Privacy
The whole model, including the parts that are inconvenient for us.
Five modes, what each one actually does, what it costs you, who processes your prompt on every route, how long anything is kept, and the full list of companies that can see any of it. Nothing on this page is a claim you cannot check inside the product.
routes in the catalogue
423 models, refreshed from the gateway
qualify for Private
every one names its processor and its verification date
processors, all named
409 routes have no named processor and stay at Standard
The five modes
Set per conversation, enforced per request
An admin can set a floor for the whole organisation; nobody can go below it, including the admin, without an entry in the route log.
Standard
all 428 routesThe default. Threads, attachments and generated images are stored on our servers so you can search them, resume them on another device and share them with a team.
Live from the router: Standard · T0 · web search allowed · stored server-side
What you get
- Every model in the catalogue
- Web search with citations
- Sync, search, export and share
- Lowest price per token
What you give up
- The provider that serves the request may retain the prompt briefly for abuse monitoring — up to 30 days on some routes
- Your thread text sits in our database, encrypted at rest but readable by us if you ask support to look at it
Retention
Thread stored until you delete it. Provider retention: whatever that route's declaration says — the route table on the privacy page states it per route.
Private
5 of 428 routesThe router will only choose a route whose contract says the prompt and response are used for inference and then discarded. If no such route can serve your model, the request is refused.
Live from the router: Private · T1 · no web search · stored server-side
What you get
- Contractual zero retention on the provider side
- Named provider, region and contract date on every reply
- Still synced to your account so you keep your history
What you give up
- Far fewer routes — only the ones a human has verified qualify, and the count is on the privacy page
- Higher cost per token on the zero-retention routes
- No web search: fetching a page means telling a search provider what you asked
Retention
Thread stored until you delete it. Provider retention: none, contractually.
Browser-only
5 of 428 routesMessages are held in your browser. Our server sees the request in flight because it has to proxy it, and then forgets it — no thread row, no message row, no attachment on disk.
Live from the router: Browser-only · T1 · no web search · never written server-side
What you get
- No server-side record of the conversation exists
- Works with every zero-retention route
- Clearing your browser data really does delete it
What you give up
- No sync — the thread exists on one device only
- No cross-device search
- No recovery: clear your browser, lose the thread
- No sharing, no team access
Retention
Nothing stored server-side beyond a usage counter with no content.
Temporary
5 of 428 routesHeld in memory for the life of the tab. Nothing is written to our database and nothing is written to your device's storage either.
Live from the router: Temporary · T1 · no web search · never written server-side
What you get
- The shortest possible lifetime for a conversation
- No artefact to delete afterwards, anywhere
- Ideal for a question you would not put in a ticket
What you give up
- No history at all — close the tab and it is gone
- A refresh loses the thread
- You cannot export it after the fact, only during
Retention
Nothing stored, anywhere. A usage counter records that a request happened, not what it said.
Local model
designed, not enabled in this buildYour own routesPoint the workspace at a model server on your own network. The prompt never leaves your perimeter. Designed and specified; not switched on in the current build.
Live from the router: Local model · T3 · no web search · stored server-side
What you get
- No egress at all — nothing leaves your network
- You own the logs, the weights and the hardware
- The only mode that survives an offline audit
What you give up
- Weaker models than the frontier closed-weight ones
- Slower, unless you own real GPUs
- You run the infrastructure and carry the uptime
Retention
Whatever your own server does. We never see it.
Side by side
Mode comparison
| Standard | Private | Browser-only | Temporary | Local model | |
|---|---|---|---|---|---|
| Thread stored on our servers | Yes | Yes | No | No | No |
| Thread stored on your device | Cached | Cached | Yes | In memory only | Yes |
| Provider may retain the prompt | Per route — see the table | No | No | No | Not applicable |
| Synced across devices | Yes | Yes | No | No | No |
| Server-side search of history | Yes | Yes | No | No | No |
| Web search available | Yes | No | No | No | No |
| Document Q&A available | Yes | Yes | No | No | Yes |
| Image generation available | Yes | Yes | Yes | Yes | No |
| Relative cost per token | Baseline | Higher | Higher | Higher | Your hardware |
| Survives losing your laptop | Yes | Yes | No | No | Depends on you |
Scroll the table sideways to see all five modes.
