Introducing GTMRouter — one API for the entire GTM loop Join the beta ›
LEGAL
GTMRouterLast updated

Privacy Policy

How GTMRouter, the unified GTM API for AI agents, collects, uses, shares and safeguards personal data — yours, and the business contacts your agents work with.

01Who we are

GTMRouter (“GTMRouter”, “we”, “us”, “our”) provides a unified go-to-market API for AI agents. Through one API key and one prepaid credit balance, your agents and software can find business leads, check buying intent, enrich contacts to verified work emails, verify deliverability, provision warmed sending capacity, draft and launch outbound email campaigns, read replies, and call large language models (together, the “Service”).

GTMRouter is registered in the United Kingdom.

In relation to your account, your API keys, your credit balance, billing records and correspondence with us, we act as a data controller. In relation to the audiences, lead lists, campaign content, replies and other material you or your agents submit to or retrieve through the Service (“Customer Content”), we act as a data processor and process it on your documented instructions. Our Data Processing Addendum sets out those terms.

If you have a question about this policy, or wish to exercise a right described in it, contact founders@gtmrouter.dev.

02Scope of this policy

This policy governs all personal data processed in connection with the Service, namely:

  • our marketing website at gtmrouter.dev and our documentation at docs.gtmrouter.dev;
  • the console at app.gtmrouter.dev (the “Console”);
  • the API at api.gtmrouter.dev and the hosted MCP server at mcp.gtmrouter.dev (together, the “API”); and
  • the emails and notifications we send you about your account.

GTMRouter is a business-to-business service. We do not market or sell to consumers, and the Service is not intended for personal or household use.

This policy does not apply to the AI assistants, coding agents, workflow tools or other software you connect to the API, or to the third-party websites we link to. Those services operate under their own privacy notices, which you should review before connecting them.

03Personal data we collect

We collect personal data directly from you when you create an account, create an API key, top up credits or contact us; automatically when you or your agents use the API and the Console; from third parties where you authorise a connection, for example when you sign in with Google; and from our data providers when your agents ask the API for business contact information.

Account data

Your email address, the name of your workspace, your email verification status and the date of your most recent sign-in. We hold no passwords. You sign in with a one-time link or code sent to your email, or with Google. Where you sign in with Google, we receive your Google account identifier, name, email address and profile image.

API keys and OAuth grants

The keys you create, stored only as a one-way cryptographic hash together with a name, scopes, spend limits and last-used time. The full key is shown to you once, at creation, and cannot be recovered by anyone at GTMRouter. Where you connect an AI assistant through OAuth, we store the client’s registration details and the grants you approve.

Customer Content

The audiences you describe, the lead lists and company domains you submit, the campaigns and email copy you or your agents draft, the replies received by the mailboxes leased to you, and the prompts and completions passed through the LLM endpoint. Customer Content ordinarily contains the personal data of the business contacts you are prospecting (“Recipient Data”): typically name, job title, employer, work email address, work telephone number, professional profile URL and the company signals associated with them.

Provider Data

When your agent calls a data verb, we retrieve Recipient Data from specialist business-data providers on your instruction and return it to you. Each provider is an independent controller of its own database. Once returned to you, that data forms part of your Customer Content and you are responsible for it as controller.

Usage and ledger data

A record of every API request: the verb called, the key used, the parameters and result summary, the outcome (hit, miss or error), the credits charged and the immutable ledger entry that settled the charge. Your balance is derived from that ledger and nothing else.

Billing data

Your Stripe customer and checkout identifiers, the credits you purchased and the amounts paid. We never receive or store card numbers. Payment credentials are collected and held by Stripe, which acts as an independent controller for its own compliance purposes.

Suppression data

The email addresses of people who replied, unsubscribed or bounced, held so that they are never contacted again from your workspace.

Technical data

Session cookies, IP address, browser and device characteristics, and the server logs generated when you use the Console or the API.

We do not request special category data within the meaning of Art. 9 UK GDPR — including data revealing health, racial or ethnic origin, political opinions or biometric identifiers — and you must not submit it to the Service.

