Privacy Policy
1. Introduction and Scope
1.1 Purpose
This Privacy Policy (this "Policy") describes how LMIW LLC ("we," "us," or "our") collects, uses, discloses, stores, and otherwise processes information in connection with OpenCheese.Dev - Intelligent AI Routing (the "Platform" or "Services") available at https://opencheese.dev.
The Services are an AI API gateway: authentication, routing, metering, and billing for large-language-model and related AI requests to configured upstream providers, together with a user dashboard and related tools (which may include optional features such as chat, referrals, plans, and prepaid balance top-ups).
1.2 Relationship to Terms of Service
This Policy forms part of our relationship with users and should be read together with our Terms of Service. Capitalized terms not defined here have the meanings given in the Terms of Service, where applicable.
1.3 Contact
Privacy-related inquiries may be sent to: [email protected].
2. Geographic Scope and Regulatory Position
2.1 Restricted Regions (Contractual)
The Services are not offered to persons who are residents, citizens, or located in, or who access the Services from:
- the United States of America (including territories);
- all European Union (EU) and European Economic Area (EEA) member states;
- the Russian Federation; or
- countries or persons subject to applicable international sanctions (including OFAC, UN, or similar regimes) or designated high-risk in a manner that, in our judgment, makes service inappropriate
(collectively, "Restricted Regions"), as further described in our Terms of Service.
You must not use the Services if you are in a Restricted Region. We may refuse, limit, or terminate access where we believe the Restricted Region rules are violated. Technical blocking may be added or changed over time; the contractual prohibition applies whether or not a technical block is active at a given moment.
2.2 GDPR, UK GDPR, and U.S. State Privacy Laws
We do not target or market the Services to users in the EU/EEA, the United Kingdom, or the United States. The Services are contractually limited as described above.
Because of that targeting and offer model, we do not intend the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the UK GDPR, or U.S. state privacy laws such as the California Consumer Privacy Act as amended by the CPRA ("CCPA/CPRA") (or similar U.S. state laws) to apply to the delivery of the Services to our intended user base.
If a competent authority determines that any such law applies to a specific processing activity, we will handle that activity in accordance with applicable mandatory requirements.
2.3 Baseline Principles
Regardless of the foregoing, we maintain the following baseline principles:
- data minimization — collect only what is reasonably needed for stated purposes;
- purpose limitation — use information for disclosed, legitimate operational purposes;
- security — apply reasonable technical and organizational measures; and
- transparency — describe practices in this Policy.
2.4 Controller
For purposes of this Policy, the entity responsible for determining the purposes and means of processing is:
LMIW LLC
Jurisdiction of organization: Nevis, Federation of Saint Kitts and Nevis
Contact: [email protected]
3. Information We Collect
We collect the categories of information described below.
3.1 Account and Authentication Data
If you create or use an account, we may collect:
- account identifiers, display names, and profile fields you provide;
- authentication data from supported sign-in methods (for example OAuth identity-provider identifiers and email addresses the provider shares with us, or a public wallet address if you choose wallet-based sign-in);
- session tokens and related security signals; and
- preference settings (language, theme, and similar UI preferences).
3.2 API Keys and Access Credentials
We generate and store user API key identifiers and cryptographic hashes or equivalent secure representations of secret key material so we can authenticate gateway requests (typically via Bearer token authentication). We do not re-display full secret key values after the one-time reveal at issuance. You are responsible for safeguarding keys we show you once.
3.3 Technical and Security Data
We may collect and process:
- Internet Protocol (IP) addresses and related connection metadata appearing in server access logs (for security, abuse investigation, operations, and troubleshooting);
- browser type, version, and language settings;
- device type, operating system, and similar device identifiers where available;
- referring URLs, pages viewed, timestamps, and access logs;
- API request metadata (endpoints, status codes, latency indicators, error codes); and
- cookies, local storage, or similar technologies for session integrity, security, consent records, and essential platform operation.
We do not currently use IP addresses as a country geofencing system. IP data in logs is operational, not a map of user identity in our product database.
3.4 Usage, Metering, and Billing Data
To operate the gateway and bill usage, we may process:
- model and provider identifiers selected or resolved for a request;
- token counts, cache metrics, and related usage statistics;
- estimated and billed costs, plan or balance deductions, and delivery outcomes;
- session or request identifiers (including client-supplied or generated session UUIDs);
- latency, retry, and routing metadata; and
- prepaid balance, plan entitlements, credit-code redemptions, and payment or top-up records (amount, currency, status, provider reference, timestamps).