Fail-closed
A rule with an exception is a preference.
Before any request leaves, the router resolves your mode into a set of hard constraints — retention term, region, whether a subprocessor is involved — and filters the catalogue against them. If the filtered set is empty, the request is refused and nothing is transmitted. There is no fallback path, no “best effort” route, and no configuration flag that turns this off.
The refusal itself is logged, because you should be able to prove later that a request was held. Its content is not.
Who processes your prompt
The route table, published.
Every route we have written a declaration for names the legal entity that runs it, the region it runs in, the retention term we hold it to, and the date we last read those terms. The product records which route served each of your requests. This table is generated from that same table — it is not a copy maintained separately for marketing.
This is the part most privacy pages leave out. A zero-retention promise is only as good as the party making it, so a promise that does not name the party is not checkable — you are being asked to trust a company you have not been told about. Publishing the table costs us almost nothing and it is the only version of the claim that means anything.
| Processing entity | Region | Routes | Private-eligible |
|---|---|---|---|
| Anthropic PBC | us | 2 | — |
| Black Forest Labs GmbH | us | 1 | — |
| DeepInfra, Inc. | us | 2 | 1 |
| Fireworks AI, Inc. | us | 2 | 1 |
| Google LLC | us | 3 | — |
| Mistral AI SAS | eu · us | 2 | 1 |
| OpenAI, L.L.C. | us | 3 | — |
| Together Computer, Inc. | us | 4 | 2 |
Scroll the table sideways to see route counts.
Private-eligible routes
Every route that can serve a Private conversation, and why we say so.
A date on its own is an appeal to our own authority. So each route below carries the sentence describing what its claim actually rests on — which published terms were read, and what they said. Where the evidence is thinner than its neighbours', the sentence says that too.
- Processed by
- DeepInfra, Inc.
- Region
- us
- Retention
- None — contractual
- Verified
- 18 August 2026
- Re-check due
- in 86 days
On what basis: DeepInfra's published privacy policy states that inference input and output are not stored. Read 2026-08-18. This is the thinnest evidence of the five: it is a privacy policy, not API-specific terms, and it carries no certification. Treated as sufficient for T1 and disclosed as weaker than its neighbours.
- Processed by
- Fireworks AI, Inc.
- Region
- us
- Retention
- None — contractual
- Verified
- 18 August 2026
- Re-check due
- in 86 days
On what basis: Fireworks AI's published API terms state that inference requests are not logged or retained on the serverless API. Read 2026-08-18 alongside OpenRouter's zero-retention endpoint policy. Open weights, so the model can be served by an operator willing to say this; the closed frontier models cannot be.
- Processed by
- Mistral AI SAS
- Region
- eu
- Retention
- None — contractual
- Verified
- 18 August 2026
- Re-check due
- in 86 days
On what basis: Mistral's published API privacy terms state that La Plateforme API data is processed in the EU and is not retained or used for training without opt-in. Read 2026-08-18. EU processing is the load-bearing part of this route's claim; the zero-retention part rests on the same published page.
- Processed by
- Together Computer, Inc.
- Region
- us
- Retention
- None — contractual
- Verified
- 18 August 2026
- Re-check due
- in 86 days
On what basis: Together AI's published API terms state that prompts and completions on the inference API are not stored and not used for training. Read 2026-08-18 alongside OpenRouter's zero-retention endpoint policy. Published terms, not a negotiated addendum, and not independently audited.
- Processed by
- Together Computer, Inc.
