How to read this page
AI Reserve routes requests to the model you select. The table below lists each model provider we route to and summarizes, from that provider's own published enterprise API terms:
- Trains on API inputs? — whether the provider uses API inputs or outputs to train or fine-tune its models under its current terms.
- Retention — how long the provider retains prompts and completions after processing.
- Processing region — where the provider states requests are processed and stored.
- Role — the provider's role under our Data Processing Addendum. A Subprocessor processes data only on our documented instructions. A provider that processes data for its own purposes (for example, one whose terms permit training on inputs) is an Independent controller, not a subprocessor, and is identified as such.
Provider table
| Provider | Trains on API inputs? | Retention | Processing region | Role |
|---|---|---|---|---|
| OpenAI (direct API) | No, by default.1 | Inputs/outputs retained up to 30 days for abuse monitoring, then deleted. Zero Data Retention available on approval.2 | United States | Subprocessor |
| Anthropic (direct API) | No, under commercial terms.3 | Inputs/outputs deleted within 30 days. Note: Anthropic's "Covered Models" (including Claude Fable 5, which we route) require 30-day retention and are not eligible for Zero Data Retention.4 | United States | Subprocessor |
| AWS Bedrock | No. Inputs/outputs are not used to train foundation models and are not shared with the underlying model providers.5 | Not stored by default; retention depends on the account's Bedrock data-retention mode (abuse-detection retention may apply in default mode; none = zero retention). Our account's configured mode: pending verification.6 |
United States (us-east-1) | Subprocessor |
| Google Gemini API (paid tier) | No, on paid services.7 | Prompts/responses logged up to 55 days solely for abuse monitoring, then deleted.8 | Global — Google's terms state data may be stored transiently or cached in any country where Google or its agents maintain facilities.7 | Subprocessor |
| xAI (Grok) | No, without explicit permission.9 | Requests/responses stored encrypted for 30 days for abuse auditing, then auto-deleted. Zero Data Retention available for enterprise accounts.9 | United States | Subprocessor |
| Perplexity (Sonar) | No.10 | Zero data retention on the Sonar API — prompts/responses deleted after processing; only billing metadata (token counts, timestamps) retained.10 | United States (AWS, North America)11 | Subprocessor |
| DeepSeek (direct API) | Yes. DeepSeek's privacy policy states inputs are used to train and improve its models and services.12 | No published fixed deletion window; retained under its privacy policy. pending verification | China (People's Republic of China) — DeepSeek states it collects, processes, and stores data on servers in the PRC.12 | Independent controller |
| Moonshot AI (Kimi) | Yes. Moonshot's platform privacy policy states user content is used to train and refine its models.13 | No published fixed deletion window; retained under its privacy policy. pending verification | China (PRC-headquartered provider). Moonshot's international platform terms state its servers are located in Singapore; the endpoint serving our account is pending verification. Treat data sent to Kimi models as processed outside the United States under PRC-affiliated jurisdiction.13 | Independent controller |
| Together AI | No — training use is opt-in only and not enabled.14 | Prompts/outputs not stored by default (zero-data-retention posture); temporary caching may be used for performance.14 | United States | Subprocessor |
| Fireworks AI | No, without explicit opt-in.15 | Zero data retention by default — prompts/generations exist only in volatile memory for the duration of the request; not written to persistent storage.15 | United States | Subprocessor |
| OpenRouter | No — OpenRouter does not train models; its own prompt logging is opt-in and off by default.16 | OpenRouter stores request metadata only (no prompt/response content) by default. Retention at the downstream serving endpoint is governed by that endpoint's own policy; per-route endpoint policies for our account: pending verification.16 | United States (routing layer); downstream serving endpoint varies by route. pending verification | Subprocessor (routing layer; see note) |
| NVIDIA (hosted NIM API catalog) | Under the published API-catalog trial terms, NVIDIA may use inputs/outputs to improve its products and services, including AI models. Whether different terms apply to our account tier: pending verification.17 | Content used to provide the service during the session; usage logged for security/fraud/abuse monitoring. No published fixed deletion window. pending verification | United States | Independent controller (under current trial terms; pending verification) |
| fal.ai (image/video generation) | No — fal's API services terms state client content is not used to train or develop its products, except for models designated "Pending Enterprise Ready".18 | Request payloads stored 30 days by default (opt-out available per request); generated media stored on fal's CDN per configured lifecycle.18 | United States | Subprocessor |
Notes & clarifications
Aggregators and open-weight models
Together AI, Fireworks AI, OpenRouter, and NVIDIA serve open-weight models
published by other organizations (for example, Meta Llama, Mistral, Qwen, DeepSeek,
Moonshot Kimi, and OpenAI's GPT-OSS family). When a model is served by a US aggregator,
the aggregator's data-handling terms apply — the model's original
publisher never receives the request. For example, deepseek-v4-flash and
kimi-k2.6 are served by Fireworks AI in the United States under Fireworks'
zero-retention terms, even though the underlying models were published by DeepSeek and
Moonshot. Only the direct-API rows above (DeepSeek direct, Moonshot's own
API for kimi-k3 and moonshot-v1-*) send data to those companies.
