Privacy policy
Effective: August 21, 2026
This page explains what Vynaris collects about you, why, and what we do — and don't do — with it. We built Vynaris on "radical cost transparency," and we want this policy to be just as plain.
The short version
- Chat stores its messages and conversation memory so you can return to a session. Deleting a chat deletes that content.
- Metadata-only keys store request details such as model, tokens, cost, and latency. Keys with transcript capture also store the full request and response for debugging.
- Vynaris-hosted reduced-refusal model IDs never persist prompt or output bodies, even if transcript capture is enabled on the key.
- Your prompts and completions pass through to the model provider that serves the request.
- We do not train on your content. Some providers may retain or use it only when you enable that option for a key.
- Payments, including supported stablecoins, go through our payment partner — we never see your card number or wallet private keys.
What we collect
- Account info: your email address, and an identifier from your auth provider if you sign up with GitHub or Google.
- Chat content: messages, model responses, and compact conversation memory for sessions you create in the app.
- Request metadata: which model you used, token counts, cost, latency, timestamp, and the prefix of the API key used (not the full key).
- Website analytics and attribution: pages visited, referral and campaign parameters, an X ad click identifier when present, and your Vynaris account ID and email after sign-in.
- IP address, kept for security and abuse prevention (for example, detecting fraudulent access or disruptive traffic).
- Billing records: plan, subscription status and dates, payment and invoice identifiers, credited amount, charged currency, settlement amount, and provider fees when supplied to us.
Prompt and completion content
For the model IDs listed on our hosted reduced-refusal model pages, Vynaris does not persist prompt or response bodies. This rule overrides the API key's transcript capture setting. Content is processed in memory by the private inference service and discarded after the response. Infrastructure subprocessors necessarily handle the content in order to run inference, but they are not presented to you as separate model providers.
We retain non-content metadata for those requests: account and key identifiers, selected model, token counts, price, timestamp, latency, request status, request ID, and security signals such as IP address. This supports prepaid billing, reliability, fraud and abuse response, and compliance with valid legal process.
When you send a request through Vynaris, the prompt and the model's response pass through to the third-party inference provider that serves it. Those providers have their own privacy policies governing how they handle that content, and we'd encourage you to review them if you're sending sensitive data.
Each API key starts with metadata-only routing. This excludes deployments we have marked as potentially retaining or using prompt and completion content. You can enable more providers for an individual key to unlock more models and potentially lower prices. The provider's own terms then govern its use of that content, including any product-improvement or model-training use it permits. This setting does not currently constrain processing region, so don't send content that must not cross regional boundaries.
In Vynaris Chat, we store messages, responses, and compact conversation memory until you delete the chat or your account. Chat uses deployments marked as restricted from provider data collection. Billing and audit metadata may remain where legally required.
Except for Vynaris-hosted reduced-refusal model IDs, keys with transcript capture enabled store the complete request and response payload—including messages, system prompts, tool definitions and calls, generation parameters, streamed response chunks, provider errors, and routing metadata. We use this content for dashboard debugging, quality-refund review, evaluation, and improving the routing system. Turning the option off stops future transcript capture. Previously captured transcripts remain until the account is deleted or you ask us to delete them.
For these opted-in keys, we may also send request content to routing-evaluation services solely to compare model-selection recommendations. We currently use Not Diamond for this purpose. Its recommendation does not replace the model Vynaris serves unless we explicitly announce a future routing change.
Vynaris does not train models on your prompt or completion content. A third-party provider may do so only for keys where you explicitly allow provider data collection.
Advertising and analytics
- We don't sell your personal data.
- We don't run third-party ads on Vynaris.
- We use Mixpanel to understand product and website usage, and X conversion measurement to evaluate our own ads. A first-party analytics and attribution cookie can span vynaris.com and app.vynaris.com for up to 90 days.
- When our payment partner confirms a payment, our X conversion measurement may send X the ad click identifier, credited USD amount, and a one-way hash of the account email. We never use the unverified checkout-return page as payment confirmation.
Payments
Payments are handled by our payment partner, which acts as merchant of record. Card details and stablecoin wallet interactions go directly to them — we never see or store your card number or wallet private keys.
For plans, we store the customer, subscription, checkout, and payment identifiers needed to add credit once, show billing state, reconcile missed events, and let you manage renewal. Subscription status never authorizes API usage; your ledger balance does.
Emails
We send transactional email only: email verification, payment receipts, and low-balance warnings. Where the law allows it, you can unsubscribe from non-essential notices; we'll still need to send you account-critical messages like receipts.
Data retention and deletion
We keep metadata-only request logs for billing accuracy and audit purposes. Chat content remains until you delete the chat or your account. For keys with transcript capture enabled, we also keep captured transcripts until the account is deleted or you ask us to delete them. Turning the option off stops future capture but does not erase existing transcripts. You can ask us to delete your account and associated data by emailing us — we'll do so promptly, except where we're required to retain billing records for legal or accounting reasons.
Hosted reduced-refusal prompts and outputs are not available for later export, disclosure, or recovery because they are not persisted. We may preserve and disclose account, billing, security, and request metadata when required by valid legal process.
Security
We encrypt data in transit and store API keys hashed, not in plain text. No system is perfectly secure, and we don't claim any particular certification — but we take reasonable, standard precautions to protect your data.
Exporting your data
You can export your request history and account data as a CSV from your dashboard at any time.
Regional privacy rights
Depending on where you live, you may have rights over your personal data, such as access, correction, or deletion. Email us at hello@vynaris.com and we'll do our best to honor requests that apply to you.
Where your data is processed
Vynaris's servers are located in the United States, and that's where your account and request metadata are processed and stored. Opted-in transcripts are stored there too. When you route a request to a model provider, your prompt is also processed wherever that provider operates. If you're outside the US, your data will cross borders to reach our servers and the upstream providers.
Contact
Questions about this policy, or a request about your data? Email hello@vynaris.com.