Data policy
Decide what is archived and for how long, redact secrets before archiving, turn on zero data retention, limit providers and regions, and get your legal documents.
The data policy decides what happens to your prompts and responses: whether they are archived, for how long, which providers may see them, and where they are processed. Open it from the Data policy tab under Settings.
The settings here are the defaults for the whole organization. Projects and keys can only be stricter, never looser. See projects and API keys.
Changing the policy needs the owner or admin role. Other roles can read it.
The page has three parts: the policy form, the Per-provider policy table and Documents.
Logging and retention
Archive prompts and responses turns the payload archive on or off. With it on, you can open a request later and read what was sent and returned. See requests.
Retention is how long an archived payload is kept: 7, 30, 90 or 365 days. When that time is up, the payload is made unreadable for good.
Images and audio are never archived.
Redaction before archive
Redaction removes sensitive values from the archived copy. It never changes what reaches the provider. A removed value is replaced by a marker that says which rule matched.
Tick the presets you want:
- API keys: keys and tokens from common providers and services, and bearer tokens.
- Card numbers: card numbers that pass the standard check digit test.
- Aadhaar: Aadhaar numbers.
- PAN: Indian income-tax PANs.
- Email addresses
- Phone numbers: Indian and international formats.
Hover a preset to see what it catches.
Custom patterns
Under Custom patterns (one regex per line), add your own regular expressions, one per line. A policy can hold up to 20 patterns. A pattern is refused if it is empty, longer than 200 characters, or able to match an empty string, because such a pattern would redact everything. An invalid pattern shows its error under the field.
Preview
Preview on a sample shows what your presets and patterns would do. Type or paste some text, or leave the field empty to use the built-in sample. The box below updates as you type and shows the number of redactions and the redacted text.
Use the preview before you save. Nothing in it is stored.
Zero data retention
Zero-data-retention mode is one switch that does four things:
- Nothing is archived, so the archive checkbox and the retention selector are disabled.
- The response cache and request replay are off.
- Requests are routed only to endpoints that offer zero data retention.
- The end-user ids you send are kept only as a hash.
When you tick it, the page checks which models would stay available and lists the ones that would not. Press Save data policy and a confirmation appears with the number of models that become unavailable. Press Confirm and save to turn it on.
While it is on, the page reminds you that routing only to these endpoints can reduce capacity during a provider incident.
Providers and regions
No-train: exclude providers that train on API data removes every provider whose terms allow training on what you send.
Allowed processing regions (none = any) limits where your requests are processed: India, United States or European Union. Tick none to allow any region. If you allow India only, models hosted only elsewhere become unavailable.
A request that no allowed endpoint can serve is refused. It is never sent to a provider your policy excludes.
Save
Press Save data policy. Keys pick up the new policy within a minute.
Per-provider policy
This table shows what each provider does with API data, taken from its published terms:
- Trains on data: yes or no.
- Retention: how many days the provider keeps data, or none.
- ZDR: whether zero data retention is available.
- Regions: where the provider processes requests.
- Source: a link to the provider's terms.
- Verified: when the entry was last checked.
The no-train and zero-data-retention settings above filter on these values.
Documents
Accept a legal document
The Documents table lists the published legal documents with their version and status. Click a title to read the document.
A document that needs your acceptance shows not accepted, or new version when a newer version has replaced the one you accepted. Press Accept to record your acceptance.
A document that binds the whole organization can be accepted only by an owner or admin. Other roles see owner or admin only.
The console also shows a banner at the top of every screen while a document is waiting, with an I accept button for each one. Nothing is paused while a document is unread: your API keys keep working.
Download the data processing agreement
The data processing agreement is in the Documents table. Click its title to open your organization's copy.
Sub-processors
Sub-processors shows the version of the list in force, since when, and how many sub-processors it names. A change is announced ahead of time, by email and through the subprocessors.changed webhook. The section says how many days ahead.
When a change is pending, a notice lists what will be added, removed or updated and the date it takes effect. To object, restrict the provider in the policy above.
Acceptance records
Acceptance records lists every acceptance for the organization: the document, the version, who accepted it, when, and the address it came from.
Templates for your own compliance
Three downloads at the bottom of the section are filled in with your organization's details:
- download (Markdown): a DPDP notice template to give your own users.
- record of processing (Art. 30): a record of processing activities for your GDPR register.
- standard contractual clauses (module 2): the standard contractual clauses pack for customers in the EU.
They are templates, not legal advice. These and the other legal routes are in the legal API reference.
Related
- Privacy requests: erase or export the data of one end user.
- Organization settings: erase all of the organization's data.
- Your own provider keys and routing: other ways to control which provider serves a request.
Single sign-on and SCIM
Connect your SAML or OIDC identity provider, verify your email domains, map groups to roles, enforce single sign-on and provision members from your directory.
Privacy requests
Export or erase the records of one of your end users when they exercise their right of access or erasure.