XiuRouter / Data and Privacy
Last updated: September 12, 2026
XiuRouter / Data and Privacy
Last updated: September 12, 2026
XiuRouter does not store model conversation content, use it for model training, or sell user data. Usage statistics and model performance data are retained long term for billing, historical usage records, and service analysis.
This notice applies to the XiuRouter API and Playground operated by XiuLab Inc. The XiuAI Privacy Policy and Terms of Service provide the full provisions for account, payment, and support information.
Usage Records
The console provides request records containing the model, token usage, cost, outcome, and duration. Records can be located by request ID.
Model conversation content includes prompts, message history, files, images and other inputs submitted through the API or Playground, and model responses. XiuRouter processes and transmits this content solely to complete the request.
XiuRouter does not store model conversation content. The Playground displays inputs and responses within the current page.
Request records include model identifiers, timestamps, token counts, cache metering, charges, outcomes and latency for billing reconciliation and service analysis.
The console supports queries by time, API key, model, outcome and request ID. Annex I lists the fields.
Request IDs and API key identifiers may be associated with an account. These records are subject to applicable personal information requirements.
Model conversation content is processed solely to complete the requested call. XiuRouter does not use this content for model training and does not sell any user data.
Request statistics support billing, historical usage records, model performance analysis, troubleshooting, and abuse prevention. Account, billing, and support records are used for their respective services and applicable legal requirements.
Users retain their rights to submitted content and are responsible for obtaining any rights required to submit personal information or business materials. The selected model developer's data policies should be assessed against the intended use.
XiuRouter’s upstream access policy permits only services operated by model developers themselves.
Model developers process requests under the data policies for their services, including training use, security logging, retention and caching.
Requirements for a specified processing region or an enterprise data processing agreement can be discussed through the contact details below.
| Service | Information Processed |
|---|---|
| Model developer services | Model inputs and responses, processed under the developer's applicable data policy. |
| Hosting and networking | Information required to transmit requests and operate the website and API, including necessary access and operational records. |
| Authentication and payments | Account identifiers, authentication status, and transaction information required for payment and reconciliation. |
| Customer support | Contact details, messages, and attachments submitted by users, together with records of issue handling. |
| Website analytics | Necessary visit and interaction events. Model conversations are excluded from page analytics and session replay collection. |
Account, payment and support services process email addresses, account identifiers, authentication status, transaction amounts and currencies, transaction identifiers and payment results. Access information, including IP addresses and request paths, supports troubleshooting and security.
Messages, screenshots and attachments submitted by users are processed for customer support. Support requests should include the request ID, timestamp and redacted error details.
The XiuAI Privacy Policy provides the applicable processing rules.
Model conversation content is not stored. Usage statistics and model performance data are retained long term for billing reconciliation, historical usage records and performance analysis.
Account, transaction and support information is retained for the relevant services and legal requirements. Personal information rights requests are handled under applicable law.
| Data | Retention |
|---|---|
| Model conversation content | Not retained, including prompts, message history, files, images, and model responses. |
| Request statistics and model performance data | Retained long term for billing, historical usage records and performance analysis. |
| Account, transaction, and support information | Retained according to the relevant service and legal requirements, subject to applicable personal information rights. |
The console provides access to request records and API key controls for model restrictions, balance limits, expiry, rotation and revocation.
Personal information export and deletion requests, and model developer policy inquiries, may be submitted through the contact details below.
Playground inputs and outputs are excluded from page analytics and session replay. Sensitive content in API key display areas is masked from recordings.
XiuRouter uses transmission protections, access controls and permission boundaries to protect account, transaction and support information. Annex II describes the measures.
Users may request access to, correction of, export of or deletion of personal information by email, identifying the account, information and requested action. XiuRouter verifies identity or authorization where needed and handles requests under applicable law.
Applicable rights may also include objecting to or restricting processing, withdrawing consent and lodging a complaint with a competent data protection authority.
Suspected unauthorized account use, credential exposure and other data security incidents may be reported to the same address. XiuRouter meets applicable incident notification and assistance requirements.
Personal information and privacy requests are handled under applicable data protection laws, including the GDPR and the CCPA as amended by the CPRA where they apply. The relevant requirements depend on the processing activity, data location, and service arrangements.
Model developer and cloud services may involve international data transfers. Requirements for a specified processing region, a data processing agreement (DPA), or developer security documentation should be confirmed with privacy support before use, based on the available services and applicable terms.
This notice describes XiuRouter's data practices alongside the XiuAI Terms of Service and Privacy Policy. Revisions are identified by the updated date. Material changes are communicated through page notices, account notices, or other channels described in the Privacy Policy.
Annex I
Available request fields depend on the model, protocol and request outcome.
| Field | Purpose |
|---|---|
| Timestamp and request ID | Request identification, billing correlation, and support inquiries. |
| Account and API key identifiers | Identify the account and API key associated with a call. |
| Model, actual model, and service tier | Identification of the model and service tier used for a call. |
| Input and output token counts, cache metering | Measure usage and reconcile billing. |
| Cost and billing details | Review of charges and billing calculations. |
| Outcome, total duration, time to first token, and output speed | Analysis of request outcomes, performance, and service failures. |
| Upstream request ID, protocol path, and streaming status | Diagnose request forwarding and response issues. |
Annex II
| Measure | Scope |
|---|---|
| HTTPS access | The website and public API addresses use HTTPS to protect information in transit. |
| Separation of request statistics and conversation content | Model identifiers, usage, charges, and duration are recorded without writing conversation content to databases, request logs, or analytics systems. |
| Playground and API key recording exclusions | Playground inputs and outputs are excluded from page analytics and session replay. Sensitive content in API key display areas is masked from recordings. |
| Analytics field restrictions | Website analytics exclude model request and response content and sensitive fields such as passwords and API keys. |
| Account and access controls | Access to account, billing, and support information is controlled according to the relevant service and Privacy Policy. |
Contact XiuLab Inc at the following address for data processing inquiries, personal information rights requests and model developer policy information.
contact@xiu.ai