Viro AI API Privacy Policy

Effective August 1, 2026

1. Introduction

This Privacy Policy explains how Viro Climate Action, Inc. ("Viro," "we," "us," or "our") collects, uses, discloses, and protects personal information when you use:

  • the Viro AI API;
  • the Viro developer console;
  • Viro model routers;
  • our websites and documentation; and
  • related developer services,

collectively, the "Service."

This Privacy Policy applies to developers, account administrators, representatives of customers, and other people who interact directly with Viro.

It also explains how Viro processes information submitted through the API on behalf of customers. However, if you are an end user of an application built by a Viro customer, that customer's privacy policy governs its collection and use of your information. You should generally direct privacy requests concerning that application to the customer operating it.

2. Viro's Role

Our legal role depends on the type of information involved.

2.1 Account and operational information

Viro generally determines how and why account information, billing records, security logs, support communications, and Service usage metadata are processed. For this information, Viro acts as a controller, business, or similar responsible entity under applicable privacy law.

2.2 Information submitted through the API

Customers determine what information they submit through the API and why they process it. When Customer Content contains personal information, Viro generally processes that information on the customer's behalf to provide the requested Service.

For this information, the customer generally acts as the controller or business, and Viro generally acts as its processor or service provider.

This Privacy Policy does not replace any data processing agreement between Viro and a customer.

3. The Short Version for Prompts and Responses

Viro does not persistently store the content of API prompts, messages, uploaded files, tool inputs, or model responses in the Viro application database.

Our per-request usage records contain operational information such as:

  • the model and provider used;
  • token or other usage counts;
  • price and cost information;
  • latency;
  • timestamps;
  • success or failure status;
  • error classifications;
  • router selection information; and
  • environmental or energy estimates.

These usage records are designed not to contain prompt, file, or response content.

Request content is processed in memory for the time reasonably necessary to:

  1. authenticate and validate the request;
  2. select a model or Provider;
  3. send the request to the applicable Provider;
  4. receive and return the response;
  5. operate enabled tools; and
  6. maintain the security and reliability of the Service.

Viro does not use Customer Content or model responses to train foundation models. We also do not use that content for advertising or marketing profiles.

This Viro-level commitment does not automatically mean that every underlying model Provider offers zero-data-retention processing. Provider retention, abuse monitoring, and data-use practices can differ by Provider, model, endpoint, region, and commercial agreement.

Customers that require zero-retention or other specific processing terms should review the applicable model documentation or contact Viro before selecting a model or router.

4. Information We Collect

4.1 Account information

When you create or administer an account, we may collect:

  • your email address;
  • your name, if provided;
  • your organization or company name;
  • account and organization identifiers;
  • authentication-provider identifiers;
  • account role and permission information; and
  • account creation and activity timestamps.

If you sign in through Google, we receive the authentication and profile information authorized through the sign-in process, such as your email address and Google account identifier. We do not receive your Google password.

4.2 Billing and transaction information

Payments are processed by Stripe.

Viro does not receive or store your complete payment-card number or card security code. We may receive limited transaction information from Stripe, such as:

  • Stripe customer and transaction identifiers;
  • the amount and currency paid;
  • payment status;
  • purchase timestamps;
  • invoice or receipt information;
  • billing country;
  • card brand and limited card details, such as the last four digits, where provided; and
  • information concerning refunds, disputes, chargebacks, or failed payments.

We use this information to add purchased Credits to your account, maintain billing records, investigate payment issues, prevent fraud, and satisfy accounting and legal obligations.

Stripe processes payment information under its own terms and privacy policy.

4.3 API usage metadata

For each request, we may collect operational metadata including:

  • the API key or account associated with the request;
  • the requested model or router;
  • the Provider selected;
  • request and response timestamps;
  • input, cached-input, output, and reasoning-token counts;
  • image, audio, tool, search, or other billable usage units;
  • latency and processing duration;
  • pricing and cost calculations;
  • HTTP status and success or failure status;
  • generalized error types;
  • fallback activity;
  • router classifications and selection reasons;
  • request region or infrastructure location;
  • rate-limit and spend-limit information; and
  • estimated energy or environmental metrics.

Usage metadata does not intentionally contain prompt or response content.

4.4 API key information

Viro does not store complete API keys in plaintext after they are created.

