Prompt logging & retention

What ToyGate retains from your chat requests, for how long, and how to opt out.

Legal

ToyGate can retain a redacted copy of your prompt messages and, for non-streaming requests, the model response for a bounded window. This page documents what we keep, why, and how to disable future prompt logging.

What we keep

For every /v1/chat/completions request you send, we may write one row to an internal prompt_logs table containing:

  • Messages — the exact messages array as you sent it, with secrets redacted (Bearer tokens, sk-…, gw_…, JWT-shaped tokens are replaced with [REDACTED]; image content parts collapse to [redacted-image] — the raw bytes are never persisted).
  • Response — the OpenAI-shape body returned for a non-streaming request. Response bodies are omitted for every streaming request, including successful streams.
  • Metadata — the request id, the owning user, and an expires_at timestamp.

We do not keep:

  • Your API key. The gw_ secret is verified against the auth store and never lands in prompt_logs.
  • Raw image bytes or base64 payloads. Vision requests are logged with a placeholder.
  • Bodies from anonymous / catalog paths. Only authenticated /v1/chat/completions traffic is logged.

How long we keep it

  • Retention: 7 days. Rows are hard-deleted by the maintenance sweep every 15 minutes once expires_at is in the past.
  • Storage: in the same Postgres cluster as your account. Not shared with any third party. Not used for training.
  • Access: restricted to authenticated user/operator surfaces. Operator deletion is audited to admin_audit_log; this documentation does not claim an audit entry for reads.

Why we keep it

Three goals of prompt logging:

  1. Debugging — when you report a broken response, we can reproduce it from your exact messages instead of asking you to re-share them.
  2. Abuse triage — spotting keys that are being misused faster than a purely-metric view allows.
  3. Billing forensics — verifying AI credits debited against tokens the upstream actually processed, in case of a dispute.

How to opt out

Three paths:

  • Self-service account toggle. Open your profile's privacy settings and disable prompt logging. The profile sends promptLoggingEnabled: false; new requests then skip prompt_logs. Rows already written stay in the 7-day window until they expire or are deleted.
  • Right to erasure per row. An operator can delete a specific prompt_logs row by id via the admin console. The deletion is audited but the payload is gone.
  • Account data erasure. You can request erasure of your account data from the dashboard. While the request is processed your account is blocked and its sessions and API keys are revoked. Completion deletes every prompt_logs row belonging to the account along with generation jobs and generated media, and anonymizes API request-log rows. See the Privacy Policy for the full erasure scope.
  • Consent is captured at sign-up as part of the Terms of Service — you're granted access on the understanding that requests are retained for 7 days for the reasons above.
  • Retention is bounded at the platform level (not per-request); we can't extend a specific row's TTL without a global policy change.
  • No profiling, no automated decision-making, no data sharing. This retention buffer exists purely for operator forensics on a self-hosted single-tenant deploy.

If your compliance posture requires stricter guarantees (zero retention, HIPAA-style audit control, on-prem key management), talk to support before you route production traffic through the gateway.