Kurrens Data Policy: Zero Data Retention
Last Updated: September 28, 2026
This Data Policy describes how INFERERA PTE. LTD. (“Kurrens,” “we,” “us,” or “our”) handles the prompts, files, and other inputs you send to the Kurrens API and the outputs the API returns. It forms part of our Terms of Service. Capitalized terms not defined here have the meanings given in the Terms.
If this Data Policy conflicts with our Privacy Policy or any other policy, webpage, or documentation regarding Customer Content, this Data Policy controls. A Data Processing Addendum supplements, and does not narrow, these commitments.
1. Summary
| Prompts & inputs | Completions & outputs | Request metadata | |
|---|---|---|---|
| Stored on disk | No | No | Yes |
| Written to logs | No | No | Yes |
| Used to train or improve models | No | No | No |
| Shared with model developers or other third parties | No | No | Only sub-processors needed to operate and bill the Services |
| Retention | None — discarded when the response completes | None — discarded after delivery | [[13 months]] |
Zero Data Retention applies to every account by default. It cannot be turned off, and we do not offer discounts or credits in exchange for access to your data.
2. No Retention of Customer Content
Customer Content is processed in memory only for as long as strictly necessary to process a request and return the response. It is not written to persistent storage, not included in application or access logs, and not accessible to our personnel. When the response has been delivered (or the request is cancelled or fails), Customer Content is discarded.
Prompt caching, where offered, stores intermediate model state (such as key-value cache) in GPU or system memory only, for a short period (typically minutes), scoped to your account, solely to reduce latency and cost on repeated prompt prefixes. Cached state is never written to persistent storage and is evicted automatically.
3. No Training
We do not use Customer Content to train, fine-tune, distill, evaluate, benchmark, or otherwise improve any model — including our own models, the models we serve, or any third party’s models — and we do not permit any third party to do so. Where you explicitly request a service that requires using your data (for example, fine-tuning a model for your exclusive use, if offered), we will use that data only for that service and as described in the applicable service terms.
4. No Sharing
We run the models ourselves on infrastructure we operate. Customer Content is not sent to model developers. We do not sell, publish, or share Customer Content with any third party, except with sub-processors that provide the physical infrastructure on which our systems run, and only to the extent necessary for that infrastructure to operate.
5. Where Processing Happens
Inference requests are processed in the following locations: Malaysia (Johor), Indonesia (Jakarta), and Ireland (Dublin). Requests are served from Johor by default, with Jakarta as a second Asia Pacific region; Dublin hosts European dedicated deployments and serves as a failover region. Where our API or model listing identