Clear answers for your review

See what happens to a prompt you send us, who can access what, and get the documents and contacts your security and legal teams need.

  • Prompts and outputs not stored
  • Never used for training
  • European data centres
  • ISO 27001 audit in progress

What happens to your prompt

Your app calls a model through our serverless API. Here’s what we see and keep at each stop.

Example prompt
Draft a thank-you note to the team who fixed the office coffee machine.

Draft a thank-you note to the team who fixed the office coffee machine.

Nobody on our team can open it. Prompts and outputs are processed, not stored, and never used for training.
  1. Your app

    You send a request

    We see
    Nothing yet. Your request travels over HTTPS, so it’s encrypted on the way.
    We keep
    Nothing.
    We don’t keep
    Your conversation history. It stays in your app, which sends what each request needs.
  2. Our gateway

    We check your key

    We see
    Your API key, the model you asked for and your prompt, which passes through in memory.
    We keep
    A usage record: your organisation and user, the model, token counts and the time.
    We don’t keep
    Your prompt text. We never log it or write it to a database.
  3. GPU

    The model runs

    We see
    Your prompt, in GPU memory in a European data centre, while the model writes the answer.
    We keep
    Recent prompt prefixes, in GPU memory, until newer requests replace them. That’s what makes cached input cheaper.
    We don’t keep
    Your prompt, on disk or in a database.
  4. Your app

    The answer streams back

    We see
    The response, as it streams back to your app.
    We keep
    The output token count, added to the usage record.
    We don’t keep
    The response text.
usage-recordExample values
The only record a request leavesWe keep it to bill you and run the service. It never contains your prompt or the response.

What we keep

Request
req_8c1e…4f2a
Organisation
Your organisation
User
The key’s owner
Model
moonshotai/kimi-k3
Input tokens
1,204
Of which cached
896
Output tokens
312
Time
29 September 2026, 10:42am

What we never record

Prompt text
Never recorded
Response text
Never recorded

What stays, and for how long

We don’t store your prompts or responses. Here’s what we do keep, why, and what happens to it when you leave.

Your prompt and the response

Everything you send and everything the model writes back.

During a request
In memoryOn our gateway and a GPU while the model works.
After a request
Not keptRecent prompt prefixes stay in GPU memory as a cache until newer requests replace them.
When you leave
Nothing to deleteWe never stored them, so there’s nothing to return.

Usage records and system logs

Neither contains your prompt or the response.

During a request
WrittenAs your request passes through our gateway.
After a request
KeptTo bill you, run and secure the service, and plan capacity.
When you leave
Deleted or returnedThe personal data in them, unless the law requires us to keep it.

Your account

Name, email address, API keys and billing details.

During a request
CheckedWe check your API key before your request goes any further.
After a request
KeptFor as long as your contract runs.
When you leave
Deleted or returnedYou choose which, unless the law requires us to keep something.

When you leave, email us whether you want your data deleted or returned.[email protected]

Who can access your data

Three parties can: our team, our subprocessors and you. Here’s what each can and can’t see.

  • The people who run Lyceum

    Can access
    Your account details, usage records and system logs.
    Can’t see
    Your prompts and responses. We never log them or write them to a database, so there’s nothing to open.
    Why
    To run the platform, support you, bill you and keep the service secure.
    Where
    Lyceum Technology Germany GmbH in Berlin and Lyceum Switzerland GmbH in Zurich.
    In writing
    Access only where your contract needs it, and a duty of confidentiality for everyone who has it.
  • Companies that run part of the service for us

    Can access
    Only the data their part of the service needs, such as providing GPU capacity or processing payments.
    Can’t see
    Anything outside their part. A payment provider never sees a prompt, for example.
    Why
    To provide that part of the service for us, and for no other purpose.
    Where
    Mainly in the EU and the European Economic Area (EEA). Anything outside it is covered by the GDPR’s safeguards, such as standard contractual clauses.
    In writing
    The same data protection duties we have. We tell you before we add or replace one, and you can object within 10 business days.
  • The controller of your data

    Can access
    Your prompts, responses and conversation history in your own app, and your account and API keys in our dashboard.
    Can’t see
    Nothing of yours. Ask us what we hold about your account and we’ll tell you.
    Why
    You decide what we process and why. Under our DPA, you’re the controller and we’re the processor.
    Where
    Your own systems, and our dashboard.
    In writing
    Instruct us in writing at any time, audit us with notice, and choose deletion or return when you leave.

If something goes wrong, you hear from us straight away. Our DPA obliges us to tell you immediately about any breach involving your personal data.

The documents for your review

Most are open to read in Vanta, our compliance platform. The rest are one request or one email away.

All documents in Vanta

Who to ask, and what to send

Questions reviewers often ask

Do we need to sign a separate DPA?

No. The DPA is Annex 1 of our terms, so it applies when you accept them. If your legal team needs changes, send them to compliance.

Email compliance

Can we rule out a subprocessor?

Yes. Which subprocessors apply depends on the service you choose, so your choice of service can rule one out. You can also object to a new subprocessor within 10 business days of our notice.

Ask for the list

What about GPU virtual machines and training jobs?

Code you send us stays yours. We don’t store it permanently, never use it for training and delete it promptly when you ask. Storage on a GPU virtual machine is there to run your workload, not to archive it, so keep your own backups.

Read the terms

What happens if there’s a security incident?

Our DPA obliges us to tell you immediately about any breach involving your personal data. Service incidents appear on the public status page.

Check the status page

What service levels do you offer?

Our public status page shows live status, per-model latency and past incidents. Business customers also get a direct line to the engineers who run the platform, with contractual response times.

Talk to an expert

Where are you with ISO 27001?

Our ISO 27001:2022 audit is in progress. Vanta monitors our controls continuously, and its engagement letter confirms the audit engagement.

Read the engagement letter

Ready when your review is