Privacy & Cookie Policy
This policy explains how Frontier Cognition Inc, operator of NewRouters, handles information associated with the website, console, and API services.
Last updated: August 28, 2026Information we process
- Account and authentication information, such as email address, verification status, credential representations, sessions, invitation codes, and basic identity information supplied when you choose Google sign-in.
- API and service records, such as API key metadata, model and task parameters, task status, generated outputs, webhooks, usage, credits, costs, and necessary troubleshooting audit records.
- Payment and transaction records. Payment card details are handled by providers such as Stripe; we retain transaction results needed for credits, refunds, reconciliation, and compliance.
- Security and technical information, such as IP address, browser and device type, request time, errors, rate limits, and anti-abuse signals.
Cookies and third-party services
We use necessary cookies to maintain sign-in sessions, complete Google OAuth callbacks, prevent forged requests, and secure the service. Blocking these cookies may prevent sign-in or console features from working. Cloudflare Turnstile, Google OAuth, Stripe, object storage, and email providers may process information required to provide their services under their own policies.
We use signed, HttpOnly first-party visitor cookies (up to 90 days) and session cookies (a sliding 30-minute lifetime) to understand how people discover the service and associate visits with registration, API-key creation, the first actually billed API call, and Stripe funding. Attribution records include the same-origin landing-page path, language, model vendor and public model ID, the host of the referring site, standard UTM fields, marketing short links, and approved advertising click IDs. Click IDs are encrypted with AES-256-GCM. The attribution system does not retain IP addresses, full user agents, email addresses, complete external referrer URLs, or ordinary query parameters. Clearing cookies may cause a later visit to be treated as a new visitor.
This site loads Google Analytics 4 when a page opens. It measures public pages and the sign-in, registration, and password-recovery pages, and records successful sign-in or registration with the method used (email or Google). Page URLs sent to GA4 are sanitized to retain only standard UTM fields and approved advertising click IDs; search q values, invitation codes, OAuth code/state, error parameters, and first-party visitor, session, or user identifiers are excluded. We also do not send email addresses, account IDs, task IDs, or protected-console page views to GA4; Google signals and advertising-personalization signals are disabled. GA4 may use cookies and process technical information such as page path, title, referrer, browser, device, and approximate region. You can limit this processing through browser settings or the Google Analytics opt-out browser add-on.
Third-party policies and controls may change as providers update their services; review the privacy information supplied by those providers as well.
Purposes and sharing
We use information to create and protect accounts, deliver and improve API services, calculate usage and charges, process payments, provide support, detect abuse, troubleshoot failures, and meet legal obligations. We share information with infrastructure, payment, identity, security, analytics, and communications providers only as needed for these purposes, to comply with law, or to protect users and the platform. We do not sell personal information.
Retention, security, and international processing
Retention periods differ according to operational, audit, security, dispute-resolution, and legal needs. Encrypted advertising click IDs are cleared after 90 days, anonymous visit sessions are retained for up to 16 months, and user attribution snapshots are retained with the account record; we do not fabricate historical sources for existing users. GA4 data follows the retention settings of the corresponding property. We use access controls, encryption, credential isolation, and auditing to reduce risk, but no system can guarantee absolute security. Providers and infrastructure may operate outside your country or region and be subject to local law.
Your choices and contact
You may control cookies through your browser, stop using the service, or contact us to request access, correction, deletion, or restriction where applicable. Requests may be limited by identity verification, record-retention, security, or legal obligations.
For privacy questions, contact: [email protected]