Privacy
Last updated October 7, 2026
- We store metadata about your app’s AI calls so we can show you spend.
- We store request and response bodies, encrypted per workspace, for 7 days, so you can replay them. You can turn this off.
- We never store your provider API keys.
- We don’t sell data, and we don’t train models on your prompts.
Who we are
Gin is made by Winding Labs. “We” means Winding Labs. This page covers trygin.ai, the Gin dashboard, the @winding-labs/gin CLI and SDK, and the routing edge.
What we collect
- Account. When you sign in with GitHub we receive your GitHub username, name, avatar, and email address. We use them to identify you and send the daily email.
- Call metadata. For each AI call your app makes through the SDK: time, the provider URL, model asked for and served, use-case label, repo, environment, status, token counts, cost, latency and error text.
- Bodies. The JSON request and response of each call, unless your workspace uses metadata-only mode. HTTP headers are never captured.
- Billing. If you pay for replay credits or routing, our payment processor handles your card. We see only what we need to bill you.
How long we keep it
- Bodies: deleted automatically 7 days after the call. Outputs of replays you run are kept for up to 30 days so you can compare them.
- Metadata: kept while your workspace exists, so your spend history and charts keep working. Delete the workspace and it goes with it.
- Account: kept until you ask us to delete it.
How bodies are protected
Bodies are encrypted with AES-GCM using a key unique to your workspace before they are stored. In metadata-only mode, bodies are dropped on arrival and never written.
Your provider keys
When you route through Gin, your provider key travels with each request to Gin’s edge and is forwarded to the provider. We never write it to storage or logs. When you only observe, the SDK never sends your key to us at all.
What we use data for
- Showing you spend, logs and trends, and sending the daily email to your workspace.
- Replaying your calls on other models when you or your routing settings ask for it. Replays go to model providers through OpenRouter and are subject to their policies.
- Choosing a cheaper model for a use case when routing is on.
- Keeping the service running and secure.
We don’t sell your data. We don’t use your prompts or responses to train models. We don’t show ads.
Who else processes data
Cloudflare (hosting, storage, edge), GitHub (sign-in), our email delivery provider, our payment processor, and the model providers you route or replay to. Each gets only what its job needs.
Your choices
- Switch a workspace to metadata-only mode at any time in the dashboard.
- Unsubscribe from the daily email with the link at the bottom of it.
- Ask us for a copy of your data, or to delete it, by opening an issue or emailing us via GitHub.
Changes
If we change how we handle data in a way that matters, we’ll update this page and tell workspace owners by email before it takes effect.