Legal
Weirgate Privacy Policy
Effective date: July 27, 2026
This Privacy Policy explains how Weirgate — currently operated by its founder, with Weirgate LLC, a Washington limited liability company in formation, to assume this Policy automatically upon its registration — (“Weirgate,” “we,” or “us”) handles personal information for the Weirgate website, developer dashboard, APIs, SDKs, command-line tools, and support interactions (the “Service”). It covers the developer relationship. A customer that uses Weirgate in its own application remains responsible for that application’s end-user privacy notice.
Information we handle
Developer account and organization data
We handle account identifiers, name, email address, authentication and session metadata, organization membership and role, security settings, and audit activity. Authentication credentials, factors, and sessions are handled by Clerk; Weirgate stores the developer identity and tenant membership needed to authorize the Service.
Configuration and credentials
We handle tenant and application configuration, feature and rule settings, webhook configuration, and scoped-access metadata. Developer-supplied model-provider credentials are encrypted before storage and are not returned after entry.
End-user provider keys sent in the X-User-Provider-Key request header are used only
to complete that request. We do not persist or log them.
Application end-user and usage data
To provide the Service, we handle customer-defined application identifiers, pseudonymous or customer-supplied end-user identifiers, request and idempotency identifiers, feature and model routing, token or operation counts, allowance and grant events, provider and user cost metadata when available, latency, error type, and timestamps.
AI request content and responses transit Weirgate and the selected provider to complete the request. Weirgate does not retain conversation content or model output in its usage ledger or application logs. Customers and providers may separately retain them under their own configurations and policies.
Website, dashboard, and support data
We may handle IP address, browser and device information, pages and actions used, diagnostic events, security logs, and information a developer submits in support or feedback. We use only strictly necessary cookies — authentication and session cookies set by our sign-in provider. We use no analytics, advertising, or tracking cookies or tools.
Billing data
Stripe is not live in this Slice-1 draft. When billing launches, Stripe will process payment method and transaction information. Weirgate expects to receive customer, subscription, invoice, payment status, and limited billing-contact metadata, but not full payment card numbers.
Why we use information
We use information to:
- provide, meter, secure, and troubleshoot the Service;
- authenticate developers and enforce tenant, role, and scoped-key access;
- route requests and apply balances, grants, rules, and provider policy;
- present usage, cost, audit, and reliability information;
- prevent abuse and investigate security incidents;
- communicate about the account, incidents, and requested support;
- comply with law and enforce agreements; and
- improve the Service using aggregate or de-identified operational information.
We do not sell personal information. We do not use customer prompts or model outputs to train AI models. We do not engage in targeted advertising or cross-context behavioral advertising of any kind.
Legal bases
Where a legal basis is required, we process information to perform our contract, pursue legitimate interests in operating and securing the Service, comply with law, and obtain consent where required. The Service is operated from the United States and is not currently directed at users in the European Union or United Kingdom; we have not appointed an EU or UK representative. If we begin offering the Service in those jurisdictions, we will appoint representatives as required and update this Policy.
Subprocessors and disclosures
We disclose information only as needed to operate the Service, follow a customer’s instructions, complete a developer-requested integration, protect rights and safety, or comply with law.
| Subprocessor | Purpose | Information involved | Current status |
|---|---|---|---|
| Cloudflare | API and site hosting, networking, security, logs | Requests, IP/device metadata, encrypted traffic, operational logs | Live |
| Neon | Managed Postgres data storage | Developer identity and tenant data, configuration, encrypted developer keys, end-user identifiers, usage/ledger/audit records | Live |
| Clerk | Developer authentication and account security | Name/email, login identifiers, factors, sessions, authentication metadata | Live |
| OpenRouter | Model gateway and routing where selected | AI request content, routing metadata, supplied OpenRouter credential in transit, provider usage/cost response | Live for applicable routes |
| Stripe | Subscription, invoice, and payment processing | Billing contact, customer/subscription/invoice/payment status; payment method handled by Stripe | Not live; planned for Slice 2 |
Model providers selected by Customer or OpenRouter may also process AI request content. Their identity varies with Customer configuration and routing. Customer must disclose those providers to its end users as applicable.
We may disclose information in a corporate transaction or to professional advisers under confidentiality obligations. We may disclose information to authorities when legally required or reasonably necessary to protect rights and safety.
International transfers
Our providers may process information in the United States and other countries.
Information is processed primarily in the United States, with global edge routing by
our CDN. Our subprocessors provide recognized transfer safeguards (Standard
Contractual Clauses and/or EU–U.S. Data Privacy Framework certification) under their
own terms. If we onboard customers subject to GDPR or UK GDPR, we will offer a
data-processing addendum incorporating Standard Contractual Clauses.
Neon production data is currently hosted in AWS us-west-2; Cloudflare may process
network traffic through its global network.
Retention
We keep information only as long as needed for the purposes above, including account operation, security, dispute resolution, and legal obligations.
Proposed launch schedule, pending founder and counsel review:
- active tenant configuration, identity, ledger, and audit data: for the account life;
- request/usage records: for the account life, and monthly billing aggregates up to seven (7) years thereafter as financial records;
- security and access logs: twelve (12) months;
- deleted-account data and backups: deletion or de-identification within ninety (90) days, unless law or a dispute requires longer;
- end-user provider keys: never retained; and
- AI request content and model output: not retained by Weirgate.
Security
We use access controls, scoped credentials, encryption in transit, encryption of stored developer provider credentials, tenant isolation, audit records, and secret-minimizing logging. No system is completely secure. Customers must protect their credentials, limit automation grants, configure provider accounts safely, and notify us of suspected compromise at security@weirgate.com.
Choices and rights
Depending on location, a person may have rights to access, correct, delete, restrict, or export personal information, or object to certain processing. Developers may manage some account data in the dashboard and may contact us at privacy@weirgate.com.
For data Weirgate handles on behalf of a customer’s application, the end user should contact that customer first. We will assist the customer as required by contract and law.
We will not discriminate for exercising a privacy right. A person may appeal a denied request or complain to a data-protection authority where applicable.
Children
The developer Service is not directed to children, and developer accounts must be held by people legally able to enter the Terms. Customers are responsible for deciding whether their own applications may be used by children and for configuring providers and notices accordingly. Weirgate does not knowingly collect a child’s information for its own purposes.
Changes and contact
We may update this Policy prospectively and will identify the effective date and provide notice of material changes. Questions and requests may be sent to:
Weirgate · privacy@weirgate.com · Effective date: July 27, 2026.