Privacy Policy - LLM Proxy
This Privacy Policy explains how Marco Polo Research Lab LLC handles information when you use LLM Proxy.
LLM Proxy separates browser authentication, tenant configuration, model requests, and content-free usage records so each category is processed only for its stated purpose.
1. Scope
This policy applies to the public LLM Proxy website, the authenticated management app, the LLM Proxy API, and related support communications.
2. Information We Handle
- Account and authentication data supplied through MPR UI, TAuth, and Google Identity Services, including the name, email address, and profile image associated with the account.
- Tenant names, provider and model routing defaults, encrypted upstream provider credentials, and one-way digests of generated LLM Proxy client secrets.
- Prompts, message attachments, audio, and other request content while routing a request to the selected model provider and returning its response.
- Content-free usage metadata such as tenant, provider, model, operation, status, token counts, timing, and request outcome.
- Support communications and the technical records required to secure, operate, and troubleshoot the service.
3. Usage Record Content Boundary
LLM Proxy usage records do not store prompts, message attachments, input audio, transcripts, generated responses, raw provider credentials, or raw client secrets.
4. How We Use Information
- Authenticate users and protect account access.
- Route requests, apply tenant configuration, and return provider responses.
- Manage provider credentials and generated client access.
- Present usage, failure, and reliability information to authorized users.
- Secure, troubleshoot, maintain, and improve LLM Proxy.
- Respond to support, privacy, and legal requests.
5. Service Providers and Model Providers
Authentication is provided through MPR UI and TAuth, with Google Identity Services available for sign-in. Model request content is sent to the provider selected by the authenticated tenant and is subject to that provider's terms and privacy practices.
The public site uses GitHub Pages. Google Analytics and LoopAware receive website interaction and technical telemetry used to understand aggregate traffic and service quality.
6. Cookies and Browser Storage
TAuth uses secure HttpOnly session and refresh cookies for authentication. Browser JavaScript cannot read those cookies. The LLM Proxy backend receives and validates the configured session cookie through TAuth's published validator only to authorize protected LLM Proxy resources. Browser storage may retain interface preferences such as the selected theme; raw provider credentials and generated client secrets are not persisted in browser storage by the app.
8. Retention
Account, tenant configuration, credential, and usage records are retained while needed to operate the service, secure accounts, meet legal obligations, and resolve disputes. Request content is processed in transit and is excluded from the LLM Proxy usage record.
9. Security
We use access controls, transport security, encrypted storage for provider credentials, one-way secret digests, and content-free usage records to protect information. No system can guarantee absolute security.
10. Your Choices
You may request access, correction, export, or deletion of personal information, subject to applicable law and records we must retain. Contact support@mprlab.com to make a request or to disconnect an account.
11. Changes to This Policy
We may update this policy as LLM Proxy or applicable requirements change. The effective and last-updated dates on this page identify the current version.
12. Contact
For privacy questions or data requests, email support@mprlab.com. For legal notices, email legal@mprlab.com. Marco Polo Research Lab LLC can also be reached through https://mprlab.com.