Last updated: 25 July 2026
ModelGate sits between your application and the LLM providers you choose. This policy explains what we collect to do that, what we deliberately don’t, and the choices you have.
ModelGate (“ModelGate”, “we”, “us”) operates the ModelGate gateway and dashboard at modelgatehq.com. For privacy questions or requests, contact privacy@modelgatehq.com.
When you create an account we store your email address and authentication details (handled by our auth provider), and the customer, project and API-key records that make up your workspace.
You may add your own API keys for OpenAI, Anthropic, Google or Azure. These are encrypted at rest with a key we hold separately from the database, and only a short masked hint (e.g. the last few characters) is ever displayed back to you. We use them solely to route your requests to that provider on your behalf.
For every request through the gateway we record metadata needed to price it and audit for waste: timestamp, provider, model, token counts, computed cost, latency, cache-hit and waste indicators, and one-way hashes of the request and response used for caching and deduplication.
We do not store the text of your prompts or the model’s responses by default. Prompt storage is a per-project setting that is off unless you explicitly enable it (for example, to power richer recommendations). When enabled, a normalized copy of the request is stored for that project until deleted.
When automatic caching is enabled for a project, the response to a cacheable request is stored so identical later requests can be served without paying the provider again. Cache entries expire and can be cleared.
Payments are handled by PayPal. We do not receive or store your card or bank details. We retain your subscription identifier, status, and a record of the monthly success-fee invoices we raise.
We do not use your data to train models, and we do not sell it or share it for advertising.
We rely on a small number of providers to run ModelGate:
| Provider | Purpose |
|---|---|
| Supabase | Database and authentication. |
| Railway | Application hosting. |
| PayPal | Subscription and invoice payments. |
| Google Analytics | Website and product usage analytics. |
| OpenAI, Anthropic, Google, Azure | Fulfilling model requests you send — only the providers you configure and use. |
When you send a request, its contents go to the LLM provider you chose for that call, under that provider’s own terms and privacy policy.
Account and request-metadata records are kept for as long as your account is active. You can ask us to delete your account and associated data; cache entries expire automatically, and stored prompts (if you enabled them) are removed on request or when the project is deleted. We may retain limited billing records where required for tax and accounting.
Provider secrets are encrypted at rest; traffic is served over TLS. Access to production systems is limited. No system is perfectly secure, but keeping prompt content out of storage by default is a deliberate part of our design.
We use only what the product needs: a session cookie to keep you signed in, and local browser storage to remember your active project. We also use Google Analytics to understand how the site and product are used (pages visited, broad traffic patterns); it sets first-party analytics cookies. We don’t use advertising or cross-site tracking cookies, and we don’t sell any of this data.
Our providers may process data in the United States and other countries. ModelGate is a tool for businesses and is not directed to children; we don’t knowingly collect data from anyone under 16.
We’ll update this page when our practices change and revise the date above. Material changes will be communicated to account holders.
Questions? privacy@modelgatehq.com.