Kourier uses optional analytics across our website, dashboard, and docs to connect referral sources with signup, payment, and first API use. We do not send API content or use analytics for targeted advertising. Read our Privacy Policy.

Legal & data protection

Data use & retention

Last reviewed: October 3, 2026

Your prompts and outputs are not training data. Retention deserves an equally clear explanation.

Current ZDR status: not an end-to-end guarantee

Content logging is disabled in our inference gateway. Historical content-bearing logs still exist, however, and their deletion and backup expiry have not been completed and verified. We therefore do not currently claim that all prompts and outputs have zero retention across every system, cache, and backup.

No training or fine-tuning

We do not use your API prompts, supplied context, or generated outputs to train or fine-tune models. Processing a request to generate an answer is inference, not training. Operational usage measurements help us run the service; they do not require training on the contents of your requests.

What content logging being disabled means

Since October 2, 2026 (UTC), our inference gateway has been configured not to persist prompt and response content in its request logs. The reviewed settings also disable raw request/response logging overrides and content export to object storage. This describes the gateway configuration, not proof that every possible error path or infrastructure layer is free of content.

Requests necessarily pass through memory during inference. Our routing layer retains request-derived text in memory, and model servers use prefix caches that can outlive an individual request. Disabling request-body logging is not the same as disabling those caches or establishing a verified deletion deadline for them.

Older content-bearing logs and infrastructure backups are separate from newly generated request logs. Until historical deletion, backup expiry, cache behavior, and the full request path are verified, an unqualified zero-data-retention claim would be misleading. Contact us before sending data that requires a contractual ZDR commitment.

What we retain to operate the service

  • Usage and reliability metadata: request and account identifiers, model, timestamps, status, latency, token counts, and cache-use counts for your dashboard, limits, troubleshooting, and capacity planning.
  • Account and billing records: account details, authentication records, subscription state, invoices, and payment references.
  • Security and support records: technical request information, access records, and information you choose to include in a support request.
  • Optional analytics: consented website and account-activity analytics, separate from inference content. We do not send prompts or outputs as analytics event data.

These records can be personal data even when identifiers are hashed or pseudonymized. They are not all subject to the same retention period. A promise about inference-content retention would not mean that billing, security, or account records disappear after each request. Please avoid sending prompts, secrets, or sensitive customer records through support channels.

Business requirements and privacy requests

For a DPA, processing-location requirement, or a specific retention commitment, discuss your requirements with us before sending the relevant data. These commitments require an agreed scope and signed terms; this page is not a certification or an executed DPA.

For access or deletion requests, contact privacy@kourier.sh. Our Privacy Policy covers account data, service providers, cookies, and your rights; our Terms of Service cover use of the platform and content rights.