AWS Bedrock model routing
Models with a -bedrock suffix route through AWS Bedrock in the United
States. AWS operates the model inside AWS infrastructure; the model's publisher
(Anthropic, Meta, Mistral, DeepSeek) does not receive prompts or completions, except
where a specific Bedrock model requires provider data sharing and the account has
explicitly enabled that mode — we have not enabled provider data sharing.
Zero Data Retention
Several providers offer stricter Zero Data Retention (ZDR) arrangements on request (OpenAI, Anthropic, xAI, Together AI). The table reflects the standard enterprise default that applies to gateway traffic today. Where ZDR has not been separately confirmed for our account, assume the standard retention window shown. If your organization requires ZDR on a specific provider, contact us.
What AI Reserve itself retains
Independently of the providers above, the AI Reserve gateway logs request metadata (model, token counts, cost, latency, status, and user/key attribution) to operate billing and spend governance. By default, the platform also stores prompt and response content to power chat history, search, audit, and usage classification.
Zero content retention (optional). Enterprise administrators can turn off content storage for their entire organization from the admin console ("Store prompt & response content"). While disabled, the platform persists no prompt or response text and performs no content-based classification — only the billing metadata above is retained. Previously stored content can be permanently deleted on demand from the same surface. See our Terms of Service and Data Processing Addendum for the platform's retention commitments.
Sources
Provider policy documents reviewed on July 23, 2026. Providers may update their terms; this page is reviewed periodically and updated when material changes are identified.
- OpenAI — Business data privacy: https://openai.com/business-data/
- OpenAI — Data controls in the OpenAI platform: https://developers.openai.com/api/docs/guides/your-data
- Anthropic — How long do you store my organization's data?: https://privacy.claude.com/en/articles/7996866
- Anthropic — API and data retention (Covered Models): https://platform.claude.com/docs/en/manage-claude/api-and-data-retention
- AWS — Amazon Bedrock security, privacy & responsible AI: https://aws.amazon.com/bedrock/security-privacy-responsible-ai/
- AWS — Amazon Bedrock data retention modes: https://docs.aws.amazon.com/bedrock/latest/userguide/data-retention.html
- Google — Gemini API Additional Terms of Service: https://ai.google.dev/gemini-api/terms
- Google — Gemini API abuse monitoring: https://ai.google.dev/gemini-api/docs/usage-policies
- xAI — API security FAQ: https://docs.x.ai/developers/faq/security; Enterprise Terms of Service: https://x.ai/legal/terms-of-service-enterprise
- Perplexity — Privacy & Security (Sonar API): https://docs.perplexity.ai/docs/resources/privacy-security
- Perplexity — FAQ (hosting): https://docs.perplexity.ai/docs/resources/faq
- DeepSeek — Privacy Policy: https://cdn.deepseek.com/policies/en-US/deepseek-privacy-policy.html
- Moonshot AI — Kimi OpenPlatform Privacy Policy: https://platform.kimi.ai/docs/agreement/userprivacy
- Together AI — Privacy Policy: https://www.together.ai/privacy; Privacy and security docs: https://docs.together.ai/docs/privacy-and-security
- Fireworks AI — Zero Data Retention: https://docs.fireworks.ai/guides/security_compliance/data_handling; Privacy Policy: https://fireworks.ai/privacy-policy
- OpenRouter — Data collection: https://openrouter.ai/docs/guides/privacy/data-collection; Zero Data Retention controls: https://openrouter.ai/docs/guides/features/zdr
- NVIDIA — API Trial Terms of Service (§2–3): https://assets.ngc.nvidia.com/products/api-catalog/legal/NVIDIA API Trial Terms of Service.pdf
- fal — API Services Terms: https://fal.ai/legal/api-services; Data Retention & Storage: https://fal.ai/docs/documentation/model-apis/media-expiration