A full API key is displayed to you when it is generated. Viro retains:

  • a one-way HMAC-derived or otherwise protected hash used to authenticate requests;
  • a short key prefix or identifier used for display and lookup;
  • the key's name and account association;
  • creation and last-used timestamps;
  • status and expiration information; and
  • configured permissions or limits.

Because Viro does not retain the complete key in recoverable form, a lost API key must be replaced rather than recovered.

4.5 Customer Content

"Customer Content" includes prompts, messages, instructions, files, images, URLs, function arguments, tool inputs, and other content submitted through the API.

Customer Content may contain personal information selected and controlled by the customer.

Viro processes Customer Content transiently to provide the Service. We do not persistently store it in our application database or include it in ordinary usage records.

Customer Content is transmitted to the model Provider or other service provider required to perform the customer's request.

4.6 Technical and security information

When you access the Service, Viro and its infrastructure providers may automatically process:

  • IP addresses;
  • browser and device information;
  • operating system;
  • user agent;
  • requested pages and endpoints;
  • network and request timestamps;
  • approximate location derived from an IP address;
  • authentication events;
  • rate-limit events;
  • error traces;
  • security signals; and
  • suspected fraud or abuse indicators.

Viro's systems are designed not to place prompt or response content into ordinary infrastructure logs. However, technical logs may contain limited fragments of request information if necessary to diagnose an unexpected error or if information is voluntarily submitted as part of a support request.

Infrastructure providers may retain technical logs according to their own contractual and operational retention schedules.

4.7 Support and communications

If you contact us, we may collect:

  • your name and contact information;
  • the content of your message;
  • account, request, or transaction identifiers you provide;
  • attachments or examples you choose to share; and
  • records of our response.

Do not send prompt or response content to support unless it is necessary to resolve your issue and you are authorized to disclose it.

Content voluntarily included in a support request is not covered by the ordinary API zero-content-retention design. We retain and process it as part of the support communication.

4.8 Cookies and similar technologies

The developer console may use cookies, local storage, and similar technologies necessary to:

  • keep you signed in;
  • protect accounts and prevent fraud;
  • maintain session and security settings;
  • remember preferences; and
  • operate and improve the console.

Where applicable law requires consent for a non-essential cookie or similar technology, we will request consent before using it.

5. How We Use Information

We use personal information to:

  • create and administer accounts;
  • authenticate users and API requests;
  • provide, maintain, and secure the Service;
  • route requests to the selected model or Provider;
  • operate automated routers and fallbacks;
  • provide web-search and retrieval tools;
  • measure usage and deduct Credits;
  • process payments and maintain transaction records;
  • enforce spend, rate, and access limits;
  • display usage and billing history;
  • calculate aggregate availability, latency, and error metrics;
  • estimate energy use and environmental information;
  • diagnose errors and improve reliability;
  • prevent fraud, abuse, security incidents, and violations of our policies;
  • respond to support requests;
  • send security, billing, legal, and other Service-related communications;
  • enforce our Terms of Service and Acceptable Use Policy;
  • comply with legal obligations and lawful requests; and
  • establish, exercise, or defend legal claims.

We may aggregate or de-identify operational information so that it cannot reasonably be associated with a person or customer. We may use and disclose properly aggregated or de-identified information for analytics, capacity planning, environmental reporting, reliability improvements, and other legitimate business purposes.

We will not attempt to reidentify information that we maintain as de-identified, except to test whether our de-identification measures are effective or as otherwise permitted by law.

6. Legal Bases for Processing

Where European, United Kingdom, or similar privacy laws apply, Viro relies on one or more of the following legal bases:

6.1 Performance of a contract

We process information where necessary to:

  • create and manage your account;
  • authenticate API requests;
  • provide requested features;
  • route and complete model requests;
  • calculate usage;
  • process Credit purchases; and
  • provide customer support.

6.2 Legitimate interests

We may process information where necessary for legitimate interests such as:

  • securing the Service;
  • preventing abuse and fraud;
  • maintaining reliability;
  • understanding aggregate Service performance;
  • improving routing and operational systems;
  • protecting Viro, our customers, Providers, and the public; and
  • establishing or defending legal claims.

We consider the nature of the information and the potential impact on individuals when relying on legitimate interests.

