Privacy Policy
Last updated: 19 September 2026
1. Who we are
GPT Mitra (gptmitra.in) is an LLM inference marketplace operated by Midpath Software Private Limited ("Midpath", "we", "us"), CIN U72900RJ2021PTC076949, 95-B, Vidhyut Nagar, Jaipur – 302019, India. This Policy explains our handling of personal data for accounts, supplier connections, inference routing, usage accounting, support and optional recording.
2. Data we process
- Account information, including email address, password hashes, account identifiers and session records.
- API and supplier key identifiers, hashes, settings, status and associated account information.
- Prompts, messages, submitted content and generated responses processed in transit to provide inference.
- Call metadata, including requester and supplier associations, requested model, timestamps, completion status, token usage where available, and recording status or failures.
- Supplier-advertised models, capacity, connection information and operational information used for routing and quality control.
- Optional per-API-key archive settings, including storage endpoints, bucket details and credentials, and recorded prompts/responses when enabled.
- Support communications, security reports, IP addresses, browser/device information and diagnostic records where collected.
- Payment, invoice and transaction references if paid services are offered. Payment providers process payment credentials under their own policies; do not send card or banking credentials in prompts.
Prompts and outputs may contain personal or confidential information about you or others. Submit only data you are authorised to process, and minimise sensitive information. Application operators are responsible for appropriate notices and lawful instructions when using GPT Mitra for their end users.
3. Purposes and lawful processing
We use data to authenticate accounts, route inference requests, connect suppliers, account for usage, operate optional recording, provide support, assess supplier quality and reliability, detect abuse, secure systems and comply with legal obligations. Supplier quality control does not require recording every consumer prompt. We do not claim that every output is reviewed by a human.
We process personal data with consent or another basis permitted by applicable law, as appropriate to the purpose. Required account and request information is necessary to provide the relevant service. You may withdraw consent for optional future processing through available settings or by contacting us; withdrawal does not invalidate earlier lawful processing. Disabling recording affects future calls, not existing recordings or queued uploads.
4. Suppliers and other recipients
Inference requires transmitting your request content to the selected supplier's system. Suppliers may use upstream model providers with their own infrastructure, processing locations and data practices. Disabling GPT Mitra recording does not prevent this transmission and does not guarantee that a supplier or its upstream provider retains no data. Do not assume zero retention, a particular processing country or suitability for regulated/confidential workloads unless expressly agreed in writing.
We may also disclose necessary data to infrastructure and storage providers, payment providers where used, personnel handling authorised operational/support work, professional advisers and authorities where legally required. Enabled recordings are sent to the storage destination configured for the relevant API key. Access should be limited to the purpose and authorised work. We do not sell personal data.
Providers may process data outside India. We comply with applicable transfer restrictions and use safeguards where required by law. If your workload requires supplier-specific retention, training restrictions or location commitments, obtain written confirmation before submitting it; this Policy does not make those commitments on behalf of independent suppliers.
5. Optional prompt and response recording
GPT Mitra recording is disabled by default and configured separately for each API key. There is no automatic account-wide or system-wide recording destination. With recording disabled, our archive feature creates no prompt/response spool file; account, usage and operational records still exist and suppliers still process the request.
When enabled, the feature captures the original request, streamed response bytes and non-secret call metadata in a bounded local spool, then asynchronously uploads them to that key's configured S3-compatible destination. Authorization headers and API/supplier credentials are not included in the recordings. Archive storage credentials are separately stored to perform uploads.
New archive settings, including storage credentials, are stored as unencrypted JSON in PostgreSQL. Authorised database administrators and anyone with access to these database rows or backups may read them. Secrets are not returned by the settings API. Use restricted storage credentials and protect your destination. Uploads request AES256 server-side encryption, which the storage provider must support.
Each recorded call retains its destination snapshot: changing or disabling settings does not redirect or delete existing queued recordings. Queue limits, disk failures, outages or crashes may produce incomplete recordings. Failed uploads can remain on local disk pending retry or manual recovery. Account holders control access and retention in their storage destination and must disclose recording to their end users.
6. Cookies and website services
We use session cookies for authentication. Browser controls can delete or block cookies, but authenticated functions may then stop working. These legal pages load no external analytics, advertising or UI scripts. Other platform pages and third-party destinations may have their own applicable notices. We do not infer consent to advertising tracking from acceptance of this Policy.
7. Retention and deletion
We retain account, usage, support and security information only as reasonably necessary for service operation, accounting, abuse prevention, dispute handling and legal obligations. Retention depends on the category and applicable requirements; this Policy does not promise automatic deletion after a fixed number of days.
Local completed recording files are deleted after successful upload. Failed or incomplete files may remain for retry or recovery. Uploaded copies follow the storage owner's retention rules. We cannot automatically delete copies in supplier systems or customer-controlled storage; contact the relevant operator for those copies. Backups may retain eligible deleted data until the applicable backup cycle completes, with access restricted.
You may request account closure and deletion of eligible personal data controlled by Midpath. We may retain records required by law or reasonably necessary for security, accounting or legal claims, restricting them to those purposes. Disabling a key or closing an account is not itself a guarantee of immediate deletion of all historical data.
8. Your choices and rights
Subject to applicable law and identity verification, you may request information about processing, access, correction, deletion, withdrawal of consent for optional processing, or nomination of another person to exercise applicable rights where provided by law. Contact our Grievance Officer with enough information to identify the account; do not email passwords or secret keys. Requests may be limited by legal retention requirements or others' rights. You may use available statutory complaint or escalation mechanisms.
9. Security and children
We use reasonable technical and organisational safeguards, including authentication and access controls. No system, transmission or third-party storage is completely secure. Protect credentials, limit permissions and promptly report suspected misuse. We will investigate breaches and notify persons and authorities where required by applicable law. Liability provisions in our Terms do not remove mandatory data-protection obligations.
Accounts are intended for people aged 18 or older. We do not knowingly offer accounts to children. Contact us if a child has provided account data. Do not submit children's personal data without lawful authority and appropriate safeguards.
10. Changes and contact
We may update this Policy and notify material changes through the platform or another reasonable channel. A business transfer may include relevant data subject to this Policy and applicable law.
Grievance Officer: Arjoonn Sharma
Email: grievance@midpathsoftware.com
Address: Midpath Software Private Limited, 95-B, Vidhyut Nagar, Jaipur – 302019
Security reports: security@midpathsoftware.com
Legal questions: legal@midpathsoftware.com
We will acknowledge grievances within 48 hours and seek to resolve them within 30 days, subject to any shorter deadline required by law.
GPT Mitra