04Purposes and legal bases

We process personal data only where a lawful basis under Art. 6(1) UK GDPR applies. Each purpose and its basis is set out below.

  • Providing the Service you have signed up for, including executing your agents’ API calls and returning Provider Data on your instruction. Legal basis: performance of a contract (Art. 6(1)(b)).
  • Charging credits, taking payment, issuing receipts and preventing payment fraud. Legal basis: performance of a contract (Art. 6(1)(b)); compliance with a legal obligation (Art. 6(1)(c)).
  • Honouring opt-outs by maintaining suppression lists so that a person who has replied, unsubscribed or bounced is never contacted again from your workspace. Legal basis: compliance with a legal obligation (Art. 6(1)(c)); legitimate interests (Art. 6(1)(f)), namely protecting recipients and sender reputation.
  • Maintaining the security, availability and integrity of the API, including rate limiting, abuse detection and pausing campaigns that present a risk. Legal basis: legitimate interests (Art. 6(1)(f)).
  • Responding to support requests and other correspondence. Legal basis: performance of a contract (Art. 6(1)(b)); legitimate interests (Art. 6(1)(f)).
  • Improving the Service using aggregated statistics that do not identify you, your contacts or your campaigns. Legal basis: legitimate interests (Art. 6(1)(f)).
  • Sending service communications, including sign-in links, approval requests, low-balance and upkeep notices, security notices and billing notices. Legal basis: performance of a contract (Art. 6(1)(b)).
  • Sending marketing communications. Legal basis: consent (Art. 6(1)(a)), or legitimate interests (Art. 6(1)(f)) where you are an existing business customer. Every marketing email carries an unsubscribe link, which we honour immediately.
  • Meeting tax, accounting, audit and other statutory obligations. Legal basis: compliance with a legal obligation (Art. 6(1)(c)).

Where we rely on legitimate interests, we have assessed those interests against your rights and freedoms and concluded that our processing is proportionate. You may object at any time, as described in Your rights.

We do not sell personal data, and we do not share it for cross-context behavioural advertising.

05Business contacts your agents work with

The Service exists to help you reach business contacts. That means Recipient Data flows through it, and it is important to be clear about who is responsible for what.

  • You are the controller of the Recipient Data you retrieve, store, enrich and contact through the Service. You decide whom to prospect, what to say and whether to launch. You must have a lawful basis for that processing and comply with the marketing laws that apply to you and to your recipients, as our Acceptable Use Policy requires.
  • We are your processor. We execute your instructions, store the results in your workspace, and do not use Recipient Data for our own purposes, except to maintain suppression and to keep the Service secure.
  • Our data providers are independent controllers of the professional databases they maintain. We pass them the minimum needed to answer your query — typically a name and company domain, a professional profile URL or an email address — and return what they hold.
  • Human approval is enforced. No agent can purchase sending capacity or launch a campaign without a person confirming it in the Console. Suppression is applied when a campaign is drafted, re-checked at launch, and applied to live campaigns when a reply, unsubscribe or bounce arrives.

If you are a business contact who has received an email sent through the Service and wish to be suppressed, or wish to know what a GTMRouter customer holds about you, contact founders@gtmrouter.dev with the address that received the email. We will suppress the address across the sending workspace immediately and forward your request to the customer concerned.

06AI models and your data

The LLM endpoint forwards the prompts you send to large language models operated by Anthropic and OpenAI, through an AI model routing provider, and returns the completions. We record the model called, the token counts and the charge; we do not use your prompts or completions for any purpose other than delivering the response and settling the charge.

We procure these services on business API terms under which the provider does not use the data we submit to train its models.

Where you use GTMRouter from inside an AI assistant or coding agent, that assistant’s provider processes your conversation under its own terms. We see only the API calls the assistant makes with your key.

AI output is probabilistic, and providers revise their models without notice. Nothing returned by a language model is warranted to be accurate, complete or current, and you remain responsible for anything you send. See AI output, agents and results in our Terms.

