> ## Documentation Index
> Fetch the complete documentation index at: https://docs.fortytwo.network/llms.txt
> Use this file to discover all available pages before exploring further.

# Data handling

> Zero data retention, no training on customer content, prompt caching, where inference runs and how long records are kept.

## Zero data retention

Zero data retention is the default for this API. Prompts, outputs and request-specific intermediate content are not stored.

* This includes traces that contain content, reconstructed prompts and embeddings of your content.
* Fortytwo does not call tools and does not store tool definitions, arguments or results.
* `store: true` is rejected with `400 zdr_storage_not_supported`.

## No training on customer content

Customer content is not used to train models by default. This applies to every model that serves the request: swarm, draft, decoder, ranking and reward models, and models used for inference upsampling.

A content-sharing programme requires a separate express opt-in. Before the opt-in, the programme states what is covered, the purpose, the period, who has access and how to withdraw. Accepting the Terms or a cookie banner is not an opt-in.

## Abuse checks

Automated safety and abuse checks can run on requests while they are processed. If a check flags a request as a probable serious violation of [Terms of Service, section 4](/legal/terms-of-service#4-acceptable-use), the flagged content and related identifiers can be kept for up to 30 days. They are used only to investigate, to enforce the Terms or to meet a legal duty, and only designated staff can access them. A documented investigation, dispute or legal requirement can extend the period. Flagged content is never used for training. This is the only content kept without the customer's choice.

## Prompt caching

A prefix of the prompt can be served from a short-lived cache. This sets the cached-input price — see [Pricing](/docs/pricing).

| | |
| - | - |
| Storage | Memory only. Never written to disk, backups or logs. Never used for training |
| Lifetime | Up to 15 minutes after the last request that used the entry. Each reuse restarts the 15 minutes |
| Earlier deletion | When memory is needed, or when the serving process restarts |
| Scope | One conversation, for the same account, API key and model. Never shared across accounts, keys or models, and never returned as content |
| Routers | Requests through a router are cached under the router's account and key |
| Control | Automatic. It cannot be turned off |

A cache miss is charged at the full input price and gives the same result. `usage.prompt_tokens_details.cached_tokens` shows how many prompt tokens came from the cache. See [Privacy Policy, section 3](/legal/privacy-policy#3-prompt-caching).

## Where inference runs

Inference runs on Fortytwo-controlled infrastructure in the **United States**. Requests are not routed to independent public node operators. The [provider register](/legal/providers) lists every provider that processes data for Fortytwo — see [Privacy Policy, sections 7 and 8](/legal/privacy-policy#7-who-receives-information).

## Retention

| Data | Kept |
| - | - |
| Inference content | Not kept beyond the prompt cache: 15 minutes after last use |
| Content flagged by abuse checks | Up to 30 days, or longer for a documented investigation, dispute or legal requirement |
| Request and usage records, without content | 12 months |
| Security records | 90 days. IP addresses removed after 30 days where no longer needed for security |
| Account data | Deleted within 30 days of account closure |
| Payment, invoice and tax records | At least 5 years |
| Support correspondence | 24 months after the matter closes |
| Backups | Expire within 35 days of deletion from active systems |

See [Privacy Policy, section 9](/legal/privacy-policy#9-retention-and-deletion).

## Data not to send

Fortytwo is not PCI-DSS certified and does not offer a HIPAA business associate agreement. Do not send protected health information.

Do not send card security codes, secrets for other systems, classified information, or other data with special regulatory requirements, unless Fortytwo has expressly agreed to that processing and the API supports it — see [Terms of Service, section 4](/legal/terms-of-service#4-acceptable-use).

## Data Processing Addendum

A Data Processing Addendum is available from [legal@fortytwo.network](mailto:legal@fortytwo.network). It applies automatically to Business Customers once published.

If this page conflicts with the [Terms of Service](/legal/terms-of-service), the Terms prevail.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.