Is my data private? Logging and retention
Learn what data the platform sees when you call models, how logging and retention work, and the privacy considerations of sending data to third-party models.
What the platform sees
When you send a request through the platform, it passes through our API gateway. We necessarily see:
- Your API key (to authenticate you)
- The model you selected
- The request payload (your prompt and any attached data)
- Metadata such as timestamp and token counts
We do not inspect or use the content of your prompts for any purpose other than forwarding them to the model provider and returning the response.
Logging and retention
We keep minimal logs for operational purposes:
- Request metadata: timestamp, model, token counts, and status. This helps with billing, debugging, and abuse prevention.
- Prompt and response content: We do not log the full content of your prompts or the model's responses by default. If we ever need to enable content logging for troubleshooting, we will do so only with your explicit consent and for a limited time.
Retention periods for metadata are kept as short as practical. If you require specific retention guarantees, contact us before sending sensitive data.
Third-party model providers
Most models available through the platform are hosted by third-party providers. When you call a model, your request is forwarded to that provider, and their privacy policy and data handling practices apply.
- Some providers may log requests for their own purposes (e.g., abuse monitoring, service improvement).
- Some providers may retain data for a period defined in their terms.
- Some providers may use data to train future models unless you opt out or use a zero-retention endpoint.
We cannot make promises on behalf of third-party providers. Before sending sensitive data, review the provider's documentation and terms.
What we do not do
- We do not sell your data.
- We do not share your data with advertisers.
- We do not use your prompts or responses to train models.
Your responsibilities
You are responsible for the data you send through the platform. Consider these practices:
- Avoid sending highly sensitive information (e.g., personal health data, financial records, credentials) unless you have verified that the model provider offers appropriate protections.
- Use environment variables or a secrets manager to keep your API key secure.
- If you need zero data retention, check whether the model provider offers that option and whether it is available through our platform.
Summary
The platform sees your requests only to route them to the model provider. We keep minimal metadata logs and do not retain prompt content by default. However, third-party providers may have their own logging and retention policies. Always review those policies and consider the sensitivity of your data before sending it.