Legal
Privacy Policy
This policy explains what information PromptRail processes, why we process it, and the choices available to you.
Last updated: July 25, 2026
Information we collect
We collect account information such as your name, email address, and authentication details. We also process configuration data, API key metadata, budget settings, usage records, routing decisions, model identifiers, token counts, costs, and diagnostic events generated when you use PromptRail.
If you purchase a subscription or credits, our payment processor collects payment and billing information. PromptRail does not store complete payment card numbers.
How we use information
We use information to provide and secure the service, authenticate accounts, route AI requests, enforce budgets, calculate usage and charges, provide support, prevent abuse, improve reliability, and comply with legal obligations.
AI request processing
PromptRail Infinite is a hosted inference service. When you use Infinite, PromptRail receives the protocol request from your coding client. Depending on the request, this can include system instructions, conversation messages, tool definitions, tool results, structured-output settings, reasoning controls, and attachments. PromptRail transmits the protocol data needed to execute the selected declared route to that model provider. Modal hosts the PromptRail gateway, and the selected model provider processes the request under its own terms and privacy policy.
PromptRail processes raw prompts, responses, attachments, and tool arguments transiently to route and stream the request. PromptRail does not write that raw content, authorization headers, or provider credentials to application logs or execution receipts by default. Client cancellation is propagated to stop upstream work when the protocol and provider permit it.
PromptRail Plugins uses a different, local provider-inference path. Its narrower data boundary is described in the dedicated Plugins Privacy Policy.
Do not submit personal, confidential, or regulated information unless your use of PromptRail, Modal, and the selected provider is appropriate for that information.
Infinite credentials and routing records
PromptRail API keys are stored as one-way hashes. User-connected provider credentials are encrypted at rest and are available only to the authenticated internal execution path for that tenant. They remain stored until they are rotated, revoked, deleted with the account, or must be retained for a legal or security obligation.
Infinite stores sanitized execution receipts for reliability, usage, billing, and abuse prevention. A receipt can include tenant and route identifiers; policy and catalog versions; selected and executed model identifiers; capacity class; premium or degraded-mode status; hashed connection identity; attempt result and latency; token counts; estimated cost; and routing latency. It does not contain raw prompts, full responses, attachments, authorization headers, provider credentials, or full tool arguments. Execution receipts are configured to expire after 90 days.
Service providers and disclosures
We may share information with vendors that support hosting, authentication, payments, email, analytics, and model routing. We may also disclose information when required by law, to protect users or the service, or as part of a merger, financing, acquisition, or sale of assets.
Retention and security
We retain information for as long as needed to operate the service, maintain business and security records, resolve disputes, and meet legal obligations. We use reasonable administrative and technical safeguards, but no method of storage or transmission is completely secure.
Your choices
You may request access to, correction of, or deletion of your personal information. Depending on where you live, you may have additional rights under applicable privacy law. We may need to verify your identity before completing a request.
Children
PromptRail is not directed to children under 13, and we do not knowingly collect personal information from children under 13.
Changes and contact
We may update this policy as the service changes. The date above identifies the latest version. Questions and privacy requests can be sent to support@promptrail.ai.
