Privacy Policy
Last updated August 24, 2026. Questions: kavon@mutiny.ai.
The short version
We keep the metadata needed to bill and route: token counts, costs, which model served a request, and what kind of work it was. We do not store the content of your prompts or answers, with two exceptions you control: traces you choose to send us, and workload samples kept only after you opt in — redacted and capped. We never train models on your content.
What we collect
Account data. Your email address and name, your organization, team roles and invites, and an audit log of sign-ins and administrative actions.
Request metadata. For every API request: timestamps, token counts, cost, the model and routing decision that served it, and the kind of work it was classified as. This is what your receipts, usage page, and savings figures are built from. It does not include the text of the request or the answer.
Content, only where you choose it. Prompts pass through us to the model that generates your answer — that is the service working, not storage. Content is stored in exactly two cases: traces you explicitly export to us, and workload samples kept under the measurement opt-in described below. Both paths run through automatic redaction of common personal-data patterns before anything is written.
Measuring your workloads (the opt-in)
If your organization opts in, we keep a small, capped sample of requests per kind of work — redacted prompt and answer — and use it for one purpose: measuring how well models perform on your actual work, so we can show you what your current model scores and propose routing settings with evidence. Proposals never apply themselves; you press the button. You can withdraw the opt-in at any time, and deleting your organization deletes the samples.
Where your data goes
To answer a request, its content goes to the model that serves it. Today that means our upstream inference providers (such as OpenRouter and OpenAI) and the operators of the specific model your request is routed to, under their own terms. We also use Hetzner (Germany) for hosting, Render (EU, Frankfurt) for our database, and Resend for transactional email such as sign-in links and alerts. We do not sell your data, and we do not share it with anyone beyond these processors and what the law requires.
Security
Traffic is encrypted in transit. API keys are stored only as hashes. Sign-in is by short-lived email link — we hold no passwords. Every API route is exercised by an automated tenant-isolation sweep before it ships, so one organization’s data is not reachable from another’s session or key.
Retention and deletion
Request metadata is retained while your account is active, because it is your billing record. Deleting your organization deletes its data — keys, members, invites, traces, samples, measurements, and settings — in one cascade. To delete your organization or exercise access and correction rights over your data, email kavon@mutiny.ai and we will act on it.
Changes
If this policy changes materially, we will tell you by email or in the dashboard before the change takes effect. This draft has not yet completed legal review.