Skip to content

Data inventory · one source for page and JSON

What we keep.

Every place a request's text or a wallet address is read, what happens to it, and what is kept. This page and inventory.json are built from the same file, so they always say the same thing.

The short version.

No prompt or answer text is ever written to a database.
  • The router is not live. The website section describes what this site does today; the router section is the design it is built to.
  • A routed call will leave a row of counts, cost and timing plus two SHA-256 hashes, of the request and of the reply, so a receipt can be checked against a request you hold. A hash cannot be turned back into the text.
  • No table and no log line is designed to hold a network address. Rate-limit counters expire within the hour.

This website today.

These are the only places this site reads anything about you right now.

Wallet sign-in

What is read

Your wallet address and the network your wallet is on, shared by your wallet when you connect.

What is kept

Your address, wallet name and wallet id in this browser's localStorage, so you stay signed in. Disconnect removes it. Nothing is stored on a server.

Chain reads (/api/rpc)

What is read

Read-only JSON-RPC calls such as your ETH and USDG balance, relayed to Robinhood Chain because some networks block its public endpoint.

What is kept

Not stored. The call is forwarded and the answer returned. Transactions never pass through the relay.

Model catalog

What is read

The public model list, fetched by this server without any key.

What is kept

The list is held in server memory for up to an hour. It contains no user data.

Console, arena and file questions

What is read

Your prompt, and on the files page the text of the files you add, sent to the model provider through this server when the operator has configured a model key.

What is kept

Not stored by this site. Held in memory for the length of the call. The model provider handles it under its own policy.

The router, by design.

When the router routes calls, its storage is split into the groups below. Each group is described before it exists, and a column that could hold request text or an address needs a written review before it ships.

Call records

One row per call: model, provider, lane, token counts, cost, timing and SHA-256 hashes of the request and the reply. Never the text.

Balances and ledger

USDG balances per wallet, an append-only ledger, spending holds and what each provider is owed.

Receipts and proofs

Signing keys, the Merkle log of receipts, checkpoints and the hourly on-chain anchors that let anyone check a receipt without asking.

Keys and sessions

API keys stored only as hashes, their policies, agent sessions, and the issuer keys behind blind credits.

Providers and evidence

Provider bonds, canary results, attestation checks, measurements and dispute records.

Chain records

Deposits, withdrawals, bond events and anchors read from Robinhood Chain, which are public anyway.

Operations

Rate-limit counters that expire within an hour, health probes and error counts. No network addresses in any table or log line.

Your browser.

The wallet session sits in localStorage under one key and is removed when you disconnect. Pages that take an API key or files keep them in the tab's memory only; a reload clears them.

What this does not claim.

This page is about what is kept. It is not a claim that nobody reads a request while it is in flight: the router reads the text in memory to route it, and the provider that answers reads it too, under its own policy. Attested lanes narrow who that provider can be; they do not make the text invisible to the model that answers.