Privacy Policy

CostPlusIQ, a product of Ensoul Inc · Effective 2026-09-30

CostPlusIQ, a product of Ensoul Inc. This policy says what we keep and what we do not. Retention is set per API key: every key is created as standard (the default) or ZDR, and the key that authorizes a request determines how its content is handled. On top of that we keep the metadata needed to run the service and bill for it.

Standard keys (the default): you allow training

A standard-tier key — the tier pre-selected at key creation, offered in exchange for the lower standard rates listed on the pricing page — grants us a licence to retain and use the content of requests sent with it: prompts, uploaded or referenced media, and the model’s completions are written to our internal training and evaluation stores, attributed to your account email and the key id. Metadata handling is otherwise as below. Delete the key to stop granting the licence for future requests; ask privacy@ensoul.inc to remove previously retained content.

Before 2026-08-23 ZDR was the default. The tier is fixed when a key is minted, so keys created before that date are still ZDR and this change does not reach back to them, nor to content already served under a ZDR key.

ZDR keys: zero retention

Choose ZDR at key creation and request content — your prompts, uploaded or referenced media, and the model’s completions — is processed in memory only. It is never written to disk or a database, never used to train or fine-tune any model, and never shared. The inference servers run with request and output logging disabled, and the access logs record paths and status codes, never query strings or bodies. When your response finishes, the content is gone. ZDR keys bill at the full published rates.

What we do keep

datawhyhow long
Per-request metering: API key id, account email, model, timestamp, duration, HTTP status, serving host, and token counts Accurate billing, and evidence for a billing dispute 7 years, as billing records
Standard-tier request content only: prompts, media, and model completions, attributed to the key id and account email Training, evaluating and improving our models — the licence a standard key grants Until you ask us to delete it
Monthly totals derived from the above Tax and accounting obligations 7 years
Account: email address, name, Google account identifier, a one-way hash of your password if you set one (never the password itself), and metadata about the keys you create (never a key itself — we store only a SHA-256 hash) Sign-in and key management Life of the account, plus 30 days
Website and console request logs: route, status, duration, and the signed-in email Operating the site — the console, not the inference path 90 days
Cloudflare edge logs for this domain DDoS protection and TLS; retained by Cloudflare under their terms, not ours Per Cloudflare

Where inference happens

Model inference runs in us-central1 (US), uk-south1 (GB), eu-north1 (FI), us-marketplace (US), us-denver (US), ca-marketplace (CA), gb-marketplace (GB), de-marketplace (DE), fr-marketplace (FR), nl-marketplace (NL), fi-marketplace (FI), cz-marketplace (CZ), bg-marketplace (BG), au-marketplace (AU), jp-marketplace (JP), and each model’s document entry names the region serving it. Your request content touches only the machines serving your request, and none of them writes it down.

Cookies

Three, all strictly necessary, all first-party: cpiq_session (your signed sign-in session), cpiq_oauth_state (CSRF protection during Google sign-in) and cpiq_email_link (ties an emailed confirmation link to the browser that opened it, for 15 minutes). No analytics, no advertising. The one third-party script is Cloudflare Turnstile on the console’s email sign-in form, which checks that a person, not a bot, is asking us to send mail.

Subprocessors

whowhat for
CloudflareDNS, TLS termination, the edge that serves this site, object storage (R2) for retained standard-tier content, delivery of sign-in and account emails, and the Turnstile bot check on the email sign-in form
Googlesign-in (OAuth); we receive your email address and name
NebiusGPU compute, in the regions the model document lists
Vast.aiGPU compute on marketplace hosts operated by independent providers, in the countries the model document lists
SailGPU compute on nodes reserved for us in the datacenter the model document lists
Stripecard payments for prepaid credits
Mercurybanking and invoicing for customers who pay by transfer

ZDR request content is never ours to give, so none of them can receive it. The one exception is standard-tier content, which is stored encrypted in Cloudflare R2 under the licence that tier grants.

Your rights

You can see your account data, balance and usage records in the console, and you can ask us to delete your account and its records at any time, subject to the accounting records we are required to keep. We do not sell personal data, and we process it only to provide the service you asked for. Requests and questions: privacy@ensoul.inc.

CostPlusIQ, a product of Ensoul Inc · Home · API documentation · Terms · Privacy · Refunds