07Recipients and sub-processors

We disclose personal data to the service providers (“sub-processors”) that help us operate the Service. Each is engaged under a written contract restricting processing to our documented instructions and imposing confidentiality and security obligations at least equivalent to our own.

We name our AI model providers and our payment provider below. For competitive reasons we identify the remaining providers by category, as Art. 13(1)(e) UK GDPR expressly permits.

  • AI model providers — Anthropic and OpenAI, reached through an AI model routing provider. We submit the prompts you send to the LLM endpoint and collect the completions.
  • Payment processing — Stripe.
  • Business-data providers — lead search, contact enrichment, email verification and company-signal providers. We send them the query your agent makes and receive the Recipient Data they return.
  • Sending infrastructure provider — the provider through which we register domains, provision and warm mailboxes, send your campaigns and receive replies on your behalf. It holds your campaign content, recipient lists and reply threads for the mailboxes leased to you.
  • Cloud hosting, database and backup providers — operating our website, the Console, the API and our stored data.
  • Email delivery providers — transmitting our sign-in links, notifications and service communications to you.

If you require the named list of our current sub-processors — for example, to complete your own vendor assessment — email founders@gtmrouter.dev and we will provide it.

We also disclose personal data to our professional advisers, and to a regulator, court or law enforcement body where we are legally required to do so. In the event of a merger, acquisition or sale of assets, personal data may transfer to the acquirer, and this policy will continue to apply until we notify you otherwise.

08International transfers

Most of our sub-processors are established outside the United Kingdom, principally in the United States. Where personal data is transferred outside the UK or the European Economic Area, we rely on one of the following safeguards:

  • an adequacy decision made by the UK Government or the European Commission;
  • the UK International Data Transfer Addendum to the EU Standard Contractual Clauses; or
  • the EU Standard Contractual Clauses, supplemented by a transfer risk assessment where one is required.

Copies of the safeguards applicable to a particular transfer are available on request from founders@gtmrouter.dev.

09Retention

We retain personal data only for as long as is necessary for the purposes described in this policy, after which we delete or anonymise it.

CategoryRetention period
Account data, API keys and Customer ContentFor as long as your account is open.
Deleted accountsAccess ends immediately on request; data is permanently erased within 30 days.
Suppression listsRetained after account closure, so that a person who opted out is never contacted again if the workspace is reopened. Held as a hashed or minimal record where practicable.
Credit ledger and billing recordsSix years from the end of the relevant accounting period (UK tax law). The ledger is append-only by design.
API request logs and provider call recordsUp to 12 months.
Server and security logsUp to 12 months.
BackupsEncrypted, taken every 12 hours and rotated on a rolling cycle, so erased data leaves the backup set within 90 days.

Where we are required to retain data to establish, exercise or defend a legal claim, we will keep it for as long as that purpose requires and no longer.

10Security

We maintain technical and organisational measures appropriate to the risk, including:

  • encryption of data in transit (TLS) and at rest;
  • no stored passwords — sign-in is by single-use emailed link or code, or by Google;
  • API keys stored only as one-way hashes, scoped to the verbs they may call, with optional spend caps;
  • human confirmation, enforced at the server, before any purchase of sending capacity or launch of a campaign;
  • an append-only credit ledger and an append-only audit log of every administrative action;
  • encrypted backups taken every 12 hours and retained in two independent locations, with restores tested; and
  • access controls limiting production access to personnel with a demonstrated need.

No system can be guaranteed secure. Where a personal data breach is likely to result in a risk to your rights and freedoms, we will notify the Information Commissioner’s Office within 72 hours of becoming aware of it, and we will notify you without undue delay where the risk to you is high.

