Explained · Staying private

Who can see your prompts? Privacy, retention and where a provider lives

When you rent inference, your prompts pass through someone else's machines. Whether that matters depends on three questions people blur into one — is it trained on, how long is it kept, and whose law applies — with different answers at the same provider.

Updated 23 Sept 2026

When you rent inference, your prompts pass through someone else's machines. Whether that matters depends on three questions people tend to blur into one — and they have different answers at the same provider.

One: is your traffic used for training? Some providers train on what you send through free tiers or consumer apps; paid API traffic usually carries a written promise not to. The word that matters is written — a policy page you can cite, not a vibe. Our provider pages show the training answer where a provider states one, and show unknown as unknown: a blank is never a promise.

Two: how long is it kept? Separate from training. Most providers log requests for some window — often for abuse monitoring — and some offer a zero-retention option where prompts are processed and dropped. The retention window and the zero-retention mark are on our provider pages where the provider publishes them. If neither of you can point at a number, assume logs exist.

Three: who can make them hand it over? This is the one people underweight, and it follows the company, not the servers. A US-incorporated provider can be compelled under US law (the CLOUD Act) to produce data under its control wherever it is stored — a US company's EU region is still a US company. An EU-headquartered provider running EU infrastructure answers to a different legal order entirely. That is the honest version of "EU hosting": the flag on the data centre matters less than the flag on the company. Server location still matters for latency and for some compliance regimes — it just is not the whole answer.

What to actually do. For genuinely sensitive material — client work, health, anything you'd redact — the clean answer is not sending it anywhere: a local model has no third question. For everything else, pick a provider whose written policy answers all three questions, prefer the zero-retention option where one exists, and treat any unanswered question as a no. The same open model is often served by many providers at similar prices — when the model is equal, the policy is the product.

Where next: Compare providers · When to run models locally · What a provider is

Questions people actually ask

Does "EU hosting" keep my prompts out of US reach?+

Not by itself. Legal reach follows the company, not the servers — a US company's EU region is still a US company. What EU hosting does buy is latency and some compliance regimes; for legal jurisdiction, look at where the provider is incorporated.

Is the paid API safer than the free chat app?+

Usually — paid API traffic commonly carries a written no-training promise where free and consumer tiers often do not. The word that matters is written: a policy page you can cite. Our provider pages link the policy where one exists.

What does the zero-retention mark on your provider pages mean?+

The provider states that prompts on that endpoint are processed and dropped rather than logged. Where the mark is absent, that is a gap in what we hold, not a statement the provider keeps your data — but until either of us can point at a policy, assume logs exist.

Three questions, not one — trained on, kept how long, and answerable to whom. A blank is never a promise.