Back to Shunt

Privacy Policy

Last updated: October 5, 2026

1. Core Philosophy: Zero-Payload Retention

Shunt operates as an in-line reverse proxy. We believe in strict data minimization. We do not store, log, or train on the text contents of your prompts or completions.Request payloads are parsed in volatile memory solely to calculate prompt hashes for recursion detection and token counts for cost caps, then immediately streamed through to the upstream model provider.

2. Information We Store

  • Account Credentials: Your email address and hashed passwords, managed via Supabase Auth.
  • Upstream API Keys: In Zero-Trust Mode, provider keys sent in x-upstream-key are processed in request memory and are not stored. If you choose Vault Mode, keys are encrypted using AES-256 (Fernet) before storage.
  • Shunt API Keys: Proxy keys issued to you are hashed with SHA-256. Only the hash and an 8-character prefix are stored.
  • Operational Metadata: We log request metadata for billing and dashboard reporting: timestamp, session identifier, model name, token usage counts, calculated cost, HTTP status code, and whether a Shunt rule terminated the request.

3. Cookieless Analytics

Our website uses Vercel Web Analytics. We do not use third-party tracking cookies or advertising pixels. All telemetry is aggregated and privacy-friendly, fully compliant with GDPR without requiring invasive cookie consent banners.

4. Payment Processing (Merchant of Record)

Paid subscriptions are billed through Polar Software Inc., acting as our Merchant of Record. Polar handles all payment transactions, invoicing, and applicable EU/Norwegian VAT. We do not store or process your credit card numbers or banking credentials.

5. Contact & Data Deletion

You have the right to inspect, export, or permanently delete your account and all associated keys. For privacy inquiries or immediate account purge requests, contact:

contact.roandejager@gmail.com