CostPlusIQ, a product of Ensoul Inc. This policy says what we keep and what we do not. Retention is set per API key: every key is created as standard (the default) or ZDR, and the key that authorizes a request determines how its content is handled. On top of that we keep the metadata needed to run the service and bill for it.
A standard-tier key — the tier pre-selected at key creation, offered in exchange for the lower standard rates listed on the pricing page — grants us a licence to retain and use the content of requests sent with it: prompts, uploaded or referenced media, and the model’s completions are written to our internal training and evaluation stores, attributed to your account email and the key id. Metadata handling is otherwise as below. Delete the key to stop granting the licence for future requests; ask privacy@ensoul.inc to remove previously retained content.
Before 2026-08-23 ZDR was the default. The tier is fixed when a key is minted, so keys created before that date are still ZDR and this change does not reach back to them, nor to content already served under a ZDR key.
Choose ZDR at key creation and request content — your prompts, uploaded or referenced media, and the model’s completions — is processed in memory only. It is never written to disk or a database, never used to train or fine-tune any model, and never shared for another party’s own purposes. The inference servers run with request and output logging disabled, and the access logs record paths and status codes, never query strings or bodies. When your response finishes, the content is gone. ZDR keys bill at the full published rates.
| data | why | how long |
|---|---|---|
| Per-request metering: API key id, account email, model, timestamp, duration, HTTP status, serving host, and token counts | Accurate billing, and evidence for a billing dispute | 7 years, as billing records |
| Standard-tier request content only: prompts, media, and model completions, attributed to the key id and account email | Training, evaluating and improving our models — the licence a standard key grants | Until you ask us to delete it |
| Monthly totals derived from the above | Tax and accounting obligations | 7 years |
| Account: email address, name, sign-in provider account identifier, a one-way hash of your password if you set one (never the password itself), and metadata about the keys you create (never a key itself — we store only a SHA-256 hash) | Sign-in and key management | Life of the account, plus 30 days |
| Website and console request logs: route, status, duration, and the signed-in email | Operating the site — the console, not the inference path | 90 days |
| Edge logs for this domain | DDoS protection and TLS; retained by our edge provider under its terms, not ours | Per the edge provider’s policy |
Model inference runs in us-central1 (US), uk-south1 (GB), eu-north1 (FI), us-marketplace (US), us-denver (US), ca-marketplace (CA), gb-marketplace (GB), de-marketplace (DE), fr-marketplace (FR), nl-marketplace (NL), fi-marketplace (FI), cz-marketplace (CZ), bg-marketplace (BG), au-marketplace (AU), jp-marketplace (JP), and each model’s document entry names the region serving it. Your request content touches only the machines serving your request. ZDR request content is not retained.
During an outage, or when a model’s own serving capacity is full, direct API requests for models with a configured backup may route to a third-party provider in the US, with zero-retention routing and response caching disabled. A backup may use a different model. These providers process the request to return your answer; they do not retain its content or use it for training. The response identifies the model that answered, and your token rates stay the same.
Inference and routing providers process ZDR content only to serve the request, without retaining it or training on it. They may retain billing and operational metadata. Standard-tier content is also stored encrypted in object storage under the licence that tier grants.
Three, all strictly necessary, all first-party:
cpiq_session (your signed sign-in session),
cpiq_oauth_state (CSRF protection during sign-in) and
cpiq_email_link (ties an emailed confirmation link to the
browser that opened it, for 15 minutes). No analytics, no advertising. The one
third-party script is a bot check on the console’s email
sign-in form, which checks that a person, not a bot, is asking us to send
mail.
You can see your account data, balance and usage records in the console, and you can ask us to delete your account and its records at any time, subject to the accounting records we are required to keep. We do not sell personal data, and we process it only to provide the service you asked for. Requests and questions: privacy@ensoul.inc.