DevPass Supplemental Privacy Policy
Effective Date: April 26, 2026
Last Updated: August 20, 2026
DevPass privacy in plain English
A human-readable summary of the key points. This overview is for convenience only and is not legally binding — the full text below is what governs.
This policy adds DevPass-specific detail to the LLM Gateway Privacy Policy, which still governs everything else — legal bases, your GDPR and CCPA rights, security and international transfers.
We log tokens, cost, latency, model, provider and which coding tool sent the request. Your prompts and the model’s responses aren’t retained, and there is no setting to turn payload storage on.
Requests to /v1/responses are stateful, so their input and output items are stored for up to 30 days to make response chaining work. Send store: false to opt out.
Prompts are forwarded to the AI provider behind the model you chose — each applies its own retention and training policy. Enable No AI training in Settings to use only providers that explicitly opt API inputs out of model training.
We don’t sell your personal data and we never train our own models on your prompts or completions. Data is shared only with a small set of vetted sub-processors.
Request metadata is kept for the life of your subscription and billing records for 10 years where tax law requires it. You can access, export or delete your data at any time.
This Supplemental Privacy Policy describes how LLM Gateway (“we”, “our”, or “us”) collects, uses, and protects information when you use DevPass, our flat-rate subscription for AI coding tools, available at devpass.llmgateway.io.
This DevPass Privacy Policy is an addendum to, and incorporates by reference, the main LLM Gateway Privacy Policy (the “Base Policy”), which forms the base of how we handle your data. The Base Policy applies in full to DevPass and governs all topics not specifically addressed here — including our role as controller and processor, legal bases for processing, your privacy rights (GDPR, UK GDPR, CCPA/CPRA), security, international transfers, and children’s privacy. This DevPass Privacy Policy only adds DevPass- specific detail to the Base Policy.
Order of precedence. If there is a direct conflict between this DevPass Privacy Policy and the Base Policy with respect to DevPass, this DevPass Privacy Policy controls for that conflict only. In all other respects, the Base Policy remains in full force and effect.
1. Information We Collect
a. Account Information
When you sign up, we collect your name, email address, and authentication credentials. For paid plans, we also collect billing details (company name, country, payment method) processed securely through Stripe.
Your DevPass API key secret is shown only when it is created or rolled. We retain a keyed one-way hash and masked preview; authentication hashes the secret you present and compares the result. Previously issued keys remain valid and move to hash-only storage when rolled.
b. Usage and Request Data
We log technical metadata for every request routed through DevPass, including:
- Request and response timestamps, latency, finish reasons, and HTTP status codes
- Token counts (prompt, completion, cached, reasoning) and computed cost
- The model and provider used, the routing tier, and the source coding tool (Claude Code, Cursor, Cline, OpenCode, Codex, Autohand, etc.)
- IP address, user agent, and approximate region
DevPass is metadata only: we keep the counts, costs, and routing information listed above, and full request and response payloads (your prompts and the model output) are not retained in your DevPass logs or dashboard. There is no setting to turn payload storage on, on any DevPass plan — the configurable data retention available on pay-as-you-go LLM Gateway organizations does not apply to DevPass.
Exception — the Responses API. Requests to /v1/responses (used by tools such as Codex CLI) are stateful by design: so that previous_response_id chaining and GET /v1/responses/{id} work, the input and output items of those requests are held in dedicated storage for up to 30 days, after which they are automatically deleted. This applies regardless of retention settings and matches OpenAI’s own Responses API retention. Send store: false with the request to opt out; other endpoints, such as /v1/chat/completions and /v1/messages, are unaffected. Payloads may also be held transiently in memory or cache while a request is being processed.
c. Cookies and Local Storage
We use first-party cookies and local storage to keep you signed in, remember your UI preferences, and operate basic product analytics (PostHog). Browser-level Do Not Track signals are not currently a supported opt-out mechanism. To opt out of analytics, contact us at contact@llmgateway.io; we are working on a self-serve in-app toggle.
2. How We Use Information
- To operate, secure, and improve the DevPass service
- To meter usage, enforce plan allowances, and process billing
- To power dashboards (per-agent costs, sessions, and usage trends)
- To detect abuse, fraud, and policy violations
- To send transactional emails (receipts, plan changes) and, with consent, occasional product updates
As stated in the Base Policy, we do not sell your personal data, and we do not use your prompts or completions to train any model of ours.
3. Sharing With AI Providers
When you make a request, your prompt is forwarded to the AI provider you selected. Each provider applies its own privacy and data-retention policy to that traffic. You can enable No AI training in DevPass Settings to restrict routing to providers that explicitly state API inputs are not used to train models. Providers with an unknown training policy are excluded while this setting is enabled, so some models may be unavailable. The Base Policy’s sections on AI Providers and on stealth/undisclosed providers also apply to DevPass.
4. Sub-processors
DevPass uses the same sub-processors as the rest of the LLM Gateway platform. The complete, versioned list — including what each one processes, its primary processing locations, and how changes are notified — is maintained on the LLM Gateway Sub-processor page. That page is the authoritative disclosure and is updated independently of this supplemental policy.
5. Data Retention
This section supplements the Base Policy’s Data Retention terms:
- Account and billing data — kept for the life of your account, and deleted promptly when you delete it. Billing and accounting records — purchases, payments, and the transaction history of credits bought and spent — are retained to meet legal, tax, and accounting obligations for 10 years, even after you delete your account, after which they are deleted or anonymized
- Request metadata — kept for the life of your active DevPass subscription on every plan (Lite, Pro, and Max)
- Request payloads — not retained; prompts and responses are discarded once the request completes. The one exception is the Responses API described in Section 1b, whose stored responses are kept for up to 30 days and then deleted
- Logs and audit trails — kept for security and integrity for up to 12 months
6. Your Rights and Contact
Your privacy rights (including access, correction, deletion, export, objection, and the right to lodge a complaint with a supervisory authority), our security practices, and international transfer safeguards are described in the LLM Gateway Privacy Policy and apply to DevPass. To exercise any of these rights, or for questions about this Policy, email contact@llmgateway.io from the address associated with your account.
© 2026 LLM Gateway. All rights reserved.