- Region
- us
- Retention
- None — contractual
- Verified
- 18 August 2026
- Re-check due
- in 86 days
On what basis: Served by Together AI under the same published no-storage, no-training API terms as the Llama route. Read 2026-08-18. The model weights are Alibaba's; the processor is Together, and the processor is what this claim is about.
5 of 428 routes. The oldest verification still standing is 18 August 2026. These dates are the dates the published terms were read. They are not an audit, and there is no third-party report behind them.
Each declaration has a re-check date. When it passes, the route stops qualifying for Private by itself — no deploy, no decision, no meeting — and the count at the top of this page goes down. A number that can fall on its own is the only kind worth printing.
Data retention
What is kept, and for how long
Deletion is real deletion: a delete removes the row, and we keep no shadow copy for analytics. Where a row has no scheduled deletion yet, the table says so rather than quoting a period nothing enforces.
| Data | Standard | Private | Browser-only | Temporary |
|---|---|---|---|---|
| Thread and message text | Until you delete it | Until you delete it | Never written | Never written |
| Attachments and uploads | Until you delete it | Until you delete it | Never written | Never written |
| Generated images | Until you delete it | Until you delete it | Held in the tab | Held in the tab |
| Provider-side copy of the prompt | Per route — the route table states it | None, contractual | None, contractual | None, contractual |
| Route record (which provider served you) | Kept — no scheduled deletion yet | Kept — no scheduled deletion yet | Kept — no scheduled deletion yet | Kept — no scheduled deletion yet |
| Usage counter (tokens, cost, no content) | Kept — no scheduled deletion yet | Kept — no scheduled deletion yet | Kept — no scheduled deletion yet | Kept — no scheduled deletion yet |
| Access log (IP, user agent) | Container log, size-capped, not time-capped | Container log, size-capped, not time-capped | Container log, size-capped, not time-capped | Container log, size-capped, not time-capped |
| Backups | Only what an operator takes by hand | Only what an operator takes by hand | Nothing to back up | Nothing to back up |
Scroll the table sideways to see every mode.
Subprocessors
Every company that can touch your data
The full register, with what each one is for. The model processors above are generated from the route table; this list is the rest of the stack — hosting, TLS, search and billing — and it is maintained by hand, so it carries a date rather than a query.
| Company | Purpose | Region | Data it sees | Terms |
|---|---|---|---|---|
| Anthropic PBC | Model inference (Claude family) | United States | Prompt and response content | Zero-retention addendum on the Private route; 30-day abuse retention on the Standard route |
| OpenAI, L.L.C. | Model inference (GPT family) | United States | Prompt and response content | Zero-data-retention endpoint, contractual |
| Google LLC | Model inference (Gemini family) | United States | Prompt and response content | Standard API terms — Standard mode only, never offered under Private |
| Mistral AI SAS | Model inference (Mistral family) | France | Prompt and response content | Zero retention, EU processing |
| OpenRouter, Inc. | AI gateway — every model call is routed through it before reaching any vendor above | United States | Prompt and response content for every route, plus request metadata | Governed by OpenRouter's own policy — read it and record the basis before relying on it |
| Internet Security Research Group (Let's Encrypt) | TLS certificate issuance | United States | The hostname only. No request or conversation content | Certificate transparency logs are public by design |
| [VPS provider — fill in] | Server hosting | [fill in] | All stored data, at rest on their disks | [check whether a DPA is in place] |
Scroll the table sideways to see region, data and terms.
What we will not do
Train on your conversations. Sell or share them. Add a subprocessor without telling you. Serve a request from a route that does not meet the mode you set.
What we cannot do
Promise end-to-end encryption. We proxy the request, so in flight we can read it. Any product that offers server-side search of your history is in the same position, whatever the marketing says.
What is not audited yet
There is no SOC 2 report and no ISO 27001 certificate. The route table is self-published and verified by us. An independent audit is planned; until it exists we will not imply it does.
Try it, then go and check the route log.
Free plan, 200 credits a month, no card. Every answer you get will tell you which company processed it — including the ones on the free plan.