Privacy Policy

Last updated: 19 May 2026

This Privacy Policy explains how G0I ("G0I", "we", "us", or "our") collects, uses, shares, and protects personal information when you visit g0i.ai, g0i.ai, or any other website or service operated by G0I (collectively, the "Service"). It also explains the rights you have over your personal information.

By using the Service, you agree to the practices described in this policy. If you do not agree, please do not use the Service.

1. Who we are

G0I is an AI gateway platform that provides developers and businesses with API access to multiple large language models, image-generation models, and related AI services through a single, OpenAI-compatible interface.

The data controller for the personal information processed under this policy is:

G0I LLC
30 N Gould St, STE R
Sheridan, WY 82801
United States
Email: [email protected]

2. Information we collect

2.1 Information you provide

2.2 Information collected automatically

2.3 Information from third parties

If you sign in using a third-party identity provider (for example, Google, GitHub) we receive basic profile information from that provider as authorised by you.

3. How we use information

PurposeLawful basis (GDPR)
Provide, operate, and maintain the ServicePerformance of a contract
Process payments and prevent fraudPerformance of a contract / legitimate interest / legal obligation
Communicate service, security, and billing notificationsPerformance of a contract / legitimate interest
Detect, prevent, and respond to abuse, fraud, and security incidentsLegitimate interest / legal obligation
Improve, debug, and develop the Service (aggregate analytics)Legitimate interest
Comply with legal obligations and respond to lawful requestsLegal obligation
Send optional product news and marketing emailsConsent (revocable at any time)

4. Model providers and prompt routing

To fulfil an API request, G0I may transmit the inputs you submit (prompts, messages, files) to one or more upstream model providers and infrastructure operators that we have integrated. Only the data needed to complete your request is transmitted. We do not sell your prompts or outputs to third parties.

We retain a record of each request's metadata (timestamp, model name, token count, latency, status) for billing and abuse-prevention. By default we do not log the contents of your prompts or model outputs beyond what is required for short-term operational caching and error diagnostics. If logging of contents is enabled for a workspace (for example, for compliance or replay purposes), this is opt-in and clearly indicated in workspace settings.

5. How we share information

We share personal information only as described below. We do not sell personal information.

6. Data retention

CategoryRetention
Account informationFor the life of the account, then deleted within 90 days of account closure unless required for legal or accounting reasons.
Billing records and invoicesRetained for at least seven (7) years to comply with tax and accounting law.
Request metadata (timestamps, token counts, latency)Retained for up to 24 months for billing reconciliation, capacity planning, and abuse prevention.
Prompt and output contentNot retained by default beyond short-term operational caching, unless workspace-level content logging is explicitly enabled.
Security and abuse logsRetained for up to 18 months.
Support communicationsRetained for up to 3 years.

7. Cookies and similar technologies

We use a small number of essential cookies for session management, authentication, and CSRF protection. We may also use limited first-party analytics cookies to understand aggregate usage of the marketing pages. We do not use third-party advertising cookies on the Service.

You can disable cookies in your browser settings. Disabling essential cookies will prevent you from signing in or using the Service.

8. Security

We apply reasonable technical and organisational measures to protect personal information against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, and unauthorised access. These measures include encryption of data in transit (HTTPS/TLS), encryption of sensitive data at rest, access controls, audit logging, and regular security review.

No security control is perfect. We will notify affected users and applicable regulators of any personal-data breach to the extent and within the timeframes required by law.

9. International data transfers

G0I operates infrastructure in multiple countries. Where personal information is transferred outside your country of residence, we rely on appropriate safeguards, including Standard Contractual Clauses approved by the European Commission for transfers from the EU/EEA, and equivalent mechanisms for transfers from the United Kingdom and other jurisdictions.

10. Your rights

10.1 General rights

Subject to applicable law, you have the right to:

10.2 Residents of the European Economic Area, United Kingdom, and Switzerland (GDPR / UK GDPR)

The data controller is G0I, contactable at [email protected]. The lawful bases on which we rely are described in Section 3. You may lodge a complaint with the data-protection authority in the EU member state, the UK, or the canton in which you reside, where you work, or where the alleged infringement occurred.

10.3 Residents of California (CCPA / CPRA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA):

You may exercise these rights by emailing [email protected] from the address associated with your account, or by an authorised agent on your behalf.

10.4 Residents of other US states

If you live in Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, or another US state with a comprehensive consumer-privacy law, you have substantially the same access, correction, deletion, portability, and opt-out rights. Submit requests to [email protected].

10.5 How to exercise your rights

Send a request to [email protected] from the email address registered to your account, or use the in-product data-export and account-deletion tools where available. We will respond within the timeframes required by applicable law (generally 30 to 45 days). We may need to verify your identity before fulfilling the request.

11. Children's privacy

The Service is not directed to children under 16, and we do not knowingly collect personal information from children under 16. If you believe a child has provided us with personal information, please contact [email protected] and we will take appropriate steps to delete it.

12. Automated decision-making

We use automated systems to detect abuse, fraud, and security threats. These systems may flag or temporarily limit access to an account when suspicious activity is detected. You can request human review of any such decision by contacting [email protected].

13. Changes to this policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email (to the address registered to your account) and post a prominent notice on the Service before the change takes effect. The "Last updated" date at the top of this page indicates when the policy was most recently revised.

14. Contact us

If you have questions about this policy or our privacy practices, contact us at:

Privacy team — G0I
Email: [email protected]
General support: [email protected]

© 2026 G0I. All rights reserved.