6.3 Legal obligations

We process information when necessary to comply with applicable tax, accounting, sanctions, regulatory, law-enforcement, and other legal obligations.

6.4 Consent

We may rely on consent where required, such as for certain optional cookies or communications. You may withdraw consent at any time, although withdrawal does not affect processing that occurred before it was withdrawn.

7. How We Disclose Information

We do not sell personal information.

We do not share personal information for cross-context behavioral advertising or use Customer Content to create advertising profiles.

We disclose information only as described below.

7.1 Model Providers

We transmit Customer Content and required request information to the model Provider selected by you or selected by a Viro router.

Current Providers may include:

  • OpenAI;
  • Anthropic;
  • Google;
  • xAI;
  • Nscale; and
  • TensorX.

Providers receive the request information needed to generate and return the requested result. Depending on the Provider, this may include:

  • prompts and conversation context;
  • files or images;
  • system and developer instructions;
  • tool definitions;
  • structured-output schemas;
  • request settings; and
  • limited technical identifiers.

The Provider returns model Output and usage information to Viro.

Provider availability may change. Viro may add, replace, or remove Providers as the Service evolves. Current model and Provider information is available through our documentation and developer console.

A Provider's processing may be governed by both its agreement with Viro and its own published privacy and service terms. Viro selects and configures Providers but cannot promise a particular Provider retention practice unless that practice is expressly identified for the applicable model or service configuration.

7.2 Search and web-retrieval providers

When you explicitly enable a tool such as viro:web_search, Viro sends the search query and related parameters to the applicable search provider.

Brave Search may receive search queries when the Brave-backed search feature is used.

When you use a web-retrieval tool, the operator of the destination website may receive standard network information associated with the retrieval request, such as the requested URL, request time, and the IP address of Viro's retrieval infrastructure.

Search and retrieval information is shared only when the relevant tool is enabled or invoked.

7.3 Payment providers

Stripe receives and processes payment, billing, and transaction information needed to complete Credit purchases and handle refunds, disputes, and fraud prevention.

7.4 Infrastructure and operational providers

We use service providers to operate the Service, including:

  • Supabase, for database, authentication, and backend infrastructure;
  • Cloudflare, for hosting, edge computing, networking, security, and content delivery;
  • Google, when you choose Google authentication; and
  • other vendors used for monitoring, communications, security, and support.

These providers may process account, transaction, usage, authentication, and technical information only as necessary to provide their services to Viro.

7.5 Professional advisers

We may disclose information to lawyers, accountants, auditors, insurers, consultants, and other professional advisers where reasonably necessary for their services and subject to appropriate confidentiality obligations.

7.6 Legal requirements and protection

We may preserve or disclose information when we reasonably believe doing so is necessary to:

  • comply with applicable law, regulation, subpoena, court order, or valid legal process;
  • respond to lawful government requests;
  • enforce our agreements and policies;
  • investigate fraud, abuse, or security incidents;
  • protect the rights, property, or safety of Viro, our customers, Providers, or the public; or
  • establish, exercise, or defend legal claims.

Where legally permitted and reasonably practical, we will seek to notify an affected customer before disclosing its information in response to legal process.

7.7 Business transactions

If Viro is involved in a merger, acquisition, financing, reorganization, bankruptcy, sale of assets, or similar transaction, information may be reviewed, transferred, or disclosed as part of that transaction.

Any recipient will be required to handle personal information consistently with applicable law and the commitments in this Privacy Policy unless you are notified of a change.

8. Model Provider Retention and Training

Viro's own zero-content-retention design does not necessarily apply to every model Provider.

A Provider may process or temporarily retain request content for purposes such as:

  • producing a response;
  • detecting abuse;
  • maintaining security;
  • satisfying legal obligations;
  • debugging Provider infrastructure; or
  • providing usage reporting.

Whether a Provider uses request content for model improvement or training depends on Viro's agreement with that Provider, the endpoint used, the account configuration, and the Provider's applicable policies.

Viro seeks to use commercial API services and configurations that do not use customer API content to train public foundation models. However, customers should not assume that every model offers identical retention or data-use terms.

Where a specific model or route is represented as offering zero-data-retention processing, that representation applies only to the documented configuration and may be subject to limited exceptions required for security or legal compliance.

