charged.
  • Technical logs: a short rolling window, for security investigation.
  • Routed content: not retained at all.

Your rights

Depending on where you live, you can ask for a copy of your data, ask us to correct it, ask us to delete it, object to processing, or ask for it in a portable form. Deletion is bounded by the financial records we are required to keep. Write to legal@shaidle.com and we will answer within the period the applicable law allows — sooner if we can.

Cookies and storage

We use a session cookie to keep you signed in, and browser storage for preferences such as your theme. There is no advertising or cross-site tracking on this site. Every key we write is listed by name on the cookie policy, which is generated from the code rather than transcribed, and the same page is where you change what this browser is allowed to keep.

Security and contact

How credentials are protected and how to report a vulnerability are on the security page. For anything else about this policy, use the contact page.