Legal & Operational

Platform Policy

This policy governs your access to and use of the EcoRouter AI API gateway, including the dashboard at ecorouter.top and the gateway API at api.ecorouter.top. By creating an account or calling the API with an EcoRouter key, you accept this policy in full.

Last updated August 18, 2026

01Overview & Acceptance

EcoRouter (“we”, “us”, “our”) operates a white-label AI API gateway that routes requests from buyers to upstream AI providers and provides authentication, rate limiting, usage metering, and billing. The gateway exposes an OpenAI-compatible Chat Completions API and an Anthropic Messages API, and is accessed via the dashboard at ecorouter.top and the gateway at api.ecorouter.top.

By registering an account, generating or using an API key, or sending any request to the gateway, you confirm that you have read, understood, and agreed to this policy. If you do not agree, do not use the service. If you are accessing the service on behalf of an organisation, you represent that you have authority to bind that organisation.


02Accounts & API Keys

You can create an account using email and password, or by signing in with Google. New Google sign-ins are created automatically with the default buyer role. You are responsible for keeping your account credentials and your API keys confidential and for all activity that occurs under your account or keys.

API keys are prefixed with gw_ and are hashed (SHA-256) before storage. A full key is shown to you only once, at creation time; only a short prefix is stored for later identification. Treat keys like passwords — store them in a secret manager, never commit them to source control, and never share them publicly. Rotate any key you believe has been exposed by revoking it in the dashboard and issuing a new one.

You must be at least 16 years old (or the age of digital consent in your jurisdiction) to use the service. You must provide accurate information at registration and keep it current.


03Acceptable Use

You may use EcoRouter to build and run your own applications, integrate AI into your products, and evaluate models. You agree not to, and not to allow third parties to, use the service to:

  • generate, store, or distribute content that is illegal, harmful, threatening, abusive, harassing, defamatory, or infringes the rights of others;
  • produce content that sexualises minors, including realistic or non-realistic depictions (we report such activity to the relevant authorities);
  • build malware, ransomware, or tools designed to attack, exploit, or gain unauthorised access to systems;
  • send unsolicited communications, spam, or automated disinformation, or generate content for deceptive or fraudulent purposes (including non-consensual deepfakes);
  • attempt to circumvent rate limits, quotas, or metering, or to reverse-engineer, decompile, or extract the underlying model weights or the gateway’s internal workings;
  • share, resell, or sub-license access to your key or account to third parties except as expressly permitted by your plan (custom-domain white-labelling routes your own traffic and is permitted);
  • overload, probe, scan, or otherwise stress the gateway or upstream providers in a manner that degrades service for others.

We may, at our discretion and without notice, block specific requests, suspend a key, or terminate an account that violates these rules. We cooperate with law enforcement where required.


04Upstream Provider Policies

EcoRouter routes requests to upstream AI providers. When a request targets a given model, the prompt and related data are transmitted to the corresponding provider so it can generate a response. You are responsible for ensuring that the content you send also complies with the upstream provider’s own usage policies — for example the OpenAI usage policies and the Anthropic usage policies — which apply in addition to this policy.

A provider may refuse to serve a request it deems disallowed; in that case the gateway returns the provider’s error to your client and no tokens are charged for the refused portion.


05Privacy & Data

We act as a data controller for account and billing information, and as a data processor for the request traffic that transits the gateway. This section explains what we collect.

What we collect

  • Account data — email address, hashed password, and (for Google sign-in) the name and profile picture Google shares with us.
  • Usage metadata — for every request we log the tenant, API key prefix, provider, model, input and output token counts, cost, latency, and HTTP status. This drives metering, billing, and the usage charts.
  • Billing data — the records needed to process payments and issue receipts, handled by our payment providers.

What we do not retain

The gateway does not persistently store the prompt or response content of your requests. Prompt and completion text are forwarded to the upstream provider to fulfil the request and are not written to our database — only the metadata above is metered. If an upstream provider retains your prompt or output, that is governed by the provider’s own privacy policy.

How we use data

To operate, secure, and bill for the service; to enforce rate limits and acceptable use; to prevent fraud and abuse; and to improve reliability. We do not sell your personal data.

Sharing & third parties

We share data only as needed to operate the service — with upstream AI providers (request content, as described above), our payment processor (HitPay, for billing), and Google (for authentication). We may disclose data when required by law or to protect the service from harm.

Retention & your rights

Usage metadata is retained for the lifetime of your account and for as long as needed for billing and audit. You may close your account at any time; upon closure, usage data is deleted on a best-effort basis within 30 days, except where retention is required for legal or accounting reasons. Depending on your jurisdiction you may have rights to access, correct, or delete your personal data — contact us (see below) to exercise them.


06Usage, Metering & Rate Limits

Each plan defines a token quota and a requests-per-minute limit. Token usage is metered asynchronously and counted against your quota; some models carry a multiplier that scales how many tokens count (for example, a 2× model counts twice its token output against quota). The multiplier for each model is shown in the model catalog.

Rate limiting is applied per API key using a sliding window and the limits are returned on every response via the X-RateLimit-Limit, X-RateLimit-Remaining, and X-RateLimit-Reset headers. When you exceed a limit, the gateway returns an appropriate HTTP error and the request does not complete.

We may adjust plan limits and rate limits at any time; changes that reduce your entitlement take effect on renewal, not mid-period.


07Billing & Refunds

Plans and prices are shown on the login and Limits & Tiers pages and are charged in Malaysian Ringgit (RM). The Trial plan is free; paid plans are billed in advance for the period shown. Taxes, where applicable, are added at checkout by the payment processor.

Because usage is metered and consumed in real time, tokens already consumed are non-refundable. A paid plan remains active until the end of its prepaid period; cancelling stops renewal but does not refund the current period.

We may change pricing on reasonable notice. Any price change applies to upcoming renewals, not to a period you have already paid for. If you believe you were charged in error, contact us within 30 days and we will review your account.


08Service & Model Availability

The service is provided on a best-effort basis. EcoRouter depends on upstream AI providers and on its own infrastructure, and we do not guarantee any specific uptime or service level. We may perform maintenance, and we may add, restrict, or remove models at any time.

The model catalog is curated and refreshed automatically every few minutes from the upstream. A model may move between Available and Out of stock without notice, and we do not guarantee that any particular model will remain available. Availability shown in the dashboard reflects the upstream state at the last refresh.


09Intellectual Property & Termination

The EcoRouter software, dashboard, branding, and documentation are proprietary. All rights are reserved. We grant you a limited, revocable, non-exclusive licence to use the service in accordance with this policy for the duration of your account. You retain all rights to the content you submit; by sending a request you grant us the limited licence needed to forward it to the upstream provider and return the response.

We may suspend or terminate your access at any time for breach of this policy, for non-payment, or to protect the service. You may close your account at any time from the dashboard. On termination, your right to use the service ends and any active keys are revoked.


10Liability & Policy Changes

The service is provided “as is” and “as available” without warranties of any kind. To the maximum extent permitted by law, EcoRouter and its operators are not liable for any indirect, incidental, consequential, or special damages, or for any loss of data, revenue, or profits, arising from your use of, or inability to use, the service — including where a request is refused by an upstream provider or where a model is unavailable.

Our aggregate liability for any claim is limited to the amount you paid us in the three months preceding the event giving rise to the claim.

We may update this policy from time to time. Material changes take effect on the “last updated” date shown above; continued use after that date constitutes acceptance. We encourage you to review this page periodically.


11Contact

EcoRouter is operated from Malaysia. For any question about this policy, your data, or your account, contact us on WhatsApp and we will respond as soon as we can.

Chat on WhatsApp