Privacy Policy
What we collect, what we do not, and how long anything is kept.
1. Request content
Prompts and completions are processed in memory and are not written to disk by default. They are forwarded to the upstream provider you selected by naming a model, and that provider's own policy applies to their handling.
2. Optional logging
You may enable 30-day request logging per key for debugging. Turning it off purges existing rows within 24 hours. Logging is off unless you switch it on.
3. Metadata we always keep
Timestamp, key id, model id, upstream id, token counts, status code and latency. This is what billing and rate limiting are computed from, and it is retained for 24 months.
4. Account data
Email, organisation name and payment references held by our payment processor. We never see or store full card numbers.
5. Sub-processors
Model providers you route to, our payment processor, and our cloud host. A current list is available on request and changes are announced before they take effect.
6. Your rights
Request export or deletion of your account data at any time by email. Deletion completes within 30 days, minus records we must retain for tax purposes.