privacy-prompt-retention · EN · 2026-10-09

Does the Aggregator Store My Prompts? Reading the Retention Policy Before You Send Sensitive Text

Understand how prompt data may be logged as it travels through an API aggregator and upstream providers, and learn practical steps to verify retention policies before sending sensitive text.

When you send a prompt through an LLM API aggregator, your text passes through multiple systems: the aggregator's gateway, the model provider's infrastructure, and sometimes intermediate services. Each may log request bodies for debugging, billing, abuse monitoring, or model improvement. Before pasting internal documents, contracts, or personal data, you should understand what is retained, for how long, and under what conditions.

The Path of a Prompt

A typical request flows through these stages:

  • Your client – The application or script that sends the API call.
  • Aggregator gateway – Receives the request, authenticates your key, routes it to the chosen model, and may log metadata (timestamp, model, token counts) and sometimes the full request body.
  • Upstream provider – The original model vendor (e.g., Anthropic, OpenAI) processes the prompt and may log it according to its own policies.
  • Response path – The generated text returns through the same chain, potentially logged at each hop.

Logging at any stage can capture your prompt in plaintext or encrypted form. The aggregator's policy determines whether it stores request bodies, for how long, and who can access them.

What Aggregators Typically Log

Aggregators vary, but common logging practices include:

  • Metadata only – Model name, token counts, latency, status code, and timestamp. This does not include your prompt text.
  • Full request/response bodies – The entire prompt and completion, often stored for a limited period (e.g., hours to days) for troubleshooting and abuse detection.
  • Error logs – When a request fails, the payload may be captured to diagnose the issue.
  • Billing records – Token usage per request, linked to your account, but usually not the text itself.

Some aggregators offer a zero-retention option or allow you to opt out of logging. Others may not log request bodies by default. Always check the specific policy.

Upstream Provider Policies Matter Too

Even if the aggregator does not log your prompt, the upstream provider likely has its own retention rules. Major providers often state that they do not train on API data by default, but they may retain data for abuse monitoring for a set period. Since the aggregator forwards your request to the provider, the provider's policy applies independently.

When you use an aggregator, you are subject to both the aggregator's and the provider's terms. Some aggregators pass through the provider's data handling commitments; others may add their own layer.

How to Verify Retention Before Sending Sensitive Text

Follow these steps to assess risk:

  1. Read the aggregator's privacy policy and terms of service – Look for sections on data retention, logging, and subprocessors. Search for terms like "request body," "prompt logging," "retention period," and "zero retention."
  2. Check for a dedicated data handling page – Many aggregators publish a trust center or security page detailing what they log and for how long.
  3. Look for opt-out or configuration options – Some platforms let you disable request logging in account settings or via a header.
  4. Review the upstream provider's policy – If you know which model you'll use, check that provider's API data usage policy. The aggregator may link to it.
  5. Contact support if unclear – Ask specific questions: Do you log full request bodies? For how long? Are logs encrypted? Who can access them? Under what circumstances are they shared?
  6. Test with non-sensitive data first – Send a canary prompt containing unique text, then ask support whether that text appears in logs. This is a practical way to confirm logging behavior.

Practical Safeguards

If you must send sensitive text, consider these precautions:

  • Redact or anonymize – Remove names, identifiers, and confidential details before sending. Use placeholders.
  • Use a zero-retention endpoint if available – Some aggregators offer a mode where request bodies are not stored. Verify it contractually.
  • Segment by sensitivity – Use the aggregator for non-sensitive tasks and a direct, enterprise-grade contract with the provider for highly sensitive data.
  • Encrypt at the application layer – If you control both ends, you could encrypt the prompt so only the model can decrypt it, but this is rarely supported by LLM APIs.
  • Keep audit logs – Track what you send and when, so you can assess exposure if a policy changes.

Remember that no API call is truly private unless you have a contractual guarantee. For regulated data (e.g., health, financial), you likely need a business associate agreement or equivalent, which most aggregators do not offer.

Summary

Prompt retention depends on both the aggregator and the upstream provider. Before sending sensitive text, read the retention policies, look for opt-out options, and ask pointed questions. When in doubt, redact or use a provider with explicit zero-retention guarantees. The convenience of a single API key should not come at the cost of uncontrolled data exposure.