Contact nick@viro.app if you need current information about the processing configuration for a specific model or Provider.

9. Customer and End-User Responsibilities

Customers are responsible for determining whether they may lawfully submit personal information through the Service.

Customers must:

  • provide appropriate privacy notices to their End Users;
  • establish a lawful basis for processing;
  • obtain any required permissions or consents;
  • avoid submitting information that is unnecessary for the intended request;
  • configure models and tools appropriately;
  • respond to End-User privacy requests;
  • protect their own copies of prompts and responses; and
  • comply with laws applicable to their Customer Applications.

Unless Viro has expressly agreed otherwise in writing, customers should not submit information that requires specialized legal or contractual safeguards, such as:

  • protected health information regulated by HIPAA;
  • complete payment-card information;
  • authentication credentials;
  • classified information;
  • biometric identifiers used to identify a person;
  • highly sensitive government identifiers; or
  • restricted export-controlled information.

If an End User contacts Viro about information controlled by a customer, we may direct the person to that customer. Where appropriate, we will assist the customer with a verified request as required by applicable law or a data processing agreement.

10. Data Retention

We retain different categories of information for different periods.

10.1 Customer Content

Viro does not persistently store API prompt, file, tool-input, or response content in its application database.

Customer Content is retained in active memory only for the time reasonably necessary to process and return the request, subject to transient buffering, network transmission, security controls, and Provider processing.

Content voluntarily submitted through support channels is retained as a support communication rather than as ordinary API content.

10.2 Account information

Account information is generally retained while your account remains active and for a reasonable period afterward to:

  • complete account closure;
  • prevent fraud and repeat abuse;
  • resolve disputes;
  • enforce agreements; and
  • comply with legal obligations.

10.3 Billing and transaction records

Billing, payment, Credit-ledger, invoice, tax, and transaction records may be retained for the period required by tax, accounting, financial, and other applicable laws.

Closing an account does not require Viro to delete records that we are legally required to maintain.

10.4 Usage metadata

Usage metadata is retained as reasonably necessary to:

  • provide usage and billing history;
  • calculate and verify charges;
  • investigate billing disputes;
  • enforce spend limits;
  • detect fraud and abuse;
  • analyze aggregate reliability; and
  • satisfy legal and accounting obligations.

Usage metadata does not intentionally contain Customer Content.

10.5 Technical and security logs

Technical and security logs are generally retained for shorter operational periods determined by security, debugging, abuse-prevention, and infrastructure requirements.

Some logs may be retained longer when associated with an active security investigation, legal obligation, billing dispute, or enforcement action.

10.6 Support communications

Support records may be retained for as long as reasonably necessary to resolve the request, maintain customer-service history, improve support operations, and establish or defend legal claims.

10.7 Backups

Deleted information may remain temporarily in encrypted backups or disaster-recovery systems until those backups are overwritten under ordinary retention cycles. We do not restore deleted information from backups except where necessary for disaster recovery, security, or legal compliance.

11. Security

Viro uses administrative, technical, and organizational safeguards designed to protect personal information.

These safeguards include, where appropriate:

  • encryption in transit using TLS;
  • protected storage and access controls;
  • one-way hashing or HMAC protection for API keys;
  • least-privilege access to production systems;
  • separation of account and request-content processing;
  • authentication and authorization controls;
  • rate limiting and abuse monitoring;
  • logging and security-event review; and
  • vendor and infrastructure security measures.

Access to production information is limited to personnel and service providers who need access to operate, secure, support, or maintain the Service.

No method of transmission or storage is completely secure. We cannot guarantee that unauthorized parties will never defeat our safeguards.

If you believe you have identified a vulnerability, contact nick@viro.app before publicly disclosing it.

12. International Data Transfers

Viro is based in the United States. Our Providers and service providers operate in the United States and other countries.

As a result, personal information may be processed in jurisdictions whose privacy laws differ from those in your place of residence.

Where required by applicable law, Viro will use an appropriate legal mechanism for an international transfer, which may include:

  • contractual protections;
  • approved standard contractual clauses;
  • an applicable adequacy decision; or
  • another legally recognized transfer mechanism.

Customers are responsible for determining whether their submission of personal information through a particular model, Provider, or region satisfies their own data-location and international-transfer requirements.

