Prompt logging & retention
What ToyGate retains from your chat requests, for how long, and how to opt out.
Legal
ToyGate can retain a redacted copy of your prompt messages and, for non-streaming requests, the model response for a bounded window. This page documents what we keep, why, and how to disable future prompt logging.
What we keep
For every /v1/chat/completions request you send, we may write one row to an internal prompt_logs table containing:
- Messages — the exact
messagesarray as you sent it, with secrets redacted (Bearer tokens,sk-…,gw_…, JWT-shaped tokens are replaced with[REDACTED]; image content parts collapse to[redacted-image]— the raw bytes are never persisted). - Response — the OpenAI-shape body returned for a non-streaming request. Response bodies are omitted for every streaming request, including successful streams.
- Metadata — the request id, the owning user, and an
expires_attimestamp.
We do not keep:
- Your API key. The
gw_secret is verified against the auth store and never lands inprompt_logs. - Raw image bytes or base64 payloads. Vision requests are logged with a placeholder.
- Bodies from anonymous / catalog paths. Only authenticated
/v1/chat/completionstraffic is logged.
How long we keep it
- Retention: 7 days. Rows are hard-deleted by the maintenance sweep every 15 minutes once
expires_atis in the past. - Storage: in the same Postgres cluster as your account. Not shared with any third party. Not used for training.
- Access: restricted to authenticated user/operator surfaces. Operator deletion is audited to
admin_audit_log; this documentation does not claim an audit entry for reads.
Why we keep it
Three goals of prompt logging:
- Debugging — when you report a broken response, we can reproduce it from your exact messages instead of asking you to re-share them.
- Abuse triage — spotting keys that are being misused faster than a purely-metric view allows.
- Billing forensics — verifying AI credits debited against tokens the upstream actually processed, in case of a dispute.
How to opt out
Three paths:
- Self-service account toggle. Open your profile's privacy settings and disable prompt logging. The profile sends
promptLoggingEnabled: false; new requests then skipprompt_logs. Rows already written stay in the 7-day window until they expire or are deleted. - Right to erasure per row. An operator can delete a specific
prompt_logsrow by id via the admin console. The deletion is audited but the payload is gone. - Account data erasure. You can request erasure of your account data from the dashboard. While the request is processed your account is blocked and its sessions and API keys are revoked. Completion deletes every
prompt_logsrow belonging to the account along with generation jobs and generated media, and anonymizes API request-log rows. See the Privacy Policy for the full erasure scope.
Legal basis
- Consent is captured at sign-up as part of the Terms of Service — you're granted access on the understanding that requests are retained for 7 days for the reasons above.
- Retention is bounded at the platform level (not per-request); we can't extend a specific row's TTL without a global policy change.
- No profiling, no automated decision-making, no data sharing. This retention buffer exists purely for operator forensics on a self-hosted single-tenant deploy.
If your compliance posture requires stricter guarantees (zero retention, HIPAA-style audit control, on-prem key management), talk to support before you route production traffic through the gateway.