Data processing.
How Smouter handles prompts, completions, and metadata in production.
1. Roles
When customers send traffic through the gateway, Smouter acts as a processor on behalf of the customer (controller). Upstream model providers — selected by your routing configuration — act as sub-processors.
2. Categories of data
- Prompts and completions. Forwarded to the chosen provider to fulfill the request. Held only as long as needed to serve the response and (where enabled) to satisfy a cache hit on a later identical request.
- Usage metadata. Model name, token counts, latency, routing decision, customer key. Retained for billing, savings reporting, and abuse detection.
- Account data. Email, organization name, and billing details for the account holder.
3. Retention
- Prompt/response bodies: short-lived by default — sufficient to serve the request and a configurable cache window. Customers can disable caching per-key or per-request.
- Usage metadata: retained for the life of the account plus a standard tail for tax and audit purposes.
- Account data: retained while the account is active, then deleted on request.
4. Sub-processors
The current shortlist (subject to change as the gateway opens up):
- Model providers — OpenAI, Anthropic, Google, and others as added. Each call routes to exactly one provider.
- Hosting & CDN — Vercel.
- Payments — to be confirmed before the first paid invoice; we will publish the choice here.
5. International transfers
Requests are routed to the upstream provider's region of choice. Where applicable, standard contractual clauses will govern transfers out of the EEA / UK. The full agreement will be available before the gateway opens to paid customers.
6. Contact
For a DPA, sub-processor list, or anything else, privacy@smouter.ai.