Legal

Privacy Policy

Plain-language privacy practices. Last updated Sep 2026.

Batchrouter never trains on your data
Routed by privacy tier
Encrypted in transit and at rest
01

Data we collect

Account info (email, name), batch metadata (item counts, timing, status), and billing records. The feedback widget collects more, and section 08 lists it. Batchrouter does not use batch item payloads to train models.

02

How we use it

To route, retry, deliver, and settle batches. To send transactional emails. To operate fraud and abuse controls. Batchrouter never trains a model on your data, and never sells it.

03

Providers

Customer payloads are forwarded only to providers selected by routing. Before dispatch, the router compares the batch's privacy tier against the tiers each provider declares. It rejects a provider that does not declare the requested tier. That tier check always runs. A stricter zero-data-retention check exists, but it runs only in the privacy-constrained routing mode. In every other routing mode it does not run. A confidential batch can therefore reach a provider that declares no zero-data-retention guarantee, and today no built-in provider declares one. A provider also declares a retention window, and we publish that window in the routing receipt. The router does not compare that window against your batch. Treat it as provider-declared information, not as a limit we enforce. Batchrouter cannot control what a provider does after dispatch, and each provider sets its own training policy. Read the provider's own policy before you send regulated data.

04

Retention

Our target is a 30-day window: 30 days after a batch reaches a terminal state, we clear the batch item payloads and the stored item output, we delete the provider request and response bodies, and we delete the uploaded input manifest. The automatic deletion job is not live in production yet — today it runs in report-only mode — so treat the 30-day window as a target, not an active schedule. Result artifacts are separate, and the 30-day target does not cover them. A batch result file, a review file, and an error file follow a storage-retention policy that your organization sets through the API. The default policy is free and keeps a result for a grace window of 7 days after completion. You can raise that to a fixed window of up to 3650 days, or keep results until you delete them. Both longer tiers are metered. The result collection job also runs in report-only mode today, so no result file is collected yet. Files you upload as input attachments (images, documents, audio, video) are separate. An attachment can serve many batches, so it has no batch-linked deletion date today. No job deletes an attachment, and the product has no delete control for one. An attachment stays in our storage until an operator removes it by request. Email privacy@batchrouter.com to ask for the removal of an uploaded file. Receipts and accounting records are retained for 7 years where required by the Swedish Bookkeeping Act (Bokföringslagen) and tax law — a legal-obligation basis under GDPR Art. 6(1)(c). This statutory retention overrides erasure requests only to the extent legally required. We act on every other erasure request manually. Section 05 states what account deletion does not reach today.

05

Your rights

You can often delete your account yourself on the Account page. The page asks for your account password first. It refuses the deletion while your organization still has another member, or a second owner. Remove them first, or email us. When the deletion runs, it does the following. It anonymises your profile and your organization record. It deletes your sessions and your membership. It revokes your API keys and your pending invitations. It removes your policy acceptances. It also deletes or strips the payloads of your saved quotes. It does not delete your batch records, your batch item payloads, your execution records, your usage records, your uploaded files, or your feedback reports — see Retention. Your profile row and your organization row stay in the database: we overwrite the identifying fields and keep the row. We also write one internal audit event that survives the scrub. That event records your pseudonymous user ID, your organization ID, and a non-identifying snapshot of what the scrub changed. Batchrouter has no self-service data export today. Email privacy@batchrouter.com for an export, a correction, an objection, or the erasure of data that account deletion does not reach. We handle each request manually. GDPR sets a one-month response deadline for these rights, and we work to it; no automatic system enforces it. CCPA rights go to the same address. We keep the records that Swedish law requires us to keep (see Retention).

06

Subprocessors

Cloudflare, OpenAI, Anthropic, Mistral AI, xAI, Together AI, Groq, OpenRouter, SWERunAi, AUTONOMOUSc, Stripe, Resend, Google (Fonts), Google (Gmail), and Operator alert webhook (vendor to be confirmed). The Legal page lists what each vendor does and the category of data it receives.

07

Cookies & tracking

Batchrouter sets strictly-necessary cookies only. They keep you signed in and run the product. We use no analytics vendor, and we set no analytics, advertising, or cross-site tracking cookies. The site also keeps a few values in your browser's local storage. All of them are functional: a flag that remembers you saw the cookie notice, your light or dark theme choice, and the models you mark as favourites on the marketplace. Clear your site data to reset all of them. Because we ask for no optional cookies, there is no consent to give and none to withdraw. One transfer is worth naming. Every page loads its web fonts from Google Fonts, so each page load sends your IP address and your browser user-agent string to Google servers in the United States.

08

Feedback widget

The feedback button sends your message to Batchrouter. The form also offers an optional contact email field, so you can ask for a reply without an account. It sends the page URL, the app version, and your browser user-agent string. It sends your browser name, your operating-system name, your language, your screen size, and your window size. It sends the referring URL. A bug report also sends up to 20 recent browser console error lines. A console error line can quote content from the page you were on. If you are signed in, it sends your account email address and your organization ID. It sends a screenshot only when you attach one. We record the IP address of the request. We store the report in our database. We also email it through Resend to a Google-hosted mailbox that a Batchrouter operator reads. That email carries your message, your contact address, your IP address, the browser context block, and any screenshot you attach. Google hosts that mailbox, so Google receives the email as a mail-host subprocessor. A separate step can also open an issue in a Batchrouter GitHub issue tracker. A deployment setting controls that GitHub step, so it does not run in every environment. That issue carries everything above except the screenshot and the IP address. It carries the report ID, your email address, your optional contact address, your organization ID, the page URL, the app version, the user-agent string, the submission time, your full message text, and the browser context block with the console error lines. The issue title repeats the first 80 characters of your message. The purpose is product support: we read each report and we fix what you tell us.

Exercising a data right?

We handle each GDPR and CCPA request manually — email privacy@batchrouter.com.