Privacy
We default to not storing prompt or completion content. Not encrypted, not retained-for-30-days — not stored.
What a request leaves behind
- ItemPrompt contentStoredNO
- ItemCompletion contentStoredNO
- ItemToken counts in / out / cachedStoredYES
- ItemModel id and serving upstreamStoredYES
- ItemCost, latency, request statusStoredYES
- ItemYour name, email, identityStoredNO
The usage record is what metering needs and nothing else: token counts (in, out, cached), model id, serving upstream, cost, latency, status. The words are relayed and forgotten. Logging toggles exist in settings and default off.
Identity
No account is required — see authentication. An accountless key has no email, name, or identity attached; the key is the identity. The HTTP-Referer and X-Title headers feed per-client attribution counts, not identification.
The honest boundary
Your prompts transit our edge and the upstream that serves the request. Each upstream has its own retention policy — we do not control their logging. Every model page names which upstreams serve that model. Full policy: /legal/privacy.