11Your rights

Under UK and EU GDPR you have the right to:

  • Access — obtain confirmation that we process your personal data, and a copy of it (Art. 15).
  • Rectification — have inaccurate or incomplete data corrected (Art. 16).
  • Erasure — have your data deleted where one of the statutory grounds applies (Art. 17).
  • Restriction — require us to limit our processing in defined circumstances (Art. 18).
  • Portability — receive the data you provided in a structured, commonly used, machine-readable format, or have it transmitted to another controller (Art. 20).
  • Object — object to processing based on legitimate interests, and to direct marketing at any time (Art. 21).
  • Withdraw consent — where processing is based on consent, withdraw it at any time, without affecting the lawfulness of processing carried out beforehand.

To exercise any of these rights, email founders@gtmrouter.dev. We respond within one month, which we may extend by up to two further months for complex or numerous requests, in which case we will tell you within the first month (Art. 12(3)). We do not charge a fee unless a request is manifestly unfounded or excessive.

If your request concerns Recipient Data held in a customer’s workspace, we will suppress your address immediately where you ask us to, and forward the remainder of your request to the customer as controller.

You may also lodge a complaint with the Information Commissioner’s Office at ico.org.uk, or with your local supervisory authority in the EEA. We would ask that you raise the matter with us first so that we can resolve it.

12California privacy rights

If you are a California resident, the California Consumer Privacy Act, as amended by the CPRA, gives you the right to know what personal information we collect, to request its deletion or correction, to opt out of any sale or sharing of it, and not to be discriminated against for exercising those rights.

In the preceding 12 months we collected the following categories of personal information, in each case for the business purposes set out in Purposes and legal bases.

CCPA categoryExamples we collect
IdentifiersEmail address, workspace and account identifiers, IP address.
Commercial informationCredit purchases, charges and the ledger of your usage.
Internet or network activityAPI and Console usage, session data and server logs.
Professional informationName, title, employer and work contact details of the business contacts you retrieve, as your processor.

We have not sold personal information, and we have not shared it for cross-context behavioural advertising, in the preceding 12 months. We do not knowingly collect or sell the personal information of minors under 16.

To exercise these rights, email founders@gtmrouter.dev. You may use an authorised agent, in which case we will ask for written proof of authorisation and may verify your identity directly.

13Cookies

Our marketing website and documentation set no advertising cookies and no analytics cookies, and we do not track you across other websites. The documentation remembers your light-or-dark preference in your own browser’s local storage; nothing is sent to us.

The Console sets a single strictly necessary cookie to maintain your authenticated session; the Console cannot operate without it. Our internal administration tool sets an equivalent session cookie for staff only.

Because we use strictly necessary cookies alone, no consent banner is displayed, consistent with regulation 6(4) of the Privacy and Electronic Communications (EC Directive) Regulations 2003. If we introduce analytics or marketing cookies, we will obtain your consent before setting them and publish a cookie notice.

14Children

The Service is offered to businesses and is not directed to anyone under 18. We do not knowingly collect personal data relating to children. If you believe a child has provided us with personal data, contact founders@gtmrouter.dev and we will delete it.

15Automated decision-making and profiling

The Service classifies replies, scores deliverability and ranks results so that your agents can act on them. We do not carry out automated decision-making that produces legal effects concerning you, or that similarly significantly affects you, within the meaning of Art. 22 UK GDPR.

Agents acting under your key can retrieve and draft freely, but every purchase of sending capacity and every campaign launch requires a person to confirm it in the Console. The decision to contact anyone always rests with a human on your side.

16Changes to this policy

We may update this policy to reflect changes to the Service, to our sub-processors or to applicable law. The date of the most recent revision appears at the top of this page. Where a change materially affects how we process your personal data, we will notify you by email before it takes effect.

17Contact us

Privacy and legal enquiries: founders@gtmrouter.dev

Support and complaints: founders@gtmrouter.dev

GTMRouter is registered in the United Kingdom.

The unified GTM API for AI agents. One key, one credit balance — find, enrich, verify, and send from warmed inboxes that land.

All systems operational
Product
Verbs Pricing MCP server Providers Social Soon
Company
About Contact Community Soon Best practices
© 2026 GTMRouter — the unified GTM API for AI agents