Back to Airside

Airside Supplemental Privacy Notice

Effective Date: August 27, 2026
Last Updated: August 27, 2026

This notice describes how LLM Gateway, a service of Polar Lights LLC, handles personal data in Airside, the carrier console at airside.llmgateway.io.

It supplements the main LLM Gateway Privacy Policy, which applies in full and covers everything not specific to Airside — legal bases, security, international transfers, your rights, and how to exercise them. Where this notice and the main policy conflict for Airside, this notice controls for that conflict only.

Airside is a business-facing console. The personal data involved is almost entirely business contact data about the people who operate a carrier account — not data about the developers whose requests we route.


1. What We Collect

Account and company data

  • Your account: name, email address, authentication credentials (password hash or passkey), and email-verification status. Sign-in via GitHub or Google, where enabled, provides your name, email address, and account identifier.
  • Your provider company: company name, website, the members of the company account, and each member’s role.

Claim data

  • The provider claimed, the claim type, and the registrable email domain that satisfied the match — this is the record of how the claim was authorized, so we retain it for as long as the claim exists.
  • For a newly registered provider: the submitted display name, OpenAI-compatible API base URL, and description.
  • Logo and icon files you upload, which are stored with the claim and displayed publicly.
  • Review metadata: which account filed the claim, who reviewed it, the decision, any review note, and the timestamps.

Listing and filing data

  • Model listings and their attributes, and every tariff filing with its prices, your note, the reviewer’s decision and note, and who submitted it.
  • Your routing discount and the gateway margin you accept.

Filings are an audit trail: because a filed price is what developers are billed, we keep the full history of filings and decisions, including rejected ones, together with the accounts that submitted and reviewed them.

Payment data

Where a listing fee applies, checkout is handled by Stripe. We store the Stripe checkout session identifier, whether the fee is paid, and when — we never receive or store your full card number.

Technical data

Standard server and security logs (IP address, user agent, timestamps) generated when you use the console, as described in the main policy.


2. Traffic Data You See Is Aggregated

The console reports usage of your claimed providers: requests, errors, tokens, and billed traffic, broken down by model and by day.

These figures come from pre-aggregated hourly rollups, not from individual request records. They are summed across every gateway tenant that routed to you, and they deliberately exclude the identity of the organizations, projects, API keys, and end users behind that traffic. Prompts and responses are never exposed to carriers through Airside. Under the Airside Terms you must not attempt to re-identify the sources of this traffic.

This is separate from what you receive as a provider: when we route a request to your endpoint, you receive its content directly and act as an independent controller of any personal data in it, under your own privacy policy.


3. How We Use It

  • To verify and review claims — matching your verified email domain against the provider’s endpoint or website, and deciding whether to approve.
  • To operate your listings — publishing approved models and prices into the catalogue and routing requests to them.
  • To bill correctly — filed prices determine what developers are charged, and the margin you accept determines what is attributed to you.
  • To collect the listing fee where one applies.
  • To communicate with you about reviews, decisions, listing issues, and service changes.
  • To protect the platform — detecting fraudulent claims, abuse, and misrepresented listings.

We do not sell your data, and we do not use it for advertising or profiling.


4. What Is Public

Once a claim is approved, the following appear on public LLM Gateway pages: your provider name and description, the logo and icon you upload, and your listed models with their approved prices and capabilities. Your account email address, the matched domain, filing notes, and review notes are not public.


5. Sharing and Sub-processors

We share Airside data only with the sub-processors listed in the main sub-processor list, which for Airside principally means our hosting and database providers, Stripe for the listing fee, and our transactional email provider. We also share where required by law or to enforce our terms, as described in the main policy.


6. Retention

  • Account and company records — for as long as the account exists, then deleted or anonymized in line with the main policy.
  • Claims, listings, and filings — retained while the carrier is active and afterwards for as long as needed as a billing and pricing audit trail, because they evidence what developers were charged.
  • Payment records — as required by tax and accounting law.
  • Aggregated usage rollups — retained as platform-level statistics; they contain no carrier or developer identities beyond the provider and model.

Deleting your account removes you from the provider company. Where you are the only member, the company’s claims and listings are withdrawn from routing; records we are required to keep for audit, billing, or legal reasons are retained as described above.


7. Your Rights and Contact

You have the rights described in Section 9 of the main LLM Gateway Privacy Policy — including access, correction, deletion, portability, and objection — and the same routes to exercise them. Note that we may need to retain pricing and filing records that are necessary to evidence past billing even after an erasure request, as permitted by law.

Privacy questions about Airside: contact@llmgateway.io

Polar Lights LLC
16192 Coastal Highway
Lewes, DE 19958
United States