Privacy Policy
Last updated: July 16, 2026
This Privacy Policy describes how Phthos (“Phthos,” “we,” “us,” or “our”) collects, uses, and shares information when you visit phthos.ai, use the Phthos console at console.phthos.ai, or call our gateway API at gateway.phthos.ai.
1. Who we are
Phthos provides an LLM gateway and control plane that lets teams route, observe, and orchestrate model traffic across providers. For privacy questions or requests, contact us at hello@phthos.ai.
2. Information we collect
- Account information — name, email address, organisation and workspace membership, and authentication details when you sign in (including OAuth profile data from providers you choose).
- Billing information — subscription status, invoices, and payment metadata processed by Stripe. We do not store full payment card numbers on our servers.
- API and configuration data — API keys (stored encrypted), provider credentials you configure, model aliases, routers, RAG and vector store settings, agent flows, and related workspace configuration.
- Usage and observability data — gateway request logs (including prompts, completions, token counts, latency, and cost estimates), agent run metadata, and aggregated usage statistics needed to operate metering and dashboards.
- Technical data — IP address, browser type, device information, and cookies or similar technologies used for session management and security.
- Communications — messages you send to us (for example support or billing email at hello@phthos.ai).
3. How we use information
- Provide, secure, and maintain the Phthos platform and APIs.
- Authenticate users, enforce access controls, and prevent abuse.
- Meter usage, calculate credits, process subscriptions, and send transactional email (for example via Resend from noreply@phthos.ai).
- Display observability, logs, and billing history in the console.
- Improve reliability, debug incidents, and develop new features.
- Comply with law and respond to lawful requests.
We do not sell your personal information.
4. LLM content and customer data
When you send prompts or files through Phthos, that content is processed to fulfill your requests — including forwarding to third-party model providers you configure (such as OpenAI, Anthropic, or Google). Those providers handle data under their own terms and policies. You are responsible for ensuring you have the right to submit content and for configuring retention and logging appropriately for your use case.
Gateway request logs may contain prompts and model outputs. Retention periods may vary by plan and operational settings. Minimize sensitive data in prompts where possible.
5. How we share information
- Service providers — hosting (for example Hetzner Cloud in the EU), payment processing (Stripe), email delivery (Resend), and infrastructure partners that help us run the service.
- Model and tool providers — when you route traffic through the gateway, request content is sent to the upstream providers you select.
- Team members — other users in your organisation or workspace who have been granted access.
- Legal and safety — when required by law, to protect rights and safety, or in connection with a merger or acquisition.
6. International transfers
Phthos may process data in the European Union and in other countries where our service providers operate. Where required, we rely on appropriate safeguards for cross-border transfers.
7. Retention
We retain account, billing, and configuration data for as long as your account is active and as needed to provide the service, resolve disputes, and meet legal obligations. Observability and request logs are retained for operational and metering purposes; older logs may be deleted or aggregated according to our data lifecycle practices.
8. Security
We use technical and organisational measures designed to protect information, including encryption for API key secrets, access controls, and network isolation for production infrastructure. No method of transmission or storage is completely secure; please protect your account credentials and API keys.
9. Your rights
Depending on where you live, you may have rights to access, correct, delete, or export personal data, or to object to or restrict certain processing. To exercise these rights, email hello@phthos.ai. We may need to verify your identity before responding.
10. Cookies
The console uses cookies and similar technologies for authentication and session management. You can control cookies through your browser settings; disabling them may limit sign-in functionality.
11. Children
Phthos is not directed to children under 16, and we do not knowingly collect personal information from children.
12. Changes
We may update this Privacy Policy from time to time. We will post the revised version on this page and update the “Last updated” date. Material changes may also be communicated through the console or email where appropriate.