Privacy
HyperProxy is a bring-your-own-key (BYOK) gateway that hides your provider API keys. This page explains what we process and why.
About this policy
This policy explains how HyperProxy (“we”, “us” and “our”) handles information when you use our website, managed gateway and dashboard. We are responsible for the account, website, security and billing-administration data described here. For privacy requests, contact [email protected].
When we process your application's data on your instructions to provide the gateway, you remain responsible for your application's users and content. Paddle processes payment and tax data in its separate merchant-of-record role, as described below.
What we process
- Provider keys (BYOK). Your real provider keys are encrypted at rest using split-key envelope encryption. A key is reconstructed only in process memory when it is needed for an authorized upstream request and is not intentionally written to logs or persistent storage in plaintext.
- Request transit. Your requests and the upstream responses pass through the proxy. Bodies are streamed through and are not persisted; a capped portion of a response may be held transiently in memory only to extract token/cost usage, then discarded.
- Usage and security metadata. We retain metadata needed for analytics, billing, debugging, and abuse prevention, including timestamp, service/provider, model, request/response token counts, computed cost, latency, HTTP status, client and session identifiers you supply, and the trusted client IP associated with a request. New error logs contain status summaries, not response text. Older error excerpts may remain until their retention period expires; they are no longer exposed in request history or exports.
- Content you deliberately save. Prompt templates, presets, request properties, session labels and annotations you explicitly submit are stored to provide those features. Do not place secrets or unnecessary personal information in these fields. This is separate from transient request and response bodies.
- Account & project data. We process your name, email address, authentication identifiers and credentials in protected form, session and security information, project names, plan, and configuration such as endpoint allowlists, rate limits, alerts, and App Attest identity.
- Billing data. We retain Paddle customer, transaction, and subscription identifiers and the minimum status and entitlement metadata needed to reconcile plans and account credit. Paddle, not HyperProxy, receives full card and wallet credentials.
- Website analytics. If you allow analytics cookies, we use Google Analytics to understand visits, traffic sources, viewed pages and sections, and interactions with navigation and calls to action. This may include the page URL and title, referrer, campaign parameters, browser and device information, approximate location, and interaction timestamps. We do not send account credentials, provider keys, prompt content, or response content to Google Analytics.
Why we process it
We process account, security, request, and billing metadata to provide the service you ask for, protect accounts and infrastructure, prevent fraud and abuse, enforce quotas, support customers, meet legal obligations, and improve reliability. Where applicable, these purposes rely on performance of our contract, legitimate interests in operating a secure service, compliance with law, or your consent.
What we don't do
- We don't record transit request or response bodies in new request logs. Deliberately saved content and legacy error excerpts are described above.
- We don't sell your data or use it to train models.
- We don't ship your real provider key to your app — that's the whole point.
Cookies, website analytics, and sign-in
Website analytics is off until you select Accept cookies. When enabled,
Google Analytics may set first-party cookies such as _ga to distinguish visits and
sessions. Advertising storage, personalized advertising, and Google signals are disabled. You
can refuse analytics without losing access to the public site and can change your choice at any
time through Cookie settings in the footer.
The dashboard uses essential cookies for an authenticated session and CSRF protection. They are required for the account to work and are not advertising cookies. If you choose Google sign-in, Google processes that authentication under its own terms. Cloudflare Turnstile may process device and network signals to distinguish people from abusive automated traffic.
Security
Keys are protected by split-key encryption (a database breach yields only ciphertext plus one half of the key). Transport is HTTPS. Optionally, App Attest restricts a service to requests from your genuine app on real Apple hardware.
Retention & deletion
Usage metadata is retained only while needed to provide analytics, enforce quotas, resolve disputes, and meet legal obligations. Deleting a project removes its services, keys, and usage records from active systems, subject to short-lived backups and records we must keep by law. You may ask to access, correct, export, restrict, object to, or delete personal data where your local law provides those rights.
Third parties
When you send a request, HyperProxy forwards it to the upstream provider you configured, under your BYOK key — that provider's own privacy terms apply to that call. Managed hosting relies on infrastructure, email, authentication, and security providers, including Railway, Cloudflare, Postmark, and (when you choose Google sign-in) Google. They process data needed to provide those functions under their own privacy terms and our service arrangements. Paddle is the merchant of record for paid plans and processes checkout, payment, tax, invoice, refund, and subscription data under Paddle's privacy notice. HyperProxy does not receive or store full card or wallet credentials.
If you enable website analytics, Google processes the website usage data described above as our analytics provider. Learn more about how Google uses information from sites that use its services.
International processing and children
These providers may process data in countries other than your own. Where required, transfers are protected by the provider's lawful transfer mechanisms. The managed service is intended for people who can enter into a binding contract and is not directed to children.
Contact
Questions or privacy requests? Email [email protected].