Clear answers for your review
See what happens to a prompt you send us, who can access what, and get the documents and contacts your security and legal teams need.
- Prompts and outputs not stored
- Never used for training
- European data centres
- ISO 27001 audit in progress
What happens to your prompt
Your app calls a model through our serverless API. Here’s what we see and keep at each stop.
Draft a thank-you note to the team who fixed the office coffee machine.
- Your app
You send a request
- We see
- Nothing yet. Your request travels over HTTPS, so it’s encrypted on the way.
- We keep
- Nothing.
- We don’t keep
- Your conversation history. It stays in your app, which sends what each request needs.
- Our gateway
We check your key
- We see
- Your API key, the model you asked for and your prompt, which passes through in memory.
- We keep
- A usage record: your organisation and user, the model, token counts and the time.
- We don’t keep
- Your prompt text. We never log it or write it to a database.
- GPU
The model runs
- We see
- Your prompt, in GPU memory in a European data centre, while the model writes the answer.
- We keep
- Recent prompt prefixes, in GPU memory, until newer requests replace them. That’s what makes cached input cheaper.
- We don’t keep
- Your prompt, on disk or in a database.
- Your app
The answer streams back
- We see
- The response, as it streams back to your app.
- We keep
- The output token count, added to the usage record.
- We don’t keep
- The response text.
What we keep
- Request
- req_8c1e…4f2a
- Organisation
- Your organisation
- User
- The key’s owner
- Model
- moonshotai/kimi-k3
- Input tokens
- 1,204
- Of which cached
- 896
- Output tokens
- 312
- Time
- 29 September 2026, 10:42am
What we never record
- Prompt text
- Never recorded
- Response text
- Never recorded
What stays, and for how long
We don’t store your prompts or responses. Here’s what we do keep, why, and what happens to it when you leave.
Your prompt and the response
Everything you send and everything the model writes back.
- During a request
- In memoryOn our gateway and a GPU while the model works.
- After a request
- Not keptRecent prompt prefixes stay in GPU memory as a cache until newer requests replace them.
- When you leave
- Nothing to deleteWe never stored them, so there’s nothing to return.
Usage records and system logs
Neither contains your prompt or the response.
- During a request
- WrittenAs your request passes through our gateway.
- After a request
- KeptTo bill you, run and secure the service, and plan capacity.
- When you leave
- Deleted or returnedThe personal data in them, unless the law requires us to keep it.
Your account
Name, email address, API keys and billing details.
- During a request
- CheckedWe check your API key before your request goes any further.
- After a request
- KeptFor as long as your contract runs.
- When you leave
- Deleted or returnedYou choose which, unless the law requires us to keep something.
When you leave, email us whether you want your data deleted or returned.[email protected]
Who can access your data
Three parties can: our team, our subprocessors and you. Here’s what each can and can’t see.
The people who run Lyceum
- Can access
- Your account details, usage records and system logs.
- Can’t see
- Your prompts and responses. We never log them or write them to a database, so there’s nothing to open.
- Why
- To run the platform, support you, bill you and keep the service secure.
- Where
- Lyceum Technology Germany GmbH in Berlin and Lyceum Switzerland GmbH in Zurich.
- In writing
- Access only where your contract needs it, and a duty of confidentiality for everyone who has it.
Companies that run part of the service for us
- Can access
- Only the data their part of the service needs, such as providing GPU capacity or processing payments.
- Can’t see
- Anything outside their part. A payment provider never sees a prompt, for example.
- Why
- To provide that part of the service for us, and for no other purpose.
- Where
- Mainly in the EU and the European Economic Area (EEA). Anything outside it is covered by the GDPR’s safeguards, such as standard contractual clauses.
- In writing
- The same data protection duties we have. We tell you before we add or replace one, and you can object within 10 business days.
The controller of your data
- Can access
- Your prompts, responses and conversation history in your own app, and your account and API keys in our dashboard.
- Can’t see
- Nothing of yours. Ask us what we hold about your account and we’ll tell you.
- Why
- You decide what we process and why. Under our DPA, you’re the controller and we’re the processor.
- Where
- Your own systems, and our dashboard.
- In writing
- Instruct us in writing at any time, audit us with notice, and choose deletion or return when you leave.
If something goes wrong, you hear from us straight away. Our DPA obliges us to tell you immediately about any breach involving your personal data.
The documents for your review
Most are open to read in Vanta, our compliance platform. The rest are one request or one email away.
- Open to readRead the DPA
Data processing agreement (DPA)
- Request in VantaRequest the TOMs
Technical and organisational measures (TOMs)
- By emailAsk for the list
Subprocessor list
- Open to readRead the letter
ISO 27001 engagement letter
- Open to readSee the controls
Security controls
- On this siteRead the terms
Terms of service
- On this siteRead the policy
Privacy policy
Who to ask, and what to send
- Email compliance
Security questionnaires
- Email compliance
The DPA and your contract
- Talk to an expert
Dedicated endpoints and locations
A call with our engineers
- Email privacy
Requests about your own data
Questions reviewers often ask
Do we need to sign a separate DPA?
No. The DPA is Annex 1 of our terms, so it applies when you accept them. If your legal team needs changes, send them to compliance.
Email complianceCan we rule out a subprocessor?
Yes. Which subprocessors apply depends on the service you choose, so your choice of service can rule one out. You can also object to a new subprocessor within 10 business days of our notice.
Ask for the listWhat about GPU virtual machines and training jobs?
Code you send us stays yours. We don’t store it permanently, never use it for training and delete it promptly when you ask. Storage on a GPU virtual machine is there to run your workload, not to archive it, so keep your own backups.
Read the termsWhat happens if there’s a security incident?
Our DPA obliges us to tell you immediately about any breach involving your personal data. Service incidents appear on the public status page.
Check the status pageWhat service levels do you offer?
Our public status page shows live status, per-model latency and past incidents. Business customers also get a direct line to the engineers who run the platform, with contractual response times.
Talk to an expertWhere are you with ISO 27001?
Our ISO 27001:2022 audit is in progress. Vanta monitors our controls continuously, and its engagement letter confirms the audit engagement.
Read the engagement letter