Privacy

We default to not storing prompt or completion content. Not encrypted, not retained-for-30-days — not stored.

What a request leaves behind

  • ItemPrompt content
    StoredNO
  • ItemCompletion content
    StoredNO
  • ItemToken counts in / out / cached
    StoredYES
  • ItemModel id and serving upstream
    StoredYES
  • ItemCost, latency, request status
    StoredYES
  • ItemYour name, email, identity
    StoredNO

The usage record is what metering needs and nothing else: token counts (in, out, cached), model id, serving upstream, cost, latency, status. The words are relayed and forgotten. Logging toggles exist in settings and default off.

Identity

No account is required — see authentication. An accountless key has no email, name, or identity attached; the key is the identity. The HTTP-Referer and X-Title headers feed per-client attribution counts, not identification.

The honest boundary

Your prompts transit our edge and the upstream that serves the request. Each upstream has its own retention policy — we do not control their logging. Every model page names which upstreams serve that model. Full policy: /legal/privacy.