policy · matches the machines

Privacy

This page is written against the Hostinger VPS stack and this console's database. It is not a template. If the logging behavior changes, this page changes first. See the file-by-file audit.

Two hosts

api.demonroute.com is a Hostinger VPS we operate (new-api, Caddy, Postgres, Redis, billing-bridge). That is the path that carries your prompts. We configure it so client IPs are not persisted.

demonroute.com (marketing site and console) is served from the same VPS by the same Caddy — access logs discarded there too. Our application code never reads the client address. Session rows that Better Auth would stamp with an IP are stripped to null on insert by database trigger.

Never collected (application DB)

  • Client IP addresses. Session ipAddress is forced null.
  • User-agent strings on sessions. Forced null.
  • On anonymous keys: email, legal name, card numbers, billing address.
  • Prompt bodies in a searchable dump. Usage rows store model, token counts, cost, upstream id — not the text.
  • Training on your content. We run no training jobs, fine-tunes, or evals on user prompts, and we sell no data. Prompts are proxied to the upstream host that serves the model; we do not retain them.

Collected, then discarded

  • TLS peer address at Caddy — used to terminate HTTPS, never written (access logs discarded).
  • In-memory rate-limit counters hashed from the TCP peer. RAM only. Lost on restart. Never on disk.
  • Verification and password-reset tokens, hashed, until used or overwritten.

Collected and kept

  • Username, password hash (Better Auth).
  • On standard accounts only: email, email-verified flag.
  • Prepaid balance, ledger, API key hashes (not the secret after mint), usage token counts.
  • Crypto payment ids from NOWPayments / BTCPay (the wallet is yours; we store the invoice id to credit quota).
  • Anonymous flag, recovery-ack flag, suspend flag.

Retention

Usage events: 90 days, then we drop them. Ledger (money): kept while the account exists, for disputes. Session rows: until they expire (Better Auth), with IP/UA already null. Access logs on the VPS: not kept. Postgres logs: connections and statements off.

What upstream providers see

The request body (your prompt, your parameters) and our VPS IP. They do not see your IP. They do not see your email. They do not see your username. That is a feature of a reverse proxy, not a slogan.

Anonymous keys

Username + password. No mailbox. No recovery. Crypto deposits only. Complimentary lane unlocks with any deposit. Same catalog. Read the anonymous terms.

Cards

Card deposits go through NOWPayments fiat on-ramp (pay_currency USD) on standard accounts only. We do not use Stripe. We never put a card checkout in front of an anonymous key. Card data is identity; the on-ramp provider may run its own KYC.

Last aligned to the stack on 16 September 2026. Questions: admin@demonroute.com.