13. Your Privacy Rights

Depending on where you live and subject to applicable exceptions, you may have the right to:

  • know whether we process your personal information;
  • request access to personal information;
  • request correction of inaccurate information;
  • request deletion of information;
  • receive a portable copy of certain information;
  • object to or restrict certain processing;
  • withdraw consent;
  • opt out of certain sales, sharing, targeted advertising, or profiling;
  • appeal a decision concerning a privacy request; and
  • lodge a complaint with a privacy regulator.

Viro does not sell personal information or share it for cross-context behavioral advertising. We therefore do not currently provide an opt-out mechanism for those activities.

13.1 Submitting a request

To exercise a privacy right, contact: nick@viro.app

Please describe:

  • the right you wish to exercise;
  • the account or email address involved; and
  • any information reasonably needed to locate the relevant records.

We may request additional information to verify your identity and authority. We will use verification information only to process the request.

You may use an authorized agent where applicable law permits. We may require evidence that the agent has authority to act for you and may verify your identity directly.

We will respond within the period required by applicable law. If we deny a request, we will explain the reason where required and provide information about any available appeal process.

You will not receive discriminatory treatment for exercising an applicable privacy right.

13.2 Requests concerning a customer application

If your information was submitted through an application operated by a Viro customer, contact that customer first.

Viro may not be able to identify or retrieve your information because API Customer Content is not persistently stored in Viro's application database and may not be associated with your identity in Viro's systems.

When a customer asks Viro to assist with a valid End-User request, we will provide reasonable assistance as required by applicable law and our agreement with that customer.

13.3 Complaints

You may contact us first so that we can attempt to resolve your concern.

Where applicable, you may also complain to the data-protection or privacy authority responsible for your jurisdiction.

14. California and Other U.S. State Disclosures

This section applies only to the extent an applicable U.S. state privacy law covers Viro and the relevant information.

During the preceding 12 months, Viro may have collected the following categories of personal information:

  • identifiers, such as email address, account identifiers, IP address, and API-key prefixes;
  • customer-record information, such as billing contact and transaction details;
  • commercial information, such as Credit purchases and usage history;
  • internet or electronic activity, such as authentication, API, console, and security events;
  • approximate geolocation derived from IP addresses;
  • professional or employment-related information, such as company or organization name; and
  • inferences used for security, fraud prevention, request routing, or account administration.

We collect, use, retain, and disclose these categories for the purposes described in this Privacy Policy.

We may disclose them to:

  • model and search Providers;
  • payment processors;
  • infrastructure and authentication providers;
  • security and support vendors;
  • professional advisers;
  • parties involved in a business transaction; and
  • government authorities or other parties where legally required.

We do not sell these categories of personal information or share them for cross-context behavioral advertising.

We do not knowingly use or disclose sensitive personal information for purposes other than providing the Service, maintaining security, preventing fraud, and other purposes permitted by applicable law.

15. Children's Privacy

The Service is intended for developers, businesses, and other users who are at least 18 years old.

We do not knowingly collect personal information directly from anyone under 18 through account registration.

Customers must not permit a person under 18 to create or control a Viro developer account.

Customer Applications may have their own permitted audiences. Customers are responsible for determining whether their applications may lawfully submit information relating to children and for complying with applicable parental-consent, notice, age-assurance, and children's-privacy requirements.

If you believe a person under 18 has created a Viro account or submitted personal information directly to Viro, contact nick@viro.app.

16. Third-Party Services and Websites

The Service may contain links to or retrieve content from third-party services and websites.

This Privacy Policy does not govern the independent privacy practices of those third parties. Review their privacy policies before providing information to them or relying on their services.

Enabling a tool or instructing a model to interact with an external service may cause information to be transmitted to that service.

17. Changes to This Privacy Policy

We may update this Privacy Policy as the Service, Providers, or applicable laws change.

When we update it, we will revise the effective date at the top.

If a change materially affects how we collect, use, or disclose personal information, we will provide reasonable notice through email, the developer console, or another appropriate method before the change takes effect, where required.

Your continued use of the Service after an updated policy takes effect is subject to the updated policy. Where applicable law requires consent for a change, we will request it separately.

18. Contact

Questions, concerns, security reports, and privacy requests may be sent to:
Viro Climate Action, Inc.
Email: nick@viro.app