Privacy
Zero request retention, no training on customer requests, regional processing, and data handling.
Zro is built so that your inference traffic stays yours. This page summarizes how requests are processed and what is stored. The full legal text lives in the Privacy Notice.
Zero request retention
We do not retain prompts, responses, or request bodies. Content exists only for as long as it takes to process the request and return your response.
Zero retention is built into how the service runs. There is no setting, plan, or feature that stores request content.
One caveat: prompt caching holds prefixes you have recently sent in a short-lived cache so repeated requests finish faster and cost less. Cached prefixes are scoped to your account and to the model that served them, and they age out of the cache. They are not kept after they are no longer useful for serving your requests.
No training on your requests
We do not use customer requests or logs for training, fine-tuning, evaluations, analytics, or other secondary purposes unless you separately and explicitly agree, and we do not authorize our providers to do so either.
Where inference runs
Every request is authenticated and routed through the European Union. Your API key's region setting determines whether model inference may run in Europe, the United States, or either:
- A request fails rather than running outside the key's allowed regions.
- When our own GPU capacity is unavailable, inference runs on third-party infrastructure providers acting on our instructions. A provider receives only the request content needed to generate a completion, and the completion comes back to you. The region setting binds this equally.
- Region selection applies to model inference only. It does not determine where account, billing, authentication, analytics, or web-search processing occurs.
What is stored
| Data | Retained |
|---|---|
| Prompt and completion content | Never |
| Account identifiers, API-key metadata | While the account is active, plus legal retention |
| Token and cost totals, billing records | While the account is active, plus legal retention |
| Security and reliability logs | As needed to operate and protect the service |
| Analytics events | Per provider retention periods |
Analytics
Website and product analytics run through PostHog EU and Google Analytics. Prompt and completion bodies are never sent to analytics services. PostHog session recording and autocapture are disabled, so your screen, keystrokes, and form contents are never recorded.
Data Processing Agreement
Our Data Processing Agreement describes the processor obligations, security measures, sub-processors, international transfer mechanisms, and data-subject rights assistance that apply when MoonMath processes personal data on your behalf as part of the service. It is mainly relevant for Teams and Enterprise customers who need formal processor terms, and it applies only when a copy has been executed with you. If you need a DPA, download the DPA (PDF), review it, and return a countersigned copy to us.
Web search
When a tool call invokes web search, only the search query and its parameters are sent to the search provider, never the full conversation.
Related
- Regions: per-key region selection.
- Privacy Notice: the complete legal notice, including your rights.