EnroutiaEU

How our privacy works

“We cannot read your prompts” is a claim about architecture, not about our intentions. This page explains what makes it literally true, and where its limits are.

Last updated: 2026-08-19

What we keep, and for how long

DataWhereHow long
Prompts and responsesMemory, during the request (plus a 1 h in-memory cache unless Confidential Mode)Zero on disk on the API path
Audit samples you send usDatabase, encrypted at restUntil you delete it
Alias examples you saveDatabase, encrypted at restUntil you delete the alias or the account
Usage metadata (tokens, model, latency)DatabaseDetail for 90 days, then daily aggregates
Credit ledger (amounts, no content)Database6 years, accounting obligation
Error and security logs (hashed IP)Disk7 days
Comparator (metadata, no prompt)Database30 days
Transactional emailsEmail providerPer their policy; never any prompt content

What we cannot see

The content of your requests and responses is never written to any disk: not to the database, not to logs, not to backups. The web server's access logs are switched off, so there is not even a record of which IP address requested which path. Application logs carry only errors and security events, with the IP passed through a hash with a daily salt.

The only thing we store is what you hand us

Your traffic prompts are not stored anywhere, and that does not change. The first exception is the test bench: if you press “Save as test”, that specific prompt is stored encrypted so it can be re-run against other models and show you whether a cheaper one does the same job. You choose it, prompt by prompt, there is a limit of 10, and deleting it really deletes it — the prompt and its answers.

Audits work the same way

A spend audit stores the task samples you (or your agency's collector) hand us on purpose: pseudonymised before they leave your systems, encrypted at rest, and capped per audit package. They exist so we can re-run your tasks against cheaper models and show you the evidence. Deleting an audit really deletes it — the samples and every result — and deleting your account deletes all of them.

Saved examples on an alias

The second table that holds prompt text is the one behind an alias's watch: up to five examples you type into the alias's page so that a new model can be tried against them without you doing it by hand. Encrypted at rest exactly like the test bench, never read by anyone but the process that runs them, deleted when you delete the alias, and deleted with everything else when you delete the account.

Confidential Mode

Any key can turn it on. With it, that key never reads or writes the response cache: your content does not spend even an hour in shared memory.

Who else is involved

Your prompts are processed on the inference provider's servers, in the European Union, with no retention and no training. Saying less than this would be a lie: somebody has to run the model, and that somebody sees the text for as long as it takes to answer.

Third parties in your browser

This site loads no external fonts, scripts or CDNs. The two exceptions are the anti-abuse captcha, only on signup and the comparator, and the payment provider's script, only on the payment screen. The analytics we use are cookieless, which is why there is no banner.

The honest limit

Real end-to-end encryption does not exist for inference: the model has to read the prompt to answer it. The serious version of that promise — confidential computing on GPU with attestation — is on the roadmap, with our own infrastructure. We will not promise it before we can demonstrate it.