Privacy Policy
Clear boundaries for what passes through and what you choose to store. This policy describes how AIRCTRL handles request content, credentials, and account information.
Last updated: September 22, 2026
1. Overview
This Privacy Policy explains how AIRCTRL (“airctrl”, “we”, “us”, or “our”), a Theovex company, collects, uses, and safeguards information when you use our websites, APIs, and related services (the “Services”). By using the Services, you agree to the practices described here.
2. Information we collect
We collect the following categories of information:
- Account information, such as your name, email address, and organization details.
- Usage metadata, such as model and provider identifiers, request timestamps, usage totals, and aggregate spend.
- Record metadata, such as names, tags, secret formats, rotation dates, authors, and timestamps. This metadata is not protected by Vault value encryption.
- Technical data, such as IP address, device and browser information, and diagnostic logs.
3. Secrets and credentials
Vault secret values are encrypted on your device. AIRCTRL stores ciphertext and wrapped keys, while authorized clients hold the keys needed to decrypt them. Record metadata is separate from the encrypted value.
Provider credentials configured for Gateway are a different category. They are encrypted server-side and can be decrypted by the proxy to make upstream requests. They are not covered by Vault’s zero-knowledge model. We do not sell your credentials or use your prompt or secret content to train models.
4. How we use information
We use information to operate, maintain, and improve the Services; authenticate users; route and govern AI traffic; enforce spend limits; provide support; ensure security; and comply with legal obligations.
5. Sharing and disclosure
We share information with third-party model providers only as needed to fulfill your requests, and with service providers who process data on our behalf under appropriate confidentiality obligations. We may disclose information when required by law or to protect our rights and users.
6. Data retention
Gateway processes AI requests on your behalf. Prompt and response retention depends on request-body logging and caching settings. Review those settings and your model provider’s policies before sending sensitive data. Zero-knowledge Vault encryption is not a guarantee that Gateway never stores request content.
We retain account information, encrypted Vault data, Gateway credentials, and operational metadata for as long as your account is active or as needed to provide the Services, resolve disputes, and comply with our legal obligations. You may request deletion of your account data as described below.
Cryptographic erasure removes the relevant stored key material. Security audit records are preserved where required, with referenced identifying data pseudonymized as appropriate. Erasure does not remove copies already exported to another device.
Connected model and service providers process requests under their own data policies and configurations. AIRCTRL’s retention policy does not replace those providers’ terms.
7. Security
We use administrative, technical, and organizational measures designed to protect your information. No method of transmission or storage is completely secure, however, and we cannot guarantee absolute security.
Our Security & architecture page explains client-side Vault encryption, server-side Gateway credentials, request settings, and readable metadata.
8. Your rights
Depending on your location, you may have rights to access, correct, export, or delete your personal information, and to object to or restrict certain processing. To exercise these rights, contact us using the details below.
9. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be reflected by updating the “Last updated” date above, and where appropriate we will provide additional notice.
10. Contact
Questions about this policy can be sent to privacy@airctrl.dev.