Privacy Policy
Your privacy is important to us. This policy explains how Trubit ApS collects, uses, and protects your personal data when you use Heimdall.
On this page
Introduction
This Privacy Policy describes how Trubit ApS ("we", "us", or "our") collects, uses, and discloses your information in connection with your use of our website and our LLM routing proxy platform (collectively, the "Service").
Last updated: April 3, 2026
Data Controller
For the purposes of the EU General Data Protection Regulation (GDPR), the data controller is:
Trubit ApS
Okseholm 21
4000 Roskilde, Denmark
CVR: 43010379
Email: privacy@heimdall.run
What Data We Collect
We collect information in the following ways:
- Information You Provide: This includes account information (name, email address), API keys you register with our service for third-party AI providers, and any content or metadata associated with your requests routed through Heimdall.
- API Keys: You provide API keys for third-party AI providers. These keys are encrypted at rest and used solely for routing your requests to the specified providers. We do not share your API keys with any third party beyond the intended provider for request authentication. You are responsible for ensuring you have the right to use the API keys you provide to Heimdall and for any charges incurred through your provider accounts.
- Information We Collect Automatically: This includes usage data (log files, IP addresses, browser type, device information), request metrics (token counts, model usage, provider routing decisions), and information collected through cookies and similar technologies to help our Service function and to understand how you use it.
- Communications: If you contact us directly, we may receive additional information about you such as your name, email address, the contents of the message and/or attachments you may send us.
How and Why We Use Your Data
We use your data based on the following legal grounds:
- To Provide the Service: We process your data as a matter of contractual necessity to create your account, route your AI requests, provide observability and analytics, bill you for services, and provide customer support.
- For Legitimate Interests: We use data to improve and secure our Service, prevent fraud, and analyze usage patterns to enhance user experience.
- With Your Consent: We may ask for your consent to send you marketing communications, which you can withdraw at any time.
- To Comply with Legal Obligations: We may be required to process your data to comply with legal, regulatory, or tax obligations.
Data Sharing & Sub-processors
We do not sell your personal data. We work with trusted third-party service providers who help us operate our Service:
- Stripe
We have data processing agreements in place with our sub-processors to ensure they protect your data in accordance with GDPR standards.
Third-Party AI Providers
Heimdall routes your AI requests to third-party model providers such as OpenAI, Anthropic, Google, and others. When you send a request through Heimdall, the content of that request is forwarded to the provider you have selected.
These providers process your data according to their own privacy policies and terms of service. We do not control how these providers handle your data, and we strongly advise you to review their privacy policies before using their services through Heimdall.
Heimdall itself does not use your content to train AI models. We act solely as a routing and observability layer between your applications and the AI providers you choose.
When you provide an API key for a third-party provider, Heimdall uses that key solely to authenticate your requests to that provider. Your keys are encrypted and never exposed in logs or shared with unauthorized parties.
Data Security
We implement appropriate technical and organizational measures to protect your personal data, including encryption of API keys at rest and in transit, access controls, and regular security reviews. However, no method of transmission over the Internet is 100% secure, and we cannot guarantee its absolute security.
Data Retention
We retain your personal data for as long as your account is active or as needed to provide you with the Service. API keys are retained for as long as your account is active and you wish to use them for routing. You may revoke or rotate your API keys at any time through the Service. We may also retain your data to comply with our legal obligations, resolve disputes, and enforce our agreements.
Your Data Rights (GDPR)
If you are in the European Economic Area (EEA), you have the following rights regarding your personal data:
- The right to access – You have the right to request copies of your personal data.
- The right to rectification – You have the right to request that we correct any information you believe is inaccurate or complete information you believe is incomplete.
- The right to erasure – You have the right to request that we erase your personal data, under certain conditions.
- The right to restrict processing – You have the right to request that we restrict the processing of your personal data, under certain conditions.
- The right to object to processing – You have the right to object to our processing of your personal data, under certain conditions.
- The right to data portability – You have the right to request that we transfer the data that we have collected to another organization, or directly to you, under certain conditions.
- The right to withdraw consent – You can withdraw your consent at any time where we are relying on consent to process your personal data.
To exercise any of these rights, please contact us at privacy@heimdall.run. You also have the right to lodge a complaint with a supervisory authority, such as the Danish Data Protection Agency (Datatilsynet).
International Data Transfers
Your information may be transferred to — and maintained on — computers located outside of your state, province, country, or other governmental jurisdiction where the data protection laws may differ. As a Danish company, we ensure that any transfer of personal data outside the EEA is done in compliance with GDPR, typically through the use of Standard Contractual Clauses (SCCs).
Note for U.S. Users
If you are a resident of a U.S. state with applicable privacy laws (such as California's CCPA/CPRA), you may have additional rights regarding your personal information. Heimdall does not "sell" your personal information as that term is typically defined. To exercise any rights you may have under your local laws, please contact us.
Children's Privacy
Our Service is not intended for use by anyone under the age of 18. We do not knowingly collect personally identifiable information from children. If you become aware that a child has provided us with personal data, please contact us.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date. You are advised to review this Privacy Policy periodically for any changes.
Contact Us
If you have any questions about this Privacy Policy, you can contact our Data Protection team at: privacy@heimdall.run.