Privacy Policy

Last updated: June 16, 2026

This Privacy Policy explains how GroundRoute, Inc. (“GroundRoute”, “we”) collects, uses, shares, and protects information when you use the GroundRoute API, MCP server, and web console (the “Service”). GroundRoute is a routing and caching layer for AI-agent search; we are a data controller for your account data and act on your behalf when processing the queries you send through the Service.

1. Information we collect

CategoryExamplesWhy
AccountEmail address, hashed password, organization name, account settingsCreate and secure your account
API credentialsAPI keys (stored only as a SHA-256 hash; plaintext shown once at creation)Authenticate your requests
BYOK provider keysSearch-provider keys you supply, encrypted at rest (we store only a non-reversible fingerprint for display)Route requests on your own keys
Query & usage dataSearch query text, routing decisions, cache hit/miss, latency, timestamps, request and IP metadataOperate, meter, secure, and improve the Service
Cached resultsResults returned by Search Providers, cached to avoid duplicate callsReduce cost and latency
BillingPrepaid credit balance, usage charges, payment metadata via Stripe (card token only — we never store full card numbers)Process payments and gain-share billing

We do not require you to send personal data in your queries, and we ask that you not submit sensitive personal information you don't need routed. Query content you send is processed as described below.

2. How we use information

  • To provide the Service: classify and route queries to Search Providers, cache and return results.
  • To authenticate requests, enforce rate limits and quotas, and meter usage for billing.
  • To process payments and compute gain-share charges.
  • To secure the Service — detect and prevent abuse, fraud, and unauthorized access.
  • To operate and improve performance, reliability, and routing quality (using aggregate and operational data).
  • To communicate with you about your account, security, and service changes.

3. Queries and caching

When you send a request, we forward the query to one or more third-party Search Providers and may cache the response so identical future requests can be served without a new provider call. Cached results may be shared across your own requests. We do not sell your queries, and we do not use your query content to train machine-learning models. The Search Providers receive your query to fulfill it and process it under their own terms and privacy policies.

4. Sub-processors and sharing

We share data only with service providers that help us run the Service, under contractual confidentiality and security obligations:

Sub-processorPurposeData
Search Providers (Serper, Brave, Exa, Tavily, Firecrawl, Perplexity)Fulfill search / page-fetch requestsQuery text
StripePaymentsBilling and payment metadata (card tokens; no full card numbers reach us)
Supabase (Postgres, EU)Primary databaseAccount, usage, billing, encrypted keys
Upstash (Redis)Caching, rate limiting, sessionsCached results, counters, session ids
Fly.ioAPI hostingRequest processing
VercelWeb console hostingWeb requests
ResendTransactional emailEmail address

We may also disclose information if required by law, to enforce our Terms, or to protect the rights, safety, and security of GroundRoute, our customers, or the public. If GroundRoute is involved in a merger, acquisition, or asset sale, information may be transferred subject to this Policy. We do not sell personal information.

5. Security

We apply industry-standard safeguards: encryption in transit (TLS), encryption of BYOK provider keys at rest, hashing of passwords (PBKDF2) and API keys (SHA-256), tenant isolation in the database, server-side session management, rate limiting, and webhook signature verification. No method of transmission or storage is perfectly secure, but we work to protect your data and to limit access on a need-to-know basis.

6. Data retention

We retain account data while your account is active and as needed to provide the Service. Usage and billing records are retained as required for accounting, tax, and legal purposes. Cached results expire on a rolling basis. When you close your account, we delete or anonymize personal data within a reasonable period, except where retention is required by law or for legitimate business needs (e.g., billing records, fraud prevention).

7. International transfers

Our primary database is hosted in the EU. Some sub-processors may process data in other countries. Where data is transferred across borders, we rely on appropriate safeguards (such as Standard Contractual Clauses) as required by applicable law.

8. Your rights

Depending on your location (including under the GDPR and similar laws), you may have rights to access, correct, delete, port, or restrict processing of your personal data, and to object to certain processing. To exercise these rights, contact privacy@groundroute.ai. You may also access and update much of your account data directly in the console. If you are in the EEA/UK, you have the right to lodge a complaint with your data protection authority.

9. Cookies

The web console uses strictly necessary cookies for authentication and security (e.g., your session). We keep non-essential cookies to a minimum; any analytics we use are configured to respect privacy and are not used to sell your data.

10. Children

The Service is not directed to children under 16, and we do not knowingly collect their personal data.

11. Changes

We may update this Policy. We will revise the “Last updated” date and, for material changes, provide additional notice where appropriate. Continued use of the Service after changes take effect constitutes acceptance.

12. Contact

Questions or requests? Contact privacy@groundroute.ai.

GroundRoute, Inc. · Terms of Service · Home