Where your data goes — TitanEnsemble data & privacy
The product premise is BYOK: parts of your application think through us, on your provider credentials. This page answers a security review's first question — where does our data go — from the product, not from theory.
What leaves the platform
- Your prompts and attached context go to the provider you selected — and nowhere else. Every request names a model; the model resolves to your provider credential for that seat. We never substitute our own upstream credential for yours (house keys never enter customer traffic, by construction — the BYOK dispatch adapter carries no house auth).
- The exception is AgentT, the hosted trial seat: those requests run on our own GPUs and reach no third-party provider at all.
- Per-provider records make this answerable: usage rows are attributed per key and per provider host, so "what did we send to Novita last month" is a query, not an estimate.
- Nothing else leaves: memories, knowledge sets, briefings, threads, and usage records stay on the platform.
What we keep, and for how long
- Threads: web conversations persist until you delete them (a real delete). Key-threads keep a working window (recent turns); older spans are folded into a summary and the raw turns deleted on a daily cycle — durable facts survive as memories and knowledge, not as transcript.
- Memories / learned knowledge: kept until you delete or reset them — per-key controls exist (list, delete one, reset the mind, export).
- Knowledge sets & briefings: kept until you delete them.
- Provider credentials: stored in the secret vault; values are write-only (never readable back through any API) and deleted on your instruction.
- Audit records: append-only, retained to the compliance floor that applies to your tenant's regime — deletion requests cannot shorten a regulatory retention floor, and we say so rather than pretending otherwise.
Export everything
GET /v1/user/export returns your threads (with messages), memories and
learned knowledge (public vocabulary), knowledge sets (with document text),
briefings, and per-key model configs, as one JSON document. Per-key export:
GET /v1/auth/keys/{key_id}/export.