Data inventory · one source for page and JSON
What we keep.
The short version.
No prompt or answer text is ever written to a database.
- The router is not live. The website section describes what this site does today; the router section is the design it is built to.
- A routed call will leave a row of counts, cost and timing plus two SHA-256 hashes, of the request and of the reply, so a receipt can be checked against a request you hold. A hash cannot be turned back into the text.
- No table and no log line is designed to hold a network address. Rate-limit counters expire within the hour.
This website today.
These are the only places this site reads anything about you right now.
Wallet sign-in
What is read
Your wallet address and the network your wallet is on, shared by your wallet when you connect.
What is kept
Your address, wallet name and wallet id in this browser's localStorage, so you stay signed in. Disconnect removes it. Nothing is stored on a server.
Chain reads (/api/rpc)
What is read
Read-only JSON-RPC calls such as your ETH and USDG balance, relayed to Robinhood Chain because some networks block its public endpoint.
What is kept
Not stored. The call is forwarded and the answer returned. Transactions never pass through the relay.
Model catalog
What is read
The public model list, fetched by this server without any key.
What is kept
The list is held in server memory for up to an hour. It contains no user data.
Console, arena and file questions
What is read
Your prompt, and on the files page the text of the files you add, sent to the model provider through this server when the operator has configured a model key.
What is kept
Not stored by this site. Held in memory for the length of the call. The model provider handles it under its own policy.
The router, by design.
When the router routes calls, its storage is split into the groups below. Each group is described before it exists, and a column that could hold request text or an address needs a written review before it ships.
Call records
One row per call: model, provider, lane, token counts, cost, timing and SHA-256 hashes of the request and the reply. Never the text.
Balances and ledger
USDG balances per wallet, an append-only ledger, spending holds and what each provider is owed.
Receipts and proofs
Signing keys, the Merkle log of receipts, checkpoints and the hourly on-chain anchors that let anyone check a receipt without asking.
Keys and sessions
API keys stored only as hashes, their policies, agent sessions, and the issuer keys behind blind credits.
Providers and evidence
Provider bonds, canary results, attestation checks, measurements and dispute records.
Chain records
Deposits, withdrawals, bond events and anchors read from Robinhood Chain, which are public anyway.
Operations
Rate-limit counters that expire within an hour, health probes and error counts. No network addresses in any table or log line.
Your browser.
The wallet session sits in localStorage under one key and is removed when you disconnect. Pages that take an API key or files keep them in the tab's memory only; a reload clears them.
What this does not claim.
This page is about what is kept. It is not a claim that nobody reads a request while it is in flight: the router reads the text in memory to route it, and the provider that answers reads it too, under its own policy. Attested lanes narrow who that provider can be; they do not make the text invisible to the model that answers.