> ## Documentation Index
> Fetch the complete documentation index at: https://docs.fortytwo.network/llms.txt
> Use this file to discover all available pages before exploring further.

# Privacy Policy

**Effective date:** 16 September 2026

## 1 Scope and who is responsible

This Policy explains how Fortytwo MENA Limited, incorporated in Abu Dhabi Global Market, Abu Dhabi, United Arab Emirates, with registration number 36387 and registered address DD-14-117-013, Floor 14, Al Khatem Tower, WeWork Hub71, ADGM Square, Al Maryah Island, Abu Dhabi, United Arab Emirates ("Fortytwo", "we", "us") handles personal data in connection with the Fortytwo API, its developer console, playground, related account and payment functions, and support (the "Services"). It also explains our handling of requests that reach Fortytwo through OpenRouter or other aggregators, marketplaces, routers, or third-party applications ("Routers").

Personal data is information that identifies a person or can reasonably be linked to them. It may appear in account records, usage metadata, prompts, or generated responses. This Policy concerns these API Services; it does not describe a public node-operator programme, token activity, or a separate product with its own privacy notice.

Fortytwo is the controller of personal data where we determine the purposes and means of its processing, including direct account administration, payments, service security, and our communications. This Policy also applies to content processing for which we act as controller, including where applicable when we provide a direct personal-use service.

When we process personal data in customer content solely on behalf of a Business Customer or Router under its instructions, we act as a processor, subprocessor, or equivalent service provider under the applicable agreement. That customer's or Router's privacy notice explains its own collection and use, and the relevant data processing agreement governs our processing on its behalf. Our role depends on the actual processing, not simply on whether a customer is an individual or has paid through a Router.

Our privacy contact is [legal@fortytwo.network](mailto:legal@fortytwo.network). Our postal address is above. We are subject to the ADGM Data Protection Regulations 2021 and other privacy laws that apply to our activities.

## 2 Default handling of inference content

In short: we do not store your prompts or outputs, we do not use them to train models, no one at Fortytwo reads them in the ordinary course of operating the service, and we do not use them for advertising. Inference runs on infrastructure we control, and our hosting providers are contractually prohibited from accessing, retaining, or using your content for any purpose other than operating that infrastructure. The rest of this Section explains the exceptions and how caching works.

"Input" includes prompts, messages, uploaded material, code, and tool results sent with a request. "Output" is the response returned by the Services. Our content protections also cover request-specific intermediate material, including candidate answers, rankings, and content-bearing caches produced by inference upsampling, swarm inference, swarm decoding, and related processing (together, "Customer Content").

By default, we process Customer Content to answer the request without storing prompts, outputs, or intermediate content in persistent logs, databases, or archives. We do not retain a prompt history for later human review and do not use Customer Content to train or improve models by default. Temporary prompt caching is described in Section 3. We retain account, billing, and content-free operational records separately, as explained below. Zero data retention does not mean that no personal data of any kind is processed or retained.

Inference runs on Fortytwo-controlled infrastructure. It does not involve sending launch API requests to independent public swarm node operators. Hosting a third-party open-weight model does not by itself give the model's developer access to your prompts or outputs. Our contracted infrastructure providers and personnel may have the access necessary to operate the service, subject to access restrictions and confidentiality obligations.

The same Fortytwo default applies to requests we receive through Routers. The Router may separately process or retain content before sending it to us or after receiving the result. Its own practices, settings, and agreements govern that processing. A Fortytwo privacy commitment describes the part of the request handled by Fortytwo and our appointed providers.

## 3 Prompt caching

Prompt caching lets us reuse computation associated with a repeated prompt prefix, reducing processing time and potentially qualifying input tokens for discounted pricing. The cache may contain representations derived from your content, such as key-value tensors, and related matching information. These representations are not treated as anonymous merely because they are not plain text.

Our default prompt cache is short-lived. Content-bearing cache entries are not written to backups or logs, and there is no persistent storage of cache content beyond the disclosed cache lifetime. We use caches only to serve inference; cache content is not added to a training dataset.

