Privacy Policy

For the LLM inference API at openrouter-api.aliru.ai. Version of 1 September 2026.

1. Controller

Aliru GmbH
Julius-Hatry-Straße 1, 68163 Mannheim, Germany
Represented by: Julian Kissel
Email: kontakt@aliru.de
Phone: +49 621 49088670

2. Data protection officer

Norton Engele
Email: privacy@sally.io or datenschutz@sally.io

Please address data protection enquiries to these addresses.

3. Scope

This policy applies exclusively to the use of the LLM inference API. It describes what data arises when requests to the language models are processed.

4. What happens to your inputs

The content of requests and responses is not stored. Prompts and generated text are processed in volatile memory only, for as long as the request is running, and are discarded afterwards. They are not written to disk, not logged and not transmitted to third parties.

No training takes place. Your data is not used to train, fine-tune or evaluate models.

This is enforced technically by running the inference software with request logging disabled (--disable-log-requests).

5. What data does arise

DataPurposeRetention
IP address, timestamp, path requested, status codeOperation, fault diagnosis, abuse prevention7 days, then deleted automatically
Number of tokens processed per requestBilling and capacity planningAggregated, not linked to content
System load metricsOperational monitoringNo personal reference
Content of prompts and responsesNot stored

The seven-day limit is technically enforced, not merely promised.

6. Legal basis

The operational data listed under clause 5 is processed on the basis of Art. 6(1)(b) GDPR (performance of the usage contract) and Art. 6(1)(f) GDPR (legitimate interest in secure and uninterrupted operation).

7. Place of processing

Processing takes place exclusively in Germany, in a data center in Falkenstein, Saxony. There is no transfer to third countries.

8. Processors

Service providerServiceLocation
Hetzner Online GmbHServers and data centerGermany

A data processing agreement pursuant to Art. 28 GDPR is in place with this provider.

Where the API is used through an intermediary such as OpenRouter, that party's own privacy policy governs the leg between you and the intermediary. This policy applies from the point the request reaches us.

9. Your rights

You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection (Art. 21 GDPR), as well as the right to lodge a complaint with a supervisory authority (Art. 77 GDPR).

Since content is not stored, a subject access request will in practice be limited to the operational data listed under clause 5 for the preceding seven days.

To exercise your rights, please contact privacy@sally.io.

10. Data processing on behalf of customers

Where you transmit personal data within your requests, you act as the controller and we act as your processor. In that case the parties shall conclude a data processing agreement pursuant to Art. 28 GDPR. Please contact the address above.

11. Security

Access is encrypted in transit at all times (TLS). The connection between the servers involved is additionally encrypted by VPN. Access to the systems is restricted to authenticated administrators.

12. Changes

We update this policy when the processes described here change. The version published here at the relevant time applies.