Zero prompt retention by Lithune: prompt and completion content is processed in memory, is not written to Lithune's persistent storage and is never used for training.
Inference flow
Requests may reach Lithune through OpenRouter and Cloudflare. Once received by Lithune, the request is sent only to the model running on Lithune-owned hardware in Türkiye. Lithune does not forward prompt content to an external model API, cloud GPU or model-training provider.
Training policy
- Prompts and completions are not used to train, fine-tune, evaluate or adapt a model.
- Inference content is not intentionally written to a file, database or other persistent store.
- Model weights are not updated using user requests.
- Only limited operational metadata is retained as described below.
Retention schedule
| Data | Stored by Lithune? | Retention | Purpose |
|---|---|---|---|
| Prompt content and attachments | No persistent storage | In-memory processing only | Generate the requested response |
| Completion content | No persistent storage | In-memory processing only | Deliver the response |
| Per-request token counts and timestamp | Yes | Most recent 200 records across the service and no more than 30 days, whichever limit is reached first | Operations and troubleshooting |
| Aggregate request and token totals per API credential | Yes | Until the corresponding API-key record is manually deleted | Usage accounting and capacity planning |
| API credential used for the request | Yes | For the same period as the associated request record or aggregate | Associate usage with an authorised credential |
| Public website and API access logs | No | Disabled | — |
| Nginx technical error log | Only when errors occur | Daily rotation; up to 14 rotations normally retained | Failure diagnosis and security |
Infrastructure and other providers
- Inference: performed on privately owned Lithune hardware located in Türkiye.
- OpenRouter: may handle platform access, routing, account data and billing under its own policies.
- Cloudflare: may handle network delivery and security data under its own policies.
- External model providers: none are used after a request reaches Lithune's inference pipeline.
Security controls
Controls include TLS in transit, restricted infrastructure access, API authentication, request limiting, short-lived operational logs and separation between public routing and the private model process. Security practices are reviewed as the service changes.
More information
This technical policy supplements the Privacy Notice. Data-related requests can currently be submitted through the official Lithune OpenRouter profile.