Privacy Policy
Last updated: June 16, 2026
This Privacy Policy explains how GroundRoute, Inc. (“GroundRoute”, “we”) collects, uses, shares, and protects information when you use the GroundRoute API, MCP server, and web console (the “Service”). GroundRoute is a routing and caching layer for AI-agent search; we are a data controller for your account data and act on your behalf when processing the queries you send through the Service.
1. Information we collect
| Category | Examples | Why |
|---|---|---|
| Account | Email address, hashed password, organization name, account settings | Create and secure your account |
| API credentials | API keys (stored only as a SHA-256 hash; plaintext shown once at creation) | Authenticate your requests |
| BYOK provider keys | Search-provider keys you supply, encrypted at rest (we store only a non-reversible fingerprint for display) | Route requests on your own keys |
| Query & usage data | Search query text, routing decisions, cache hit/miss, latency, timestamps, request and IP metadata | Operate, meter, secure, and improve the Service |
| Cached results | Results returned by Search Providers, cached to avoid duplicate calls | Reduce cost and latency |
| Billing | Prepaid credit balance, usage charges, payment metadata via Stripe (card token only — we never store full card numbers) | Process payments and gain-share billing |
We do not require you to send personal data in your queries, and we ask that you not submit sensitive personal information you don't need routed. Query content you send is processed as described below.
2. How we use information
- To provide the Service: classify and route queries to Search Providers, cache and return results.
- To authenticate requests, enforce rate limits and quotas, and meter usage for billing.
- To process payments and compute gain-share charges.
- To secure the Service — detect and prevent abuse, fraud, and unauthorized access.
- To operate and improve performance, reliability, and routing quality (using aggregate and operational data).
- To communicate with you about your account, security, and service changes.
3. Queries and caching
When you send a request, we forward the query to one or more third-party Search Providers and may cache the response so identical future requests can be served without a new provider call. Cached results may be shared across your own requests. We do not sell your queries, and we do not use your query content to train machine-learning models. The Search Providers receive your query to fulfill it and process it under their own terms and privacy policies.
4. Sub-processors and sharing
We share data only with service providers that help us run the Service, under contractual confidentiality and security obligations:
| Sub-processor | Purpose | Data |
|---|---|---|
| Search Providers (Serper, Brave, Exa, Tavily, Firecrawl, Perplexity) | Fulfill search / page-fetch requests | Query text |
| Stripe | Payments | Billing and payment metadata (card tokens; no full card numbers reach us) |
| Supabase (Postgres, EU) | Primary database | Account, usage, billing, encrypted keys |
| Upstash (Redis) | Caching, rate limiting, sessions | Cached results, counters, session ids |
| Fly.io | API hosting | Request processing |
| Vercel | Web console hosting | Web requests |
| Resend | Transactional email | Email address |
We may also disclose information if required by law, to enforce our Terms, or to protect the rights, safety, and security of GroundRoute, our customers, or the public. If GroundRoute is involved in a merger, acquisition, or asset sale, information may be transferred subject to this Policy. We do not sell personal information.
5. Security
We apply industry-standard safeguards: encryption in transit (TLS), encryption of BYOK provider keys at rest, hashing of passwords (PBKDF2) and API keys (SHA-256), tenant isolation in the database, server-side session management, rate limiting, and webhook signature verification. No method of transmission or storage is perfectly secure, but we work to protect your data and to limit access on a need-to-know basis.
6. Data retention
We retain account data while your account is active and as needed to provide the Service. Usage and billing records are retained as required for accounting, tax, and legal purposes. Cached results expire on a rolling basis. When you close your account, we delete or anonymize personal data within a reasonable period, except where retention is required by law or for legitimate business needs (e.g., billing records, fraud prevention).
7. International transfers
Our primary database is hosted in the EU. Some sub-processors may process data in other countries. Where data is transferred across borders, we rely on appropriate safeguards (such as Standard Contractual Clauses) as required by applicable law.
8. Your rights
Depending on your location (including under the GDPR and similar laws), you may have rights to access, correct, delete, port, or restrict processing of your personal data, and to object to certain processing. To exercise these rights, contact privacy@groundroute.ai. You may also access and update much of your account data directly in the console. If you are in the EEA/UK, you have the right to lodge a complaint with your data protection authority.
9. Cookies
The web console uses strictly necessary cookies for authentication and security (e.g., your session). We keep non-essential cookies to a minimum; any analytics we use are configured to respect privacy and are not used to sell your data.
10. Children
The Service is not directed to children under 16, and we do not knowingly collect their personal data.
11. Changes
We may update this Policy. We will revise the “Last updated” date and, for material changes, provide additional notice where appropriate. Continued use of the Service after changes take effect constitutes acceptance.
12. Contact
Questions or requests? Contact privacy@groundroute.ai.
GroundRoute, Inc. · Terms of Service · Home