Amux

Privacy Policy

Last updated August 15, 2026

What Amux collects, how we use and retain it, and how you can exercise your rights.

Amux is an LLM API gateway. Requests are forwarded to upstream model providers according to your configuration and the result is returned to the caller. Because the platform sits in the request path, some data necessarily passes through Amux. This policy explains what data that is, how it is used, and how long it is retained.

What we collect

Account information. Signing in requires an email address; if you use Google or GitHub, we receive your email and avatar from them. We never collect passwords — sign-in is by one-time code or third-party authorization.

API keys. A key is shown in full exactly once, at creation. We store only its hash and prefix, which means we cannot recover a key you have lost.

Call data. Every call records metadata: timestamp, model, provider, token usage, latency, status code, failure reason. Whether request and response bodies are recorded is under your control — it can be turned off per key or per call, after which only the metadata above is kept.

Billing and usage. For invoicing and reconciliation we retain aggregated usage records long-term. This survives deletion of the detailed logs — without it, past invoices could not be reproduced.

Technical information. Your IP and browser identifier when visiting the site, plus a small number of cookies (language preference, theme, session). We use no advertising trackers.

On-site search terms. Search terms entered into the site search box are recorded to improve documentation coverage and search quality. We keep only the de-identified term itself, the language, how many results it returned, and whether a result was opened, aggregated into per-day counts. We do not record who searched, IP addresses, or per-search logs. Terms that look like credentials are discarded and email addresses are masked, with both checks running in the browser before submission.

Where your prompts go

Your request content is forwarded to the upstream provider you selected or that routing resolved to, and is then subject to that provider's own privacy policy. The model catalog lists which providers serve each model so you can pin or avoid specific providers when needed.

We do not train any model on your requests or responses, and we do not share them with third parties beyond the upstream inference call itself.

How long we keep it

DataRetention
Call metadata90 days by default, configurable per workspace
Request and response bodies (chat)Not recorded by default; deleted alongside metadata when enabled
Image and video prompts and reference materialRetained 30 days by default, then cleared; artifact files are cleaned up separately
Aggregated usage and billingLong-term (statutory financial records)
On-site search termsPer-day counts only, no per-search log
Account informationFor the life of the account

Generation tasks are an exception to the row above and need saying plainly. Prompts, reference material, and parameters for image and video generation are stored with the task by default and are not affected by the "disable body logging" setting: these tasks are asynchronous, results are retrieved minutes to tens of minutes later, and retrieval, retries, and billing disputes all depend on that input. They are cleared on the schedule in the table above.

Generated artifacts and reference material you upload are held in publicly readable object storage: the addresses are unguessable (they contain a random id), but anyone who has one can open it without signing in. Do not treat it as private storage, and do not forward those addresses to people who should not see the content. Artifacts are cleaned up periodically, after which the address stops working.

How we protect it

Keys and upstream credentials are stored encrypted; all traffic is over TLS. Access to production data is granted on a least-privilege basis and audited.

No system is perfectly secure. If a confirmed security incident affects user data, Amux will notify affected users as soon as reasonably possible.

Your rights and choices

  • View and export: usage and call records are available in the console
  • Turn off body logging: changeable at any time, effective for subsequent calls
  • Deletion: you may request deletion of your account and associated data. Aggregated billing records are excluded, as statutory retention applies
  • Contact us: support@amux.ai

Minors

Amux is built for developers and businesses, not for minors. We do not knowingly collect personal information from minors.

Changes to this policy

When this policy changes we update the effective date at the top of this page. For material changes, we notify you by email or in the console.