Panicly legal
Privacy Policy
Panicly is an AI usage protection, gateway, and metering platform. We help developers and companies protect their AI-powered applications from abuse, unexpected costs, suspicious usage, and operational issues.
2. Information we collect
We collect information in a few different ways.
Account information may include:
- Name
- Email address
- Account login details
- Organization or workspace name
- Billing status and subscription plan
- Settings, preferences, and configuration data
When you use Panicly to protect an AI application, we may process technical data related to your projects, including:
- Project names and identifiers
- API gateway configuration
- Provider configuration, such as OpenAI, Anthropic, OpenRouter, Google, or Vercel AI Gateway
- Rules you create, enable, disable, or customize
- Rate limits, token limits, abuse thresholds, model restrictions, region rules, network controls, kill switch settings, and custom rules
- Usage metadata, such as request count, timestamps, response status, and estimated usage
To provide abuse prevention, usage metering, debugging, audit logs, and rule enforcement, Panicly may collect and process request-level metadata, including:
- Timestamp of the request
- Project and environment identifiers
- Rule evaluation results
- Whether a request was allowed, blocked, challenged, rerouted, or failed
- Estimated input and output token usage
- Model or provider used
- Error codes and gateway status
- Source metadata, which may include IP address, user agent, country or region, and similar technical identifiers
Depending on your configuration, Panicly may also temporarily process request inputs or outputs when needed to enforce rules, estimate usage, debug gateway behavior, provide security features, or deliver product functionality.
You are responsible for ensuring that your own users are properly informed if you enable features that log IP addresses, request metadata, security events, or other information about their usage.
Payments are handled by our payment processor, such as Stripe. We may receive billing-related information such as:
- Customer ID
- Subscription plan
- Payment status
- Invoice status
- Billing email
- Last four digits of a payment method, where provided by the payment processor
- Tax, invoice, or billing details required for payment processing
We do not store full card numbers.
If you contact us, we may collect your email address, the content of your message, support history, and any files, screenshots, logs, or technical information you choose to send us.
When you visit our website, we may collect basic analytics and technical information, such as pages visited, referring site, browser and device information, approximate location based on IP address, usage events, and cookies or similar technologies where applicable.
3. How we use information
We use the information we collect to:
- Provide, operate, and improve Panicly
- Authenticate users and manage accounts
- Process subscriptions, billing, invoices, and usage-based charges
- Route AI requests through the Panicly gateway
- Enforce protection rules selected by customers
- Detect abuse, suspicious activity, excessive usage, loops, blocked sources, or abnormal request patterns
- Provide logs, audit trails, dashboards, and usage insights
- Debug errors and maintain reliability
- Prevent fraud, abuse, and unauthorized access
- Communicate with you about your account, billing, support, security, or product updates
- Comply with legal, accounting, tax, and security obligations
4. AI request data
Panicly is designed to sit between your application and AI providers. This means some request data may pass through our infrastructure.
We process AI request data only to provide Panicly’s gateway, protection, logging, metering, debugging, billing, security, and related product features.
Depending on your configuration, AI request data may include:
- Prompts or inputs
- AI outputs or completions
- Request metadata
- Token estimates
- Model information
- Provider routing information
- Rule evaluation results
- Error and response metadata
If you connect third-party AI providers, your request data may also be processed by those providers according to their own terms and privacy policies.
5. No training on customer data
Panicly does not use customer data, user data, request logs, prompts, outputs, API traffic, metadata, or any other customer content to train, fine-tune, improve, or develop AI models.
This commitment applies to any current or future AI systems developed by Panicly, including any model, classifier, detection system, abuse-prevention model, suspicious-request detector, routing system, or internal AI feature.
If Panicly develops its own AI models or detection systems in the future, we will not train them on customer data unless a customer has given clear, explicit, written permission for that specific purpose.
- We do not train models on customer prompts.
- We do not train models on customer completions or AI outputs.
- We do not train models on customer request logs.
- We do not train models on customer metadata.
- We do not use customer API traffic to build future Panicly models.
- We do not sell customer data to AI model providers.
- We do not allow third parties to train models on customer data through Panicly.
