CostPlusIQ, a product of Ensoul Inc. This policy says what we keep and what we do not. Retention is set per API key: every key is created as standard (the default) or ZDR, and the key that authorizes a request determines how its content is handled. On top of that we keep the metadata needed to run the service and bill for it.
A standard-tier key — the tier pre-selected at key creation, offered in exchange for the lower standard rates listed on the pricing page — grants us a licence to retain and use the content of requests sent with it: prompts, uploaded or referenced media, and the model’s completions are written to our internal training and evaluation stores, attributed to your account email and the key id. Metadata handling is otherwise as below. Delete the key to stop granting the licence for future requests; ask privacy@ensoul.inc to remove previously retained content.
Before 2026-08-23 ZDR was the default. The tier is fixed when a key is minted, so keys created before that date are still ZDR and this change does not reach back to them, nor to content already served under a ZDR key.
Choose ZDR at key creation and request content — your prompts, uploaded or referenced media, and the model’s completions — is processed in memory only. It is never written to disk or a database, never used to train or fine-tune any model, and never shared. The inference servers run with request and output logging disabled, and the access logs record paths and status codes, never query strings or bodies. When your response finishes, the content is gone. ZDR keys bill at the full published rates.
| data | why | how long |
|---|---|---|
| Per-request metering: API key id, account email, model, timestamp, duration, HTTP status, serving host, and token counts | Accurate billing, and evidence for a billing dispute | 7 years, as billing records |
| Standard-tier request content only: prompts, media, and model completions, attributed to the key id and account email | Training, evaluating and improving our models — the licence a standard key grants | Until you ask us to delete it |
| Monthly totals derived from the above | Tax and accounting obligations | 7 years |
| Account: email address, name, Google account identifier, a one-way hash of your password if you set one (never the password itself), and metadata about the keys you create (never a key itself — we store only a SHA-256 hash) | Sign-in and key management | Life of the account, plus 30 days |
| Website and console request logs: route, status, duration, and the signed-in email | Operating the site — the console, not the inference path | 90 days |
| Cloudflare edge logs for this domain | DDoS protection and TLS; retained by Cloudflare under their terms, not ours | Per Cloudflare |
Model inference runs in us-central1 (US), uk-south1 (GB), eu-north1 (FI), us-marketplace (US), us-denver (US), ca-marketplace (CA), gb-marketplace (GB), de-marketplace (DE), fr-marketplace (FR), nl-marketplace (NL), fi-marketplace (FI), cz-marketplace (CZ), bg-marketplace (BG), au-marketplace (AU), jp-marketplace (JP), and each model’s document entry names the region serving it. Your request content touches only the machines serving your request, and none of them writes it down.
Three, all strictly necessary, all first-party:
cpiq_session (your signed sign-in session),
cpiq_oauth_state (CSRF protection during Google sign-in) and
cpiq_email_link (ties an emailed confirmation link to the
browser that opened it, for 15 minutes). No analytics, no advertising. The one
third-party script is Cloudflare Turnstile on the console’s email
sign-in form, which checks that a person, not a bot, is asking us to send
mail.
| who | what for |
|---|---|
| Cloudflare | DNS, TLS termination, the edge that serves this site, object storage (R2) for retained standard-tier content, delivery of sign-in and account emails, and the Turnstile bot check on the email sign-in form |
| sign-in (OAuth); we receive your email address and name | |
| Nebius | GPU compute, in the regions the model document lists |
| Vast.ai | GPU compute on marketplace hosts operated by independent providers, in the countries the model document lists |
| Sail | GPU compute on nodes reserved for us in the datacenter the model document lists |
| Stripe | card payments for prepaid credits |
| Mercury | banking and invoicing for customers who pay by transfer |
ZDR request content is never ours to give, so none of them can receive it. The one exception is standard-tier content, which is stored encrypted in Cloudflare R2 under the licence that tier grants.
You can see your account data, balance and usage records in the console, and you can ask us to delete your account and its records at any time, subject to the accounting records we are required to keep. We do not sell personal data, and we process it only to provide the service you asked for. Requests and questions: privacy@ensoul.inc.