Privacy Policy
Last updated: 2026-06-05
1. Introduction
PGAIN.AI ("we", "us") provides a governance and routing layer that lets you connect your own LLM provider keys to an AI agent harness. This policy explains what we collect and how we handle it.
2. Data we collect
- Your email address (for your account and login).
- Your LLM provider API keys (e.g. OpenRouter, OpenAI), stored encrypted at rest (Fernet). We never store them in plaintext and never display them after entry (last 4 characters only).
- Usage metadata — timestamps, model/provider used, token counts, and cost per request — to show your dashboard and enforce your daily cap.
- If you sign in with Google, the OpenID subject id and email returned by Google.
3. How we use it
To provide the service: authenticate you, route your prompts to the LLM provider you chose using your key, meter spend against your cap, and show your usage. We do not use your prompts or keys to train models.
4. Data sharing
We do not sell or share your data with third parties, except the LLM provider you select for a given request (your prompt and your key are sent to that provider to fulfil the call). Those providers have their own privacy policies.
5. Data retention
We retain your account, keys, and usage records until you delete your account or request deletion. Provider keys are removed immediately when you remove them in Settings.
6. Your rights
You may access your data (dashboard + Settings), export it, or request deletion at any time by contacting us. You can remove individual provider keys and unlink Google yourself in Settings.
7. Cookies
We use a single session cookie (pgain_session), set HttpOnly, Secure, and SameSite=Lax, solely to keep you logged in. No third-party tracking cookies.
8. Contact
Questions or requests: wutthibhon.invesment@gmail.com