Operate
Privacy
Prompts, responses and tool content are captured by default for debugging. Private traces expire after 30 days.
What a request leaves behind
| Item | Stored |
|---|---|
| Prompt content (30-day debug trace) | Yes |
| Completion and tool content (30-day debug trace) | Yes |
| Token counts in / out / cached | Yes |
| Model ID and serving upstream | Yes |
| Cost, latency, request status | Yes |
| Your name, email, identity | No |
Request traces retain message history, model responses, tool arguments and results, and partial streamed output. Access is restricted to authenticated administrators and content views are audited. Recognizable credentials are redacted; embedded binary data is omitted and large captures are truncated. Expired traces are hidden immediately and deleted automatically. Billing records remain separate. Content is not sent to analytics or used for training.
Identity
No account is required; see authentication. An accountless key has no email, name, or identity attached. The key is the identity. The HTTP-Referer and X-Title headers feed per-client attribution counts, not identification.
Provider privacy
Your prompts transit our edge and the upstream that serves the request. Each upstream has its own retention policy, and we do not control their logging. Every model page names which upstreams serve that model. Fusion also sends a shortened copy of the request to a TypeSafe classifier; no other model ID does. Full policy: /legal/privacy.