gin

Privacy

Last updated October 7, 2026

Who we are

Gin is made by Winding Labs. “We” means Winding Labs. This page covers trygin.ai, the Gin dashboard, the @winding-labs/gin CLI and SDK, and the routing edge.

What we collect

How long we keep it

How bodies are protected

Bodies are encrypted with AES-GCM using a key unique to your workspace before they are stored. In metadata-only mode, bodies are dropped on arrival and never written.

Your provider keys

When you route through Gin, your provider key travels with each request to Gin’s edge and is forwarded to the provider. We never write it to storage or logs. When you only observe, the SDK never sends your key to us at all.

What we use data for

We don’t sell your data. We don’t use your prompts or responses to train models. We don’t show ads.

Analytics on trygin.ai

The marketing pages use Google Analytics 4 and PostHog to count visits and a few named actions (button clicks, copying the install command, using the cost calculator, completing sign-in). The dashboard sends only named events such as completed sign-in, with an opaque user ID: no autocapture, no session recording and no page text. We never send your email, prompts, responses or keys to analytics. Neither tool loads if your browser sends Do Not Track or Global Privacy Control.

Who else processes data

Cloudflare (hosting, storage, edge), GitHub (sign-in), Google Analytics and PostHog (site analytics), our email delivery provider, our payment processor, and the model providers you route or replay to. Each gets only what its job needs.

Your choices

Changes

If we change how we handle data in a way that matters, we’ll update this page and tell workspace owners by email before it takes effect.