Cache entries are retained only for a short period and may be evicted earlier; the current maximum lifetime and expiry rules for each endpoint are stated in the endpoint documentation. Cache entries are used only to serve requests and are never returned as content to another customer; the isolation boundary applied to cache reuse, including how Router requests are separated, is described in the endpoint documentation. Where the endpoint documentation offers a control to disable caching, you can use it; otherwise caching is automatic.

These temporary caches are the disclosed caching component of our default zero data retention service. If we offer disk-based or other persistent caching, its separate setting will explain the storage, access, maximum retention, deletion, and controls before activation. It requires an affirmative selection or a valid instruction covering the affected requests. That configuration falls outside the default ZDR commitment, but the no-training default still applies. We do not silently fall back from ZDR processing to persistent caching. The same requirements apply to instructions received through a Router.

Cached-token pricing and cache-hit reporting are described in the applicable endpoint's pricing and documentation. For Router purchases, the Router sets the customer's price and treatment of cache discounts. Choosing persistent caching is separate from choosing to share data for model improvement.

## 4 Optional sharing and limited exceptions

We may offer a separate, voluntary programme through which you choose to share specified content with Fortytwo. Before you opt in, its notice will explain the data covered, whether the purposes include evaluation or model training, the retention period, who can access it, how to withdraw, and any discount or other benefit. No discount is promised by this Policy. Merely using the Services, accepting the Terms, or enabling ordinary prompt caching does not opt you into data sharing.

Our default restriction on training includes base models, Fortytwo swarm models, draft or decoder models, ranking or reward models, and models used for inference upsampling. Generating and ranking candidates to answer a current request is inference; retaining or reusing that material to improve a model across requests is a separate purpose that requires the disclosed opt-in and any other necessary legal basis.

An optional programme must explain what withdrawal does to previously shared datasets and completed training. We will honour applicable deletion and other privacy rights. We do not promise that withdrawing a choice will automatically reverse previously completed training. Sharing other people's personal data requires lawful authority; an account holder's opt-in is not automatically consent from everyone mentioned in a prompt.

For Router traffic, optional sharing applies only if a valid authorisation covering that traffic is communicated through an agreed mechanism and any necessary notices and choices have been provided. A preference on a separate Fortytwo account does not automatically change requests made through a Router.

If you choose to send prompt examples, screenshots, or other content in a support ticket, we process and retain that submitted material as support correspondence. This does not enable ongoing API content logging. We ask you to remove unnecessary personal data and secrets from support submissions.

We may preserve or disclose specific information where a binding legal obligation requires it. We limit this to the scope and duration required, restrict access, and notify the affected customer where lawful. We do not keep a general archive of prompts on the possibility of a future legal request. We may run automated safety and abuse checks on requests while they are processed. If a request is flagged as a probable serious violation of the Terms, we may retain only the flagged content and related identifiers for up to 30 days to investigate, enforce the Terms, or meet a legal duty, with access restricted to designated personnel. Flagged content is not used for training. This is the only security-related exception to our default content-retention commitments.

## 5 Other personal data we collect

We collect only the categories relevant to your use and the enabled features.

**Account and contact details.** These include your email, name if supplied, account and organisation identifiers, authorised users and roles, country, preferences, and records of accepting terms or making privacy choices. Credentials and API-key management records support authentication; we do not need your unrelated account passwords.

**Special categories of data.** We do not intentionally collect information revealing health, religion, political opinions, sexual orientation, or other special categories through account, payment, or usage records. Prompts you choose to submit may contain such information; under the default service we process it only to answer that request and do not retain it. Do not submit special-category data about other people unless you have the right to do so.

**Payment and purchase records.** For direct purchases, Stripe processes payment details. Payment card details are submitted to Stripe; Fortytwo receives transaction identifiers, status, billing information, and limited payment-method details rather than full card numbers or security codes. We also keep invoices, tax information where needed, purchases, credit balances, metered charges, and refunds. Stripe may act independently for some fraud prevention, compliance, and payment activities, as explained in its privacy notice at [https://stripe.com/privacy <Icon icon="arrow-up-right" />](https://stripe.com/privacy).