3.5 Request Content (Prompts and Completions)
When you use the gateway, prompt text, messages, files or attachments you submit, tool payloads, and model outputs are processed as needed to:
- transmit the request to the selected upstream AI provider(s);
- stream or return responses to you;
- enforce limits, optional prompt filters you configure, and acceptable-use rules; and
- troubleshoot abuse, billing disputes, or technical failures.
We do not sell request content. Upstream providers process content under their own terms and privacy practices when the request is routed to them. See Section 6.2 and our Terms of Service regarding provider practices we do not control.
3.6 Context Compaction Summaries
If context compaction features are enabled for your account or key, we may store model-generated summaries of conversation context (derived from messages you send through the gateway) so later requests can reuse a compacted history. Those summaries are operational data associated with your account and session identifiers while the account exists.
3.7 Chat and Community Features (If Used)
If you use optional chat or community features on the Platform, we may process:
- public and private message bodies;
- attachments (files you upload);
- profile display names, colors, and moderation status;
- mentions and related metadata; and
- moderation records, which may include the text of messages that were blocked.
3.8 Support and Communications
If you contact us, we may process the content of your messages, contact details, and related correspondence.
3.9 Analytics (Optional Product Setting)
Subject to your cookie settings, we may process aggregated or pseudonymous usage metrics via tools such as Cloudflare Zaraz and Google Analytics to understand how the site is used and improve the product. You can change this preference in Cookie settings.
3.10 Payment and Top-Up Data
If you top up balance or purchase a plan through a supported processor, we may receive payment status, amounts, currency, transaction references, and related metadata. Full payment-card numbers are handled by third-party processors, not stored by us as a primary card vault. Optional crypto-related top-up methods, if offered, exist only to fund account balance.
Payment processors may send webhook payloads that we store as operational records for reconciliation and dispute handling.
3.11 Information We Do Not Collect as Primary Purpose
We do not request or store:
- private keys, seed phrases, or wallet recovery secrets;
- full payment-card PAN data on our systems as a card-on-file vault; or
- government ID documents unless we expressly request them for a specific compliance review.
3.12 Sources of Information
Information comes from:
- you (account setup, dashboard use, API traffic, chat, support);
- your devices and browsers;
- identity providers and authentication flows you choose;
- upstream AI providers (usage and status metadata);
- payment or top-up processors;
- security and edge providers; and
- automated systems on the Platform (logs, metering, routing).
4. Purpose of Data Processing
We process information to:
4.1 Provide the Services
- authenticate users and API keys;
- route AI requests to configured providers;
- return model outputs;
- operate the dashboard, plans, balances, chat (if enabled), and configuration features you use.
4.2 Metering, Billing, and Account Administration
- measure usage and compute charges;
- debit plans or prepaid balance;
- record transactions and payment/top-up history;
- prevent double-spend of credits and enforce quotas.
4.3 Security and Operations
- detect abuse, credential stuffing, key leakage, and anomalous traffic;
- operate and secure the Platform;
- investigate incidents and enforce our Terms;
- maintain access logs for security and troubleshooting.
4.4 Restricted Region and Compliance Rules
- enforce contractual Restricted Region rules where we choose to refuse or terminate access;
- support sanctions and export-control compliance decisions at a commercial and operational level;
- maintain records needed for those decisions.
4.5 Legal and Operational Administration
- respond to lawful requests where required;
- enforce agreements;
- maintain business records, audits, and accounting documentation as applicable.
4.6 Product Improvement (Limited)
- understand reliability, latency, and feature usage at an aggregate level;
- fix bugs and improve routing and UX;
- run optional analytics according to your cookie settings.
4.7 Statistics After Account Closure
After an account is closed or identifiers are removed, we may retain de-identified usage and billing records (without email or account profile) for statistics, financial reporting, fraud prevention, and operational analysis. Those records are not intended to identify you.
5. Legal Bases and Justification (General Framework)
Because of our geographic offer model, detailed statutory bases under GDPR or U.S. state privacy statutes are not intended to apply to our primary user base. As a general commercial and good-practice framework, processing is justified by:
- performance of a contract or steps prior to entering a contract (providing the Services you request);
- legitimate interests in security, fraud prevention, metering integrity, and platform operations; and
- legal obligations where applicable mandatory law requires retention or disclosure.
If mandatory law in a specific case requires a different basis or additional notice, we will comply with that mandatory law.
6. Third-Party Services and Infrastructure
We use carefully selected third parties to operate the Platform. Categories include:
6.1 Security and Edge Infrastructure
DDoS protection, CDN, bot management, and related edge services (for example, services of the type offered by Cloudflare).
