Core promise
We do not log or write the content of your API requests or responses to persistent storage. When you call our inference API, the text, images, files, audio, and other content you send, along with the content the model generates, are processed in memory to serve your request. They are never written to a database, log file, or other persistent storage. Prompt-derived key-value cache data may remain temporarily in volatile GPU memory to accelerate repeated prefixes and is automatically evicted. This is the default for all API traffic.
1. Scope and our role
Open Scale operates model-inference infrastructure as a provider to OpenRouter. OpenRouter sends inference requests to our systems and returns the generated responses to its users.
End-user accounts, API keys, and billing are handled entirely by OpenRouter. Open Scale does not manage or have access to that information. OpenRouter's handling of accounts, API keys, billing, and other customer information is governed by OpenRouter's own privacy policy.
For inference content processed on OpenRouter's behalf, Open Scale acts as a data processor or subprocessor. For the limited operational metadata and website communications described below, Open Scale acts as a data controller.
2. API inference data
When the API is called, request bodies (prompts) and response bodies (completions) are processed transiently in memory and returned to the caller. This data is never written to persistent storage.
Content we do not collect
For API inference, we do not collect:
- Prompt text or any content within your requests.
- Model responses or generated output.
- Conversation history across requests.
- Images, files, or other attachments sent through the API.
How content is handled
None of the above categories of content data are written to persistent storage. Your prompts and completions are processed in memory for inference. The inference engine may temporarily retain prompt-derived key-value cache data in volatile GPU memory to accelerate repeated prefixes and increase cache hit rates across requests. This cache is isolated, automatically evicted, and never written to persistent storage.
3. What we log
To operate the platform, maintain reliability, and prevent abuse, we record metadata that does not include prompt or response content:
- Request and response token counts (input, output, and cached tokens).
- Latency metrics (time-to-first-token, throughput, total duration).
- Model identifier, endpoint, HTTP status code, and stop reason.
- Coarse request identifiers used for rate limiting and abuse prevention.
- Timestamp and, where configured, a coarse geographic region.
- API key identifier (not the key itself).
These operational logs are used for debugging, capacity planning, security monitoring, and abuse prevention. They are retained in accordance with Section 7 (Data retention and deletion).
5. Training and distillation
We do not train or fine-tune models on inference data. Your prompts, completions, and any other content submitted through the API are never used to train, fine-tune, or distill any model, whether operated by us or by any third party.
We do not use data to improve our models, develop new products, or conduct research. Data is used solely to serve API requests.
7. Data retention and deletion
- API request content. Not retained in persistent storage. The inference engine may temporarily retain prompt-derived key-value cache data in volatile GPU memory to maintain high cache hit rates until it is automatically evicted.
- Operational metadata. Retained for up to 30 days for debugging, capacity planning, and abuse prevention, then automatically deleted or anonymized.
- Website and email communications. Retained for as long as necessary to respond to your inquiry and for up to 24 months afterward for quality assurance.
Because Open Scale does not operate user accounts or process payments, there is no account deletion or billing cancellation process on our end. For requests related to your OpenRouter account, contact OpenRouter directly.
8. Security
We use industry-standard security measures to protect your data, including:
- Encryption in transit (TLS 1.2+) for all API and website traffic.
- Access controls and principle-of-least-privilege for internal systems.
- Isolated inference environments that prevent cross-tenant data access.
- Regular security reviews and operational monitoring.
9. Data breach notification
Because Open Scale does not retain API request content in persistent storage, the scope of personal information that could be exposed in a breach is limited to operational metadata (retained up to 30 days) and website/email communications.
If a breach affects personal information we control, we will notify affected individuals and relevant authorities as required by applicable law.
10. Your rights
Because Open Scale does not operate user accounts or have direct relationships with end users, the personal data we control is limited to data from website visitors and email communications. If you have contacted us directly, you may have rights to access, correct, delete, or obtain a copy of that information.
To exercise a right regarding personal data controlled by Open Scale, contact us at legal@openscalecloud.com. For information controlled by OpenRouter, submit your request directly to OpenRouter.
11. US state privacy rights
If you are a resident of California, Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Montana, Oregon, Tennessee, Texas, Utah, Virginia, or Nebraska, you may have additional rights under your state's consumer privacy law, including:
- The right to know what personal information we collect, use, and disclose.
- The right to request deletion of your personal information.
- The right to correct inaccurate personal information.
- The right to opt out of the sale or sharing of personal information.
- The right to limit use of sensitive personal information.
- The right to non-discrimination for exercising your privacy rights.
We do not sell or share your personal information. We do not use personal information for targeted advertising.
California residents: Under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA), the categories of personal information we collect are: identifiers (name, email) and internet activity (API usage metadata). We do not collect biometric data, geolocation, financial data, or sensitive personal information.
To exercise your state privacy rights, contact us at legal@openscalecloud.com.
12. EEA / UK users (GDPR)
If you are located in the European Economic Area (EEA) or the United Kingdom, the following additional provisions apply:
Legal basis for processing
We process your personal data on the following legal bases:
- Contract performance (Art. 6(1)(b) GDPR). Processing is necessary to provide the inference services requested through the platforms we serve.
- Legitimate interests (Art. 6(1)(f) GDPR). We process operational metadata for security, fraud prevention, and platform improvement, where these interests are not overridden by your rights.
- Legal obligation (Art. 6(1)(c) GDPR). We retain certain data as required by applicable law (such as tax and accounting records).
Our role
Open Scale is the data controller for website data, support communications, and operational metadata that we determine how and why to process. When we process API content on behalf of a platform partner such as OpenRouter, we act as a data processor or subprocessor and process that content only to provide the requested inference service.
13. International data transfers
Your data may be transferred to, stored, and processed in the United States or other countries where our infrastructure providers operate.
For transfers from the EEA or UK to countries that have not received an adequacy decision, we rely on Standard Contractual Clauses (SCCs) or other appropriate safeguards to ensure your data is protected in accordance with applicable data protection law.
14. Changes to this policy
We may update this privacy policy from time to time. The "Last updated" date at the top of this page reflects when changes were last made. Your continued use of the service after changes take effect constitutes acceptance of the updated policy.
Contact
For questions about this privacy policy, to exercise your data rights, or to report a security concern, contact us at:
Email: legal@openscalecloud.com