**Technical and usage records.** These may include IP address, device and browser information for the console, timestamps, account or Router identifiers, request identifiers, selected endpoint or model, token and cache-hit counts, charges, status codes, latency, and security events. These records exclude prompt text, response text, content-bearing traces, and reconstructed content under the default service. Identifiers, IP addresses, and linkable usage records may still be personal data.

**Communications.** We collect the contact details and content of messages you send us, including support requests, feedback, complaints, and privacy requests. If you provide an example containing Customer Content, the support treatment in Section 4 applies.

**Data supplied by others.** We may receive information from your organisation's administrator, a Router sending requests to us, a login provider you choose, Stripe, or providers helping us operate and secure the Services. The categories depend on that interaction. We do not ordinarily receive a Router user's payment card details or complete account profile merely because we serve an inference request, although content or identifiers included in the request may identify them.

Providing necessary account and payment details is required to create a direct account, purchase credits, or resolve certain support matters. If you do not provide them, we may be unable to provide that feature. Optional marketing or data-sharing choices are separate.

## 6 Purposes and legal bases

We use personal data to provide requested inference; create and secure accounts; authenticate requests; meter usage and manage credits; process payments and refunds; provide support; communicate service changes; investigate abuse; comply with legal duties; and establish or defend legal claims. Content-specific restrictions in Sections 2 to 4 continue to apply to all these purposes.

Under the ADGM Data Protection Regulations and, where applicable, EU, UK, or other privacy laws, we rely on the following legal bases as applicable:

* **Contract or steps requested before a contract:** information necessary to provide a direct individual customer's service, process their purchase, and respond to their requests.
* **Legitimate interests:** administering relationships with business and Router contacts, protecting accounts and infrastructure, preventing fraud, resolving disputes, and improving service reliability using operational information. We assess these interests against individuals' rights. A summary of that assessment is available on request. This basis does not override a content-use or consent commitment.
* **Legal obligations:** processing required by laws applicable to us, such as relevant tax, accounting, and legally binding disclosure requirements.
* **Consent:** optional communications, technologies, or sharing programmes where consent is required. You can withdraw consent without affecting processing lawfully carried out before withdrawal.

Where we act as a processor, we process personal data under the customer's or Router's documented instructions and applicable processing agreement, rather than assigning ourselves a separate purpose for customer content. We may use genuinely anonymised statistics for service planning and improvement. We do not attempt to identify people from those statistics or disclose confidential customer information. We carry out a data protection impact assessment where the ADGM Data Protection Regulations or other applicable law require one.

If we send product news or marketing, we obtain consent where required and provide an unsubscribe method. Opting out does not stop essential account, transaction, security, or legal notices.

## 7 Who receives information

**Providers acting for Fortytwo.** We use providers for hosting, infrastructure, security, payments, communications, support, and any enabled analytics or login functions. They receive the data needed for their work under applicable contractual safeguards. We maintain a register of these providers identifying each provider, its purpose, the relevant data, and processing countries; it is published on our website or available on request from [legal@fortytwo.network](mailto:legal@fortytwo.network). Stripe is our direct-payment provider.

**Your organisation or Router.** Organisation administrators receive information made available by their account permissions. A Router receives the results and usage information needed to provide the service it requested. We do not independently publish prompts to other users or make your content accessible to unrelated customers. Your own sharing or publication of outputs is under your control.

**Advisers and legal recipients.** We may disclose necessary information to professional advisers or public authorities to meet legal obligations, protect rights and safety, or resolve claims, subject to applicable law and the content restrictions above.

**Business transactions.** Information may be disclosed under appropriate confidentiality protections in connection with a genuine financing, reorganisation, merger, or sale, and transferred to a successor responsible for the relevant Services. This does not authorise the recipient to disregard existing data-use restrictions or applicable privacy rights.

**At your direction.** We may disclose information to an integration or recipient you specifically authorise, after explaining the relevant sharing. Third parties you choose may have their own privacy responsibilities. This does not remove our responsibility for providers we appoint to perform our own duties.

We do not sell personal data or share it for cross-context behavioural advertising, and we do not use API content for targeted advertising. If analytics or advertising tools would change this position, we will update disclosures and implement required choices before that processing begins.

## 8 Processing locations and international transfers

Our primary inference infrastructure is in the United States. We may add Fortytwo-controlled infrastructure in EU countries and the United Arab Emirates. Before those locations are used, we will identify the relevant countries and providers in the provider register and applicable endpoint documentation. Account, payment, and support data may follow a different processing path from inference content, and may be accessed by our personnel from the United Arab Emirates and other countries where they are located.

Using an endpoint does not by itself guarantee that all processing remains in a particular country. Where a service or agreement offers a specific residency commitment, it applies as described there. A Router's regional routing controls and our endpoint's processing region must both support any required regional arrangement.

Where a transfer of personal data requires legal safeguards, we implement the applicable mechanism before making the transfer. These may include an adequacy decision recognised under the relevant law, ADGM standard contractual clauses or the approved ADGM addendum, EU standard contractual clauses, and the applicable UK mechanism, with supplementary protections where necessary. Transfers outside ADGM and transfers subject to EU or UK law are assessed under their respective rules; a location elsewhere in the UAE is not automatically treated as within ADGM.

You may contact us for information about safeguards or a copy, with confidential information redacted where appropriate. Acceptance of this Policy is not consent to otherwise unlawful transfers. We do not claim that Fortytwo is certified under the EU-US Data Privacy Framework.

## 9 Retention and deletion

Our retention periods distinguish Customer Content from operational and business records.

* **Default inference content:** processed only for the request and the temporary prompt-cache lifetime stated in Section 3; no persistent prompt, output, or intermediate-content archive.
* **Default prompt-cache representations:** deleted on eviction or expiry under Section 3, subject to the disclosed maximum lifetime and refresh rules. Separately enabled persistent caches follow the retention and deletion rules disclosed before activation.
* **Content voluntarily shared under an opt-in:** the period and deletion treatment stated before that programme is enabled; no collection under that programme without the required choice.
* **Flagged content under Section 4:** up to 30 days after flagging, unless a documented investigation, dispute, or legal requirement justifies longer retention.
* **Account and access information:** while the account remains active, then deleted within 30 days after closure, except records needed for an identified continuing legal or security purpose.
* **Content-free request and security records:** 90 days, with IP addresses removed after 30 days where they are no longer needed for security, with longer preservation limited to a documented incident, dispute, or legal requirement.
* **Payment, invoice, and tax records:** the period required by applicable accounting and tax law, which is at least five years. Detailed technical logs are not retained for that entire period merely because invoices must be kept.
* **Support correspondence:** 24 months after the matter closes, unless a specific legal or dispute requirement justifies longer retention.
* **Consent, withdrawal, and objection records:** as needed to demonstrate and honour your choices and meet applicable legal duties; we minimise the information retained for this purpose.
* **Backups of retained account or business records:** expire within 35 days after deletion from active systems, subject to a lawful hold. Default inference content is not added to those backups.

When a retention purpose ends, we delete or genuinely anonymise the information. Any legal hold is limited in scope, access, and duration. Deletion requests may be subject to lawful exceptions, which we will explain where appropriate. Closing a direct Fortytwo account does not close a Router account or delete data independently held by that Router.

## 10 Security

We maintain technical and organisational measures appropriate to the data and risks, including encryption of data in transit, access restrictions and confidentiality obligations for personnel and providers, credential management for administrative systems, and incident response procedures. These measures apply across our controlled inference service and relevant providers. We give notices of personal data breaches as required by law and our processing agreements.

No service can guarantee absolute security. Protect API keys, limit permissions, avoid exposing credentials in client-side applications, and send only information necessary for your intended use. Contact [legal@fortytwo.network](mailto:legal@fortytwo.network) to report a suspected incident. Default zero retention reduces persistent content storage; it does not remove the need for lawful processing, access controls, or international transfer safeguards.

## 11 Cookies and similar technologies

The console and related web pages use cookies or similar local storage that are necessary for login, security, preferences, and recording privacy choices. We do not use advertising cookies. Any analytics tool we use is identified in the provider register described in Section 7, and we obtain consent for non-essential technologies where required before they are set.

We will obtain consent before using non-essential technologies where required, and offer a way to withdraw it. If an applicable law permits an exception, we will meet its conditions and offer required information and choices. Browser controls can also block or delete cookies, although necessary functions may stop working. A cookie preference does not by itself change server-to-server API content processing or opt you into model training.

We honour legally applicable opt-out preference signals, including Global Privacy Control where required. Older "Do Not Track" signals are distinct from those rights.

## 12 Your rights and choices

Depending on your location and applicable law, you may request access to personal data and information about its use; correction; deletion; a portable copy; restriction; objection to certain processing; withdrawal of consent; and opt-outs from sale, sharing, targeted advertising, or certain significant automated decisions. Some laws also provide a right to limit certain uses of sensitive data. Rights may be subject to lawful exceptions. We do not penalise you for exercising them.

Send a request to [legal@fortytwo.network](mailto:legal@fortytwo.network). Use the account email or provide enough information to locate the relevant records; do not send unnecessary identity documents or sensitive prompt content. Where the console offers it, you can also export or delete your account data directly. We may reasonably verify identity or an authorised agent's authority, using the least information appropriate. We respond within the period required by applicable law and explain any lawful extension or refusal. Where an appeal right applies, reply to the decision requesting a review.

If your request concerns content processed on behalf of a customer or Router, contact that organisation first. We will help it fulfil applicable requests under our processing agreement and will address information for which we are independently responsible. We cannot retrieve a prompt that was not retained under the default service.

You may complain to the ADGM Commissioner of Data Protection through the Office of Data Protection at [https://www.adgm.com/operating-in-adgm/office-of-data-protection <Icon icon="arrow-up-right" />](https://www.adgm.com/operating-in-adgm/office-of-data-protection), or another competent authority, such as your relevant EEA supervisory authority or the UK Information Commissioner's Office where applicable. You need not contact us first, although we welcome an opportunity to address concerns.

For residents covered by US state privacy laws, Sections 5 to 9 describe the categories of information, sources, purposes, recipient categories, and retention criteria. Relevant categories include identifiers, account and billing information, commercial records, internet or network activity, approximate location derived from IP addresses, business contact information, and information supplied in communications. Credentials can be sensitive information under some laws. We do not treat API content processed solely for a business as data available for our independent advertising purposes.

## 13 Automated processing and children

The Services use automated processing to generate requested outputs. Operational systems may also authenticate requests, enforce quotas, detect suspicious activity, or restrict access for security or payment reasons. Such restrictions are not final: you can contact us to have a person review an account restriction. A customer's use of outputs to make decisions is separately governed by its responsibilities and privacy disclosures.

Direct Fortytwo accounts are intended for adults aged 18 or older. We do not knowingly permit children to register directly. Contact us if you believe a child has created an account so we can investigate and take appropriate action. Children may be mentioned in material submitted by others; an adult-only account policy does not mean such data can never appear in API requests. Customers must have a lawful basis and any additional permissions required for that processing and comply with applicable restrictions.

## 14 Changes and contact

We will update this Policy when relevant practices change and revise its effective date. We keep previous versions and will provide them on request. We will give appropriate notice of material changes and obtain any consent or other authorisation required before new processing begins. Continuing to use the Services does not by itself provide consent where a separate choice is required.

Privacy questions and requests: [legal@fortytwo.network](mailto:legal@fortytwo.network).

Postal contact: Fortytwo MENA Limited, DD-14-117-013, Floor 14, Al Khatem Tower, WeWork Hub71, ADGM Square, Al Maryah Island, Abu Dhabi, United Arab Emirates.

For billing or privacy matters concerning a Router's own account or payment processing, contact that Router. You can still contact us about Fortytwo's handling of your information.
