LEGAL
Privacy policy
Last updated · July 4, 2026
This policy explains what n4n ("we", "us") collects when you use n4n.io, the n4n AI gateway at n4n.ai, and related n4n services — and what we do with it. The short version: we collect what we need to run your account, route your requests and bill you. We do not sell your data, and we do not use your prompts to train models.
What we collect
- Account data. When you sign in with Google or GitHub we receive your name, email address and profile picture, plus a stable account identifier. We do not receive your password.
- API keys. Keys are stored as salted SHA-256 hashes together with a short prefix so you can recognize them. We cannot recover a full key after it is created.
- Request metadata. For each API request we record the model, provider, token counts, latency, status and cost. This powers your usage dashboard and billing.
- Billing records. Top-ups, balances and a ledger of credits and charges. Card and wallet details stay with the payment processor — we never see or store them.
- Server logs. Standard access logs (IP address, user agent, timestamps) kept for security and debugging.
Prompts and completions
The content of your requests — prompts, messages, files and model outputs — is processed in transit to fulfil your request and returned to you. We store request metadata (token counts, model, cost), not the content itself. Content is never used to train models, ours or anyone else's.
To serve a request we forward its content to the upstream model provider you selected (for example OpenAI, Anthropic or an aggregator such as OpenRouter). Their handling of that content is governed by their own terms and privacy policies.
Google user data
When you connect a Google account to n4n — for example through n4n Connect, so an agent can work with your calendar or send mail on your behalf — you grant that access yourself on Google's own consent screen, and you can withdraw it at any time. This section explains exactly what we do with it.
What we request, and why:
openid,userinfo.email,userinfo.profile— to identify which Google account a connection belongs to, so you can tell your connections apart.calendar— to list your upcoming events and create events you ask us to create.gmail.send— to send a message you ask us to send. This scope cannot read, list or delete your mail; sending is all it permits.drive.file— to create files and reopen files created through n4n. This is the narrow per-file grant: it gives us no view of the rest of your Drive.
How it is used. Google data is used only to carry out actions you or your agent explicitly request, at the moment you request them. We do not read your Google data in the background, we do not use it for advertising or profiling, we do not sell or transfer it, and we never use it to train models — ours or anyone else's.
How it is stored. The OAuth tokens Google issues are encrypted at rest with AES-256-GCM under a key-encryption key held outside the database, and are decrypted only in memory for the moment a request is served. We do not keep copies of your emails, calendar events or files — request results are returned to you, not retained.
How to revoke. Disconnect the account in the n4n Connect dashboard, which deletes the stored credential outright, or revoke n4n's access from your Google account permissions page. Either action ends our access immediately.
Limited Use. n4n's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Cookies
We set a single HttpOnly session cookie (n4n_session) after you sign in, so we know it's you. We do not use advertising cookies or third-party trackers.
Payments
Credit top-ups are processed by PayPal or a cryptocurrency payment processor. We receive a confirmation of your payment (amount, status, a transaction reference) but not your payment credentials.
How long we keep data
- Account and billing records: for as long as your account exists, and afterwards as required for accounting and tax law.
- Request metadata: retained to provide usage history; you can ask us to delete it.
- Server logs: rotated on a short schedule, typically within 30 days.
Your rights
You can ask us to export or delete the personal data we hold about you, correct inaccurate data, or close your account entirely. Email support@n4n.io and we will respond within 30 days. If you are in the EEA or UK, you also have the right to lodge a complaint with your local supervisory authority.
Security
All traffic is encrypted in transit with TLS. API keys are stored only as hashes, sessions are opaque server-side tokens, and access to production systems is restricted. No system is perfectly secure — if we learn of a breach affecting your data we will notify you without undue delay.
Children
n4n services are not directed at children under 16, and we do not knowingly collect their data.
Changes
If we change this policy we will update the date at the top of this page, and for material changes we will notify you by email or in the console before they take effect.
Contact
Questions about privacy: support@n4n.io.