6.2 Upstream AI Providers
Model providers and related inference endpoints (for example OpenAI-compatible APIs, Anthropic, Google, Alibaba, DeepSeek, and other configured providers). When you submit a request, the content of that request and associated metadata are disclosed to the provider(s) selected for routing so the inference can be performed.
Important: Providers may publish statements that they do not train models on API data or that they retain data only for limited periods. We do not control, audit, or guarantee any provider’s internal logging, retention, security, employee access, subprocessors, training practices, or policy changes. Once content leaves our gateway to a provider, that provider’s terms and practices apply to their processing. See also our Terms of Service.
6.3 Identity and Authentication Providers
OAuth or similar identity providers you choose for sign-in, and any wallet-auth verification components if you use wallet-based login.
6.4 Hosting and Operations
Cloud hosting, storage, logging, monitoring, and backup providers necessary to run the Services.
6.5 Payment and Top-Up Processors
Third-party payment processors and optional crypto payment processors used solely to credit prepaid balance or settle plan purchases.
6.6 Analytics
Analytics tools (for example Cloudflare Zaraz and Google Analytics) subject to your cookie settings.
6.7 Communications
Email or ticketing providers if you contact support.
6.8 Role of Third Parties
Third parties process data only as needed to provide their services to us or as independent controllers where they determine their own purposes (for example, an upstream AI provider processing prompts under its own terms). We do not authorize third parties to sell your personal information obtained from us for their own marketing.
7. Prompt Filter (User Tool, Not a Privacy Guarantee)
The Platform may offer an optional Prompt Filter feature that lets you configure literal text substitutions applied to certain outbound request text before it is sent to upstream providers.
You should understand that:
- the feature is optional and is typically disabled by default until you enable it for a key and create rules;
- it performs user-defined text replacement, not automatic PII detection, not legal redaction, and not a complete content firewall;
- depending on mode and configuration, it may apply only to limited parts of a request (for example, not every message role, and not non-text blocks such as images or file attachments);
- it does not filter model outputs; and
- it may be unavailable in some deployment configurations.
Prompt Filter does not make OpenCheese responsible for what reaches upstream providers, or for how providers process data. You remain solely responsible for what you submit. Do not rely on Prompt Filter as a substitute for avoiding secrets, credentials, regulated data, or highly sensitive content.
8. Disclosures of Information
We may disclose information:
- to service providers under appropriate contractual or operational controls for the purposes in Section 4;
- to upstream AI providers as necessary to fulfill your API requests;
- to professional advisors (legal, accounting, security) under confidentiality obligations;
- in corporate transactions (merger, acquisition, financing, or sale of assets), subject to continued protection consistent with this Policy;
- to competent authorities when we believe disclosure is required by law, legal process, or to protect rights, safety, or security; and
- with your direction or consent, including when you integrate third-party clients that call our API with your keys.
We do not sell personal information.
9. International Transfers
We may process and store information on servers and with providers located outside your country of residence, including jurisdictions that may not provide the same legal protections as your home country. By using the Services, you acknowledge such transfers as necessary to operate a globally reachable AI gateway subject to our Restricted Region rules.
10. Data Security
10.1 Measures
We implement reasonable technical and organizational measures appropriate to the nature of the Services, which may include:
- transport encryption (TLS) for public endpoints;
- access controls and least-privilege practices for production systems;
- hashing or equivalent protection of user API secrets at rest;
- network edge protections against common attacks; and
- logging and monitoring for security-relevant events.
10.2 Credentials
You are solely responsible for safeguarding your account credentials, API keys, and devices.
10.3 No Absolute Security
No method of transmission or storage is completely secure. We cannot guarantee absolute security of information.
10.4 Incident Response
If we become aware of a security incident affecting personal information we control, we will take reasonable steps to investigate, mitigate, and, where we consider it appropriate or required, notify affected users or authorities.
11. Data Retention
11.1 General
We retain information as long as reasonably necessary for the purposes described in this Policy, including security, billing integrity, dispute resolution, statistics, and legal compliance, unless a longer or shorter period is required or permitted by law.
11.2 Gateway Usage and Billing
Usage transactions, metering aggregates, billing entries, audit logs, payment events, and similar operational records are generally retained for the life of our operational need. There is currently no automated deletion schedule for gateway usage history.
11.3 Context Compaction Summaries
Context compaction summaries are retained while useful for the feature and operations, and may remain after related sessions end unless removed in connection with account handling or a successful deletion request we can fulfill.
