Privacy
What changed on 4 September
Three corrections in a single day: a zero-retention claim measured against the router that actually runs, the ten percent fee on top-ups removed, and a promise we could not keep withdrawn everywhere it had been made.
The zero-retention flag now says what it means
The processing register is the machine-readable list of everyone who touches your data: which company, in which country, on which legal basis, and whether the route to them is configured to retain nothing. It listed fourteen inference recipients with zero data retention set to true.
Measured against the running service, the number is one. decide() in
server/retention-core.js returns enforced only for the OpenRouter pool
route. Every other pool, and every request using your own API key, returns none.
The same claim had been withdrawn from six documents earlier that day. The register kept it
because the register is JSON. A search for the sentence found sentences. It did not find a field
called zdr set to true in a data file. A claim is not necessarily a string,
and not necessarily text.
The register now states what the flag describes, which is what our routing enforces rather than what a provider offers under its own terms, and it names the function the value comes from. An unverifiable true is worse in a register than a wrong one, because nobody can tell which it is.
No recipient, purpose, data category or safeguard changed. This narrows an assurance that was too broad and adds none. Full text in the privacy policy.
A promise we could not keep, withdrawn in seven places
Zero data retention means the provider that answers your prompt keeps nothing afterwards. ZeroLog enforces it on exactly one route: requests through the OpenRouter pool. The site said otherwise in seven places.
Searching for the phrase found two of them. The others said it in different words, such as "pinned to providers that retain nothing", and one said it in a JSON file with no prose at all. The seven were the plain-language summary in the privacy policy, a later paragraph of §5 that contradicted the correction six paragraphs above it, the vault section of the documentation, the feature list on the signup page, the German translations of two of those, and the processing register.
The English signup page had been corrected earlier the same day and the German had not. For part of that day a German-speaking visitor was reading an assurance an English-speaking one was not.
applyRetention() sets the retention field only when a chat carries credentials from
the secrets vault, and the field it sets is the router's own. For any other provider it does
nothing. All seven places now say that.
The terms are unchanged, so we ask for no re-acceptance. The privacy policy moves to v1.3 at /legal.
The 10% fee on top-ups is gone
Topping up your credit used to carry a 10 % service fee on top of the amount. It does not any more. The setting it was read from is zero, so this takes effect on your next quote rather than on an announced date.
The 3 % currency buffer stays, and §7.2 now says what it is for. It covers the exchange rate moving between the moment you are quoted a price and the moment the payment arrives. Dropping it too would mean selling credit below cost whenever the rate jumps. It is not a margin, and the clause no longer leaves that to inference.
The 2 % margin on inference is unchanged. That is the business model, disclosed in the same clause as before.
This change is in your favour and still material, so the terms move from 1.1 to 1.2. Under §12.2 that means notice and continued use. Nothing re-gates an account that already exists. The clause is §7.2 of the terms.