LEGAL

Privacy Policy

How ModelLane collects, uses, and protects data when you use the ModelLane website and inference routing service.

1. Overview

ModelLane is an AI inference control plane operated by Galadriel Labs (“ModelLane,” “we,” “us,” or “our”), a company domiciled in New York, United States. This Privacy Policy describes how we collect, use, share, and protect information when you visit the ModelLane website (modellane.app) and use the ModelLane routing service (the “Service”).

The Service sits between your application and the model providers you choose. It routes each request to a provider based on the policies you configure. Because ModelLane is a routing layer, how your request content is handled depends in part on the providers you route to and the plan you are on. This policy explains what ModelLane itself does with your data; the model providers you select process content under their own terms.

2. Data we collect

2.1 Account and billing data

When you sign up or subscribe, we collect your name, email address, company, and billing information. Payments are processed by our payment provider; we do not store full card numbers on our servers.

2.2 API request data

When you call the Service, we process the prompts, completions, and payloads you send and receive so that we can route them to the provider you selected. We also process request metadata such as the model identifier, timestamp, token counts, latency, IP address, user agent, and API key identifier, along with error traces and diagnostic information when a request fails.

2.3 Provider credentials (BYOK)

If you bring your own provider keys, we store those credentials encrypted at rest and use them only to route your requests. Credentials are isolated per connection.

2.4 Website data

When you browse modellane.app we collect standard web analytics such as pages viewed, referrer, approximate location derived from IP address, and device and browser type. We use cookies only where needed to operate the site and for basic analytics.

3. How we use data

  • To route your inference requests and return responses.
  • To operate, monitor, and improve the reliability, performance, and security of the Service.
  • To detect and investigate abuse, fraud, and violations of our Terms of Service.
  • To bill for usage and manage your account.
  • To communicate with you about your account, service changes, and, if you opt in, product updates.

4. Model training

We do not train any model on your prompts or completions, and we do not use your request content to train, fine-tune, or otherwise alter the behavior of the models we route to. We also do not sell your prompts or completions, and we do not share them with advertisers or data brokers.

5. Data retention

Trace data — routing decisions, latency, spend, and request metadata — is retained according to your plan (Sandbox: 24 hours; Production: 30 days; Scale: 90 days; Business: 12 months) and then deleted, subject to our legal obligations.

Request content (prompts and completions) is processed in memory to route the request. It is not written to durable storage beyond what is necessary to route, log, and bill the request under your plan. Operational metadata such as token counts, latency, error codes, and related diagnostics may be retained longer for billing reconciliation, capacity planning, security, and abuse prevention.

Account and billing records are retained while your account is active and for the period required by applicable tax and accounting law after closure.

6. Zero data retention (Private Lane and Enterprise)

The Private Lane and enterprise plans support zero-retention routing to approved providers. When zero retention is configured, prompts and completions are not written to durable storage after processing, and only minimal operational metadata required to operate, secure, and bill the Service (such as timestamps, token counts, model, latency, and request IDs) is retained. Contact us for the specific retention terms that apply to your plan or agreement.

7. Sharing and subprocessors

  • Infrastructure providers. We run the Service on cloud and hardware partners under contractual confidentiality and data protection terms; they process data only on our instructions.
  • Payment and business tools. We share limited data with our payment processor, billing platform, and business communications tools.
  • Legal requests. We may disclose data to comply with valid legal process, to protect our rights or property, or to protect the safety of users or the public.
  • Business transfers. If ModelLane is involved in a merger, acquisition, or asset sale, your data may be transferred as part of that transaction, subject to this policy.

We do not sell personal data.

8. Security

We use industry-standard safeguards, including TLS encryption for data in transit, encryption at rest for stored credentials and logs, access controls on internal systems, and audit logging. ModelLane is not yet SOC 2 certified; current controls and audit status are described in the Trust Center. No method of transmission or storage is perfectly secure, and we cannot guarantee absolute security.

9. International data transfers

The Service is operated from data centers in the United States, with additional processing where our subprocessors operate. If you access the Service from outside the United States, your data will be transferred to and processed in the United States, which may have different data protection laws than your jurisdiction. By using the Service, you consent to this transfer. Customers with data residency requirements should contact us about private or single-tenant deployment options.

10. Your rights and choices

Depending on where you live, you may have rights to access, correct, delete, or port your personal data, or to object to or restrict certain processing. To exercise these rights, email privacy@modellane.app. We will verify your identity before acting on a request.

  • Delete your API keys at any time from your account.
  • Request deletion of your account and associated logs, subject to legal retention requirements.
  • Opt out of marketing emails using the unsubscribe link in any such email.

11. Children’s privacy

The Service is not directed to children under 13 (or the equivalent minimum age in your jurisdiction), and we do not knowingly collect personal data from them. If you believe a child has provided us personal data, contact us and we will delete it.

12. Changes to this policy

We may update this policy from time to time. We will post the new version on this page and update the “Last updated” date. For material changes, we will provide additional notice, such as by email or an in-product banner, before the changes take effect.

13. Contact

Questions, requests, or complaints about this policy can be sent to:

Galadriel Labs
New York, United States
Email: privacy@modellane.app
Website: https://modellane.app