Legal

Privacy Policy

Last updated: April 12, 2026

Information We Collect

We collect information you provide when creating an account (name, email), organization details, and API usage data from connected LLM providers. We do not collect or store the content of your AI conversations or prompts.

How We Use Data

Your data is used solely to provide cost tracking, optimization recommendations, and billing services. We aggregate anonymized usage patterns to improve our recommendation engine. We never sell your data to third parties.

API Key Security

Provider API keys are encrypted with AES-256 before storage in Supabase Vault. Keys are used exclusively for read-only access to usage/billing data. We never make API calls to LLM providers on your behalf.

Data Retention

Usage data is retained according to your plan tier (7 days to 1 year). You can request full data deletion at any time by contacting support or using the account deletion feature in Settings.

Self-Hosted Deployment

For teams that require full data sovereignty, AgentCostPilot offers a self-hosted Docker deployment option on Business and Enterprise plans. With self-hosted, all data — including usage logs, API keys, recommendations, and analytics — stays entirely on your own infrastructure. No data is transmitted to AgentCostPilot servers. The self-hosted version connects directly to your own PostgreSQL database and runs behind your firewall.

Third-Party Integrations

When you connect third-party data sources (LiteLLM, LangChain, RelayPlane), ACP receives only cost metadata: model name, token counts, cost, and latency. We never receive prompt content, response content, or any personally identifiable information from these integrations.

GDPR & CCPA

We comply with GDPR and CCPA requirements. You have the right to access, correct, export, and delete your personal data. To exercise these rights, contact support@agentcostpilot.com.

Contact

Questions about privacy? Email support@agentcostpilot.com.