Skip to content
Subset

Legal

Unreviewed draft

Hosted AI credits — data handling

What a hosted generation request sends, what is retained afterwards — nothing beyond the request — and which subprocessors touch it on the way.

Last changed . This is a draft, so that date says when the wording moved, not when anything came into force.

Why this page exists before the software

The AI Content Builder’s Pro feature can work two ways: with your own API key, or with credits hosted by us. The bring-your-own-key path sends your content to a provider you chose and have your own agreement with. The hosted path sends it to a provider we chose, through a proxy we run.

The second one needs explaining before anybody uses it, not after. A publishing plugin that quietly posts page content to an unnamed third party is the thing we would complain about in somebody else’s product. So the data-handling design is published now, while it is still cheap to argue with, and the implementation in #28 has to match it.

What is sent

When you use a hosted generation feature, the plugin sends to our proxy:

  • your licence key and the activated site URL, to authenticate the request and check the licence has credits;
  • the prompt and the content you are generating from — whatever the feature you invoked needs: an outline, a draft, a block of existing text, the field you are asking it to fill;
  • the model parameters the feature uses, and nothing you did not give it.

The proxy forwards the prompt and content to [AI provider] — blank; to be supplied by the business, receives the response, and streams it back to your site. It does not add your email address, your account id, your other sites, your WordPress user list or anything else about you to what the provider receives.

What is retained

Nothing beyond the request.

That is the design, and it is the sentence the implementation has to be measured against. Specifically, once a hosted generation request has been answered:

  • the prompt is not stored;
  • the content you sent is not stored;
  • the generated output is not stored;
  • none of the three is written to a log, an error report, a trace or an analytics event.

They exist in the proxy’s memory for the duration of the call and are gone when it returns. There is no transcript, no history feature, and no way for us to show you what you generated last week — because there is nothing to show you. If a history feature is ever wanted, it is a new decision with a new version of this page, not a thing that quietly became true.

What is kept

The metering has to be durable, so this part is:

KeptWhy
Which licence made a request, and whenMetering credits, and per-licence rate limits
How many credits it costThe credit ledger your dashboard shows
Whether it succeeded, and the error class if notTelling you why something failed, and finding our bugs

None of those rows contains your content. “Request 41 on this licence cost nine credits and failed on a provider timeout” is the whole of what a retained record says.

A credit reservation is taken before the provider is called and settled against the actual cost afterwards, so a failed request does not charge you for output you never got.

Subprocessors on this path

SubprocessorRoleSees your content
[AI provider] — blank; to be supplied by the businessGenerates the outputYes, while the request runs
VercelHosts the proxy; request metadata and transportNo
SupabaseHolds the credit ledger and licence recordsNo

The provider is the row that matters, and it is blank for a reason: FLX-14 has not chosen one, and the choice carries two commitments we are not willing to make vaguely — that the provider does not train on data submitted through an API, and that it retains submissions for no longer than the abuse-monitoring window its own terms describe. Those commitments go in this table, by name, with a link to the provider’s own terms, before the feature ships.

Account data rests in [data region] — blank; to be supplied by the business. A generation request will be processed wherever the chosen provider processes it, which may be another region; that is a transfer, and naming it properly is part of the same review.

Bring your own key

Supplying your own provider API key is free, stays free, and keeps your content out of our infrastructure entirely: the plugin calls the provider directly and our proxy is not involved. There are no credits, no metering and no record here of what you generated.

It is in the product for two reasons. It is the right answer for anyone with a procurement process or a data-processing agreement of their own, and it keeps us honest about what the hosted path is actually charging for — convenience and a bill we absorb, not access to a model.

What you can ask for

Because nothing about a request’s content is retained, there is no copy of it to send you, correct or delete. What we hold and can act on is the metering above and your account record; the privacy policy covers both, and requests go to [address for privacy requests] — blank; to be supplied by the business.

If a provider holds a submission under its own abuse-monitoring retention, that is the provider’s record rather than ours, and this page will link to their process for it once there is a provider to link to.

When this page becomes true

The checklist for #28, in effect. All of it has to hold before a hosted credit can be spent:

  1. A provider is chosen, named here, and its no-training and retention terms are linked.
  2. The proxy stores and logs no request content, and a test proves it rather than a comment claiming it.
  3. Out-of-credits is answered before any provider call, so a request that cannot be paid for is never sent anywhere.
  4. The data region and any transfer out of it are stated above.
  5. A lawyer has read this page, and the draft banner is gone.