Privacy Policy
Last updated: 27 June 2026
This Privacy Policy explains how Burnbreaker ("we", "us") handles personal data when you use the Service. We act as the data controller for the personal data described here. We aim to comply with the EU General Data Protection Regulation (GDPR). You can contact us at support@burnbreaker.com.
1. What we collect
- Account data: your email address and a hashed password.
- Billing data: subscription status and a customer identifier from our payment processor (Stripe). We do not store your full card details; card data is handled by Stripe.
- Usage and operational data: gateway keys (stored hashed), and run metadata you generate (run IDs, configured caps, amounts spent, call counts, timestamps, and related events) used to provide the dashboard and enforce caps.
- Your LLM provider API keys: when you send requests through the proxy, you include your own provider API key. This key is forwarded to the provider to fulfil your request and is not stored by us.
- Technical data: standard server logs (e.g. IP address, request metadata) used for security and operating the Service.
2. What we do NOT do
- We do not sell your personal data.
- We do not store your full LLM provider API keys.
- We do not store your payment card numbers.
3. Why we process it (legal bases)
- To provide the Service (performance of our contract with you): account, billing, and run data.
- Legitimate interests: security, fraud prevention, and operating and improving the Service.
- Legal obligations: e.g. accounting and tax record-keeping.
4. Sub-processors and third parties
We use third-party providers to run the Service, including:
- Stripe, for payment processing.
- Render, for hosting and infrastructure.
- Namecheap Private Email, for support email.
- Your chosen LLM providers (e.g. Anthropic, OpenAI), to which your requests are forwarded under your own account and their terms.
5. International transfers
Some providers may process data outside the EU/EEA. Where they do, appropriate safeguards (such as Standard Contractual Clauses) are intended to apply.
6. Retention
We keep personal data for as long as your account is active and as needed to provide the Service, then for any period required by law (e.g. accounting records). You can request deletion (see below).
7. Your rights
Under the GDPR you have the right to access, rectify, erase, restrict, or object to processing of your personal data, and to data portability. To exercise these rights, contact support@burnbreaker.com. You also have the right to lodge a complaint with the Swedish data protection authority (Integritetsskyddsmyndigheten, IMY).
8. Security
We use measures such as password hashing, hashed gateway keys, and encrypted transport (HTTPS). No system is perfectly secure, but we take reasonable steps to protect your data.
9. Changes
We may update this policy and will post the updated version with a new "last updated" date.
10. Contact
Privacy questions: support@burnbreaker.com