Panicly may use aggregated, anonymized, and non-customer-identifying operational metrics to improve service reliability, billing accuracy, abuse prevention, capacity planning, security, and product performance. These metrics are not used to reconstruct customer content or train AI models on customer data.
Customer data is processed only to provide Panicly’s services, including request routing, rule enforcement, abuse prevention, usage metering, logging, debugging, security, billing, and customer-requested product features.
6. Customer responsibilities
If you use Panicly in your own application, you are responsible for:
- Having your own privacy policy for your users
- Explaining that AI requests may be processed through infrastructure providers and AI providers
- Informing users if IP addresses, usage metadata, request logs, or security events are collected
- Avoiding sending unnecessary sensitive personal data through Panicly
- Configuring retention, logging, and security settings appropriately
- Complying with laws that apply to your product, users, and region
Panicly acts as a service provider or processor for some customer data, depending on how you use the product.
7. Legal bases for processing
Where required by law, we rely on the following legal bases:
- Contract: to provide Panicly and manage your account
- Legitimate interests: to secure the service, prevent abuse, improve reliability, debug issues, and understand product usage
- Consent: where required for certain cookies, marketing communications, or optional features
- Legal obligation: where we need to comply with applicable laws, accounting, tax, or security requirements
8. Sharing information
We may share information with trusted service providers who help us operate Panicly, such as:
- Cloud hosting providers
- Database and infrastructure providers
- Payment processors
- Authentication providers
- Email and support tools
- Analytics and monitoring services
- AI providers, when requests are routed through them based on your configuration
We may also share information when required to comply with law, protect Panicly, our users, our customers, or the public, prevent fraud, abuse, or security threats, enforce our terms, or complete a business transaction such as a merger, acquisition, financing, or sale of assets.
We do not sell your personal information. We do not sell customer request data. We do not share customer data with third parties for AI model training.
9. Data retention
We keep information only for as long as reasonably necessary to provide Panicly, comply with legal obligations, resolve disputes, enforce agreements, and maintain security.
Retention periods may vary depending on your subscription plan, product settings, log retention configuration, legal or accounting requirements, and security and abuse-prevention needs.
You may request deletion of your account or certain data by contacting us.
Some data may remain in backups, logs, or security records for a limited period where necessary for security, fraud prevention, legal compliance, or disaster recovery.
10. Security
We use reasonable technical and organizational measures to protect information, including:
- Access controls
- Encryption where appropriate
- Authentication protections
- Infrastructure monitoring
- Logging and audit controls
- Internal security practices
- Limited access to sensitive systems
However, no system is perfectly secure. You are responsible for protecting your own account credentials, API keys, provider credentials, and project configuration.
11. API keys and provider credentials
Panicly may allow you to connect provider keys or routing credentials.
We treat API keys and credentials as sensitive information. We use them only to provide the service and route requests according to your configuration.
You should not share API keys publicly, send them to unauthorized users, or store them in places where they can be accessed by others.
If you believe an API key has been exposed, you should rotate or revoke it immediately with the relevant provider.
12. International data transfers
Panicly and our service providers may process information in countries other than your own.
Where required, we use appropriate safeguards for international transfers of personal data.
13. Your rights
Depending on your location, you may have rights to:
- Access your personal information
- Correct inaccurate information
- Delete your information
- Object to or restrict certain processing
- Request a copy of your information
- Withdraw consent where processing is based on consent
- File a complaint with a data protection authority
To exercise your rights, contact us at:
We may need to verify your identity before responding to certain requests.
14. Cookies and tracking
We may use cookies or similar technologies to keep you signed in, remember preferences, measure website usage, improve the product, and protect against abuse.
Where required, we will ask for consent before using non-essential cookies.
15. Children
Panicly is not intended for children under the age required by applicable law. We do not knowingly collect personal information from children.
If you believe a child has provided us personal information, contact us and we will take appropriate action.
16. Changes to this policy
We may update this Privacy Policy from time to time.
If we make material changes, we will take reasonable steps to notify users, such as by updating the date above, posting a notice, or sending an email.
Your continued use of Panicly after an update means the revised policy applies.
17. Contact
For questions about this Privacy Policy or how Panicly handles data, contact: