LumiRoute
HomeTerms
Sign in Get started

Privacy Policy

Last updated: 19 September 2026 · LumiRoute (lumirouter.com)

1. Who we are

LumiRoute operates lumirouter.com and the associated API gateway. Contact: boyraz.ahmetcan@gmail.com.

2. Data we process

  • Account: email, optional name, password hash (not plaintext), Terms acceptance time.
  • API keys: LumiRoute gateway keys and, if you choose BYOK, encrypted/stored provider keys in Cloudflare KV as configured.
  • Usage: request metadata needed for rate limits and usage dashboards (for example timestamps, model/provider, token counts where available).
  • Technical: IP address and similar signals for abuse prevention and rate limiting.

3. Prompts & completions

Chat content is forwarded to the selected model provider (or Cloudflare AI when used) to fulfill your request. We do not sell your prompts. Avoid sending secrets or personal data you are not authorized to process.

4. Infrastructure

The service runs on Cloudflare Workers, D1, and KV (and related Cloudflare products). Data may be processed in regions Cloudflare operates. See Cloudflare’s privacy documentation for their role as processor/subprocessor.

5. Cookies & session

We use an HTTP-only session cookie (lr_session) to keep you signed in on the website. The dashboard may also store your API key in browser local storage for convenience when calling the API from the browser.

6. Retention

Account and usage records are kept while your account is active and as needed for security, billing readiness, and legal obligations. You may request account deletion by contacting us.

7. Your choices

  • Do not use BYOK if you do not want provider keys stored with us.
  • Sign out to clear the session cookie; clear local storage to remove a browser-stored API key.
  • Contact us to ask about access or deletion of account data.

8. Changes

We may update this Policy. The “Last updated” date on this page will change when we do.

This page is an operational summary, not formal legal counsel.