Where your data goes — TitanEnsemble data & privacy

The product premise is BYOK: parts of your application think through us, on your provider credentials. This page answers a security review's first question — where does our data go — from the product, not from theory.

What leaves the platform

  • Your prompts and attached context go to the provider you selected — and nowhere else. Every request names a model; the model resolves to your provider credential for that seat. We never substitute our own upstream credential for yours (house keys never enter customer traffic, by construction — the BYOK dispatch adapter carries no house auth).
  • The exception is AgentT, the hosted trial seat: those requests run on our own GPUs and reach no third-party provider at all.
  • Per-provider records make this answerable: usage rows are attributed per key and per provider host, so "what did we send to Novita last month" is a query, not an estimate.
  • Nothing else leaves: memories, knowledge sets, briefings, threads, and usage records stay on the platform.

What we keep, and for how long

  • Threads: web conversations persist until you delete them (a real delete). Key-threads keep a working window (recent turns); older spans are folded into a summary and the raw turns deleted on a daily cycle — durable facts survive as memories and knowledge, not as transcript.
  • Memories / learned knowledge: kept until you delete or reset them — per-key controls exist (list, delete one, reset the mind, export).
  • Knowledge sets & briefings: kept until you delete them.
  • Provider credentials: stored in the secret vault; values are write-only (never readable back through any API) and deleted on your instruction.
  • Audit records: append-only, retained to the compliance floor that applies to your tenant's regime — deletion requests cannot shorten a regulatory retention floor, and we say so rather than pretending otherwise.

Export everything

GET /v1/user/export returns your threads (with messages), memories and learned knowledge (public vocabulary), knowledge sets (with document text), briefings, and per-key model configs, as one JSON document. Per-key export: GET /v1/auth/keys/{key_id}/export.