11.4 Chat
For optional chat features, unpinned public messages are purged on a configured schedule (default approximately seven (7) days, subject to admin configuration). Pinned public messages, private messages, attachments not covered by that purge, and moderation records may be retained longer or until manually removed.
11.5 Server Logs
Access and application logs (which may include IP addresses and request metadata) are retained according to our infrastructure and logging pipeline settings.
11.6 Deletion and Anonymization
When retention is no longer necessary, we delete or de-identify information where feasible. Residual copies may remain in backups for a limited time until rotated.
12. Cookies and Similar Technologies
We use:
- Necessary cookies and storage — required for security, authentication sessions, consent records, language/theme preferences, and basic app functionality; and
- Analytics cookies — controlled through Cookie settings on the landing page and dashboard. Analytics tools (such as Cloudflare Zaraz and Google Analytics) may measure site usage so we can improve OpenCheese. You can change your preference at any time.
Declining analytics does not remove necessary storage required to run the Service. If you withdraw analytics consent, we attempt to clear related analytics cookies via our privacy cleanup endpoint where technically feasible.
13. Children's Privacy
The Services are not directed to individuals under 18 years of age. We do not knowingly collect personal information from children. If you believe a minor has provided information to us, contact [email protected] and we will take reasonable steps to delete it where required and feasible.
14. Your Choices and Requests
14.1 Access Controls
You may:
- update certain profile and preference data in the dashboard;
- rotate or revoke API keys;
- manage cookie analytics settings; and
- stop using the Services and request account closure by contacting us.
14.2 Requests
Subject to applicable law and our geographic offer model, you may contact [email protected] to request:
- information about data we hold about you that we can reasonably locate;
- correction of inaccurate account data; or
- deletion or closure of your account.
Account deletion and data requests are handled by us on request (including administrative processes). There may not be a fully self-service export or delete button for all data types.
When an account is deleted, we remove or anonymize account identifiers (such as email) so the account is no longer usable as a person profile. We may retain de-identified usage, metering, and billing records for statistics, security, financial, and operational purposes. Those records are not linked to your email after deletion.
We may need to verify your identity before acting on a request and may decline requests that are excessive, unfounded, or incompatible with our legal or security obligations.
14.3 Marketing
We do not use your data for third-party advertising networks as a core business practice. Product emails we send relate to the Service (for example security or account notices). Optional marketing, if ever offered, will include an unsubscribe mechanism.
15. Automated Controls
We may use automated means (including rate limits where enabled, edge security rules, bot scoring, and abuse detection) to protect the Platform and to refuse or limit abusive traffic. These controls are operational and security measures. They are not a substitute for the contractual Restricted Region rules in Section 2.
If you believe you were incorrectly blocked, you may contact [email protected]. We are under no obligation to provide service in Restricted Regions.
16. Changes to This Policy
We may update this Policy from time to time. The "Last Updated" date at the top will change when we do. Material changes may be highlighted in the dashboard or by other reasonable means. Continued use of the Services after an update constitutes acceptance of the revised Policy, except where mandatory law requires a different process.
17. Governing Law
This Policy is governed by the substantive laws of Nevis, Federation of Saint Kitts and Nevis, without regard to conflict-of-law principles, except where mandatory local law provides otherwise for a specific claim.
Disputes relating to this Policy are subject to the dispute-resolution provisions of the Terms of Service (exclusive venue in Nevis, Federation of Saint Kitts and Nevis, as stated there).
18. Contact
LMIW LLC
OpenCheese.Dev - Intelligent AI Routing
https://opencheese.dev
Email: [email protected]
19. Summary Table (Informational Only)
| Category | Examples | Primary purposes |
|---|---|---|
| Account | OAuth profile, preferences | Authentication, dashboard |
| API access | Key IDs, hashed secrets | Gateway authentication |
| Technical/logs | IP in access logs, device/browser | Security, operations |
| Usage/billing | Tokens, costs, balance, plans | Metering, billing, stats |
| Request content | Prompts, completions | Fulfill AI requests via providers |
| Compaction | Session summaries | Context compaction feature |
| Chat (if used) | Messages, attachments | Optional chat features |
| Cookies | Session, prefs, optional analytics | Security, prefs, metrics |
This table is a convenience summary and does not limit the full text of this Policy.
BY USING THE PLATFORM, YOU ACKNOWLEDGE THAT YOU HAVE READ THIS PRIVACY POLICY AND UNDERSTAND HOW WE PROCESS INFORMATION IN CONNECTION WITH AN AI API GATEWAY, INCLUDING TRANSMISSION OF REQUEST CONTENT TO UPSTREAM PROVIDERS UNDER THEIR OWN PRACTICES.