What we keep, and for how long
| Data | Where | How long |
|---|---|---|
| Prompts and responses | Memory, during the request (plus a 1 h in-memory cache unless Confidential Mode) | Zero on disk on the API path |
| Audit samples you send us | Database, encrypted at rest | Until you delete it |
| Alias examples you save | Database, encrypted at rest | Until you delete the alias or the account |
| Usage metadata (tokens, model, latency) | Database | Detail for 90 days, then daily aggregates |
| Credit ledger (amounts, no content) | Database | 6 years, accounting obligation |
| Error and security logs (hashed IP) | Disk | 7 days |
| Comparator (metadata, no prompt) | Database | 30 days |
| Transactional emails | Email provider | Per their policy; never any prompt content |
What we cannot see
The content of your requests and responses is never written to any disk: not to the database, not to logs, not to backups. The web server's access logs are switched off, so there is not even a record of which IP address requested which path. Application logs carry only errors and security events, with the IP passed through a hash with a daily salt.
The only thing we store is what you hand us
Your traffic prompts are not stored anywhere, and that does not change. The first exception is the test bench: if you press “Save as test”, that specific prompt is stored encrypted so it can be re-run against other models and show you whether a cheaper one does the same job. You choose it, prompt by prompt, there is a limit of 10, and deleting it really deletes it — the prompt and its answers.
Audits work the same way
A spend audit stores the task samples you (or your agency's collector) hand us on purpose: pseudonymised before they leave your systems, encrypted at rest, and capped per audit package. They exist so we can re-run your tasks against cheaper models and show you the evidence. Deleting an audit really deletes it — the samples and every result — and deleting your account deletes all of them.
Saved examples on an alias
The second table that holds prompt text is the one behind an alias's watch: up to five examples you type into the alias's page so that a new model can be tried against them without you doing it by hand. Encrypted at rest exactly like the test bench, never read by anyone but the process that runs them, deleted when you delete the alias, and deleted with everything else when you delete the account.
Confidential Mode
Any key can turn it on. With it, that key never reads or writes the response cache: your content does not spend even an hour in shared memory.
Who else is involved
Your prompts are processed on the inference provider's servers, in the European Union, with no retention and no training. Saying less than this would be a lie: somebody has to run the model, and that somebody sees the text for as long as it takes to answer.
Third parties in your browser
This site loads no external fonts, scripts or CDNs. The two exceptions are the anti-abuse captcha, only on signup and the comparator, and the payment provider's script, only on the payment screen. The analytics we use are cookieless, which is why there is no banner.
The honest limit
Real end-to-end encryption does not exist for inference: the model has to read the prompt to answer it. The serious version of that promise — confidential computing on GPU with attestation — is on the roadmap, with our own infrastructure. We will not promise it before we can demonstrate it.