Privacy Policy

CostPlusIQ, a product of Ensoul Inc · Effective 2026-10-03

CostPlusIQ, a product of Ensoul Inc. This policy says what we keep and what we do not. Retention is set per API key: every key is created as standard (the default) or ZDR, and the key that authorizes a request determines how its content is handled. On top of that we keep the metadata needed to run the service and bill for it.

Standard keys (the default): you allow training

A standard-tier key — the tier pre-selected at key creation, offered in exchange for the lower standard rates listed on the pricing page — grants us a licence to retain and use the content of requests sent with it: prompts, uploaded or referenced media, and the model’s completions are written to our internal training and evaluation stores, attributed to your account email and the key id. Metadata handling is otherwise as below. Delete the key to stop granting the licence for future requests; ask privacy@ensoul.inc to remove previously retained content.

Before 2026-08-23 ZDR was the default. The tier is fixed when a key is minted, so keys created before that date are still ZDR and this change does not reach back to them, nor to content already served under a ZDR key.

ZDR keys: zero retention

Choose ZDR at key creation and request content — your prompts, uploaded or referenced media, and the model’s completions — is processed in memory only. It is never written to disk or a database, never used to train or fine-tune any model, and never shared for another party’s own purposes. The inference servers run with request and output logging disabled, and the access logs record paths and status codes, never query strings or bodies. When your response finishes, the content is gone. ZDR keys bill at the full published rates.

What we do keep

datawhyhow long
Per-request metering: API key id, account email, model, timestamp, duration, HTTP status, serving host, and token counts Accurate billing, and evidence for a billing dispute 7 years, as billing records
Standard-tier request content only: prompts, media, and model completions, attributed to the key id and account email Training, evaluating and improving our models — the licence a standard key grants Until you ask us to delete it
Monthly totals derived from the above Tax and accounting obligations 7 years
Account: email address, name, sign-in provider account identifier, a one-way hash of your password if you set one (never the password itself), and metadata about the keys you create (never a key itself — we store only a SHA-256 hash) Sign-in and key management Life of the account, plus 30 days
Website and console request logs: route, status, duration, and the signed-in email Operating the site — the console, not the inference path 90 days
Edge logs for this domain DDoS protection and TLS; retained by our edge provider under its terms, not ours Per the edge provider’s policy

Where inference happens

Model inference runs in us-central1 (US), uk-south1 (GB), eu-north1 (FI), us-marketplace (US), us-denver (US), ca-marketplace (CA), gb-marketplace (GB), de-marketplace (DE), fr-marketplace (FR), nl-marketplace (NL), fi-marketplace (FI), cz-marketplace (CZ), bg-marketplace (BG), au-marketplace (AU), jp-marketplace (JP), and each model’s document entry names the region serving it. Your request content touches only the machines serving your request. ZDR request content is not retained.

During an outage, or when a model’s own serving capacity is full, direct API requests for models with a configured backup may route to a third-party provider in the US, with zero-retention routing and response caching disabled. A backup may use a different model. These providers process the request to return your answer; they do not retain its content or use it for training. The response identifies the model that answered, and your token rates stay the same.

Inference and routing providers process ZDR content only to serve the request, without retaining it or training on it. They may retain billing and operational metadata. Standard-tier content is also stored encrypted in object storage under the licence that tier grants.

Cookies

Three, all strictly necessary, all first-party: cpiq_session (your signed sign-in session), cpiq_oauth_state (CSRF protection during sign-in) and cpiq_email_link (ties an emailed confirmation link to the browser that opened it, for 15 minutes). No analytics, no advertising. The one third-party script is a bot check on the console’s email sign-in form, which checks that a person, not a bot, is asking us to send mail.

Your rights

You can see your account data, balance and usage records in the console, and you can ask us to delete your account and its records at any time, subject to the accounting records we are required to keep. We do not sell personal data, and we process it only to provide the service you asked for. Requests and questions: privacy@ensoul.inc.

CostPlusIQ, a product of Ensoul Inc · Home · API documentation · Terms · Privacy · Refunds