Privacy Policy
Last updated: June 2026
LLM Locker ("we", "us") helps developers store LLM API keys securely and track provider spend. This policy describes what we collect and how we use it.
What we collect
- Account email and authentication data (via Supabase)
- API keys you vault — encrypted with AES-256-GCM before storage
- Spend snapshots and usage history synced from providers you connect
- Billing data processed by Stripe (we do not store card numbers)
How we use data
We use your data to provide the vault, sync spend, send budget alerts, and process subscriptions. We do not sell your data or use your API keys for our own inference.
Security
Keys are encrypted at rest. Database access is protected by row-level security. Service-role access is limited to server-side API routes.
Contact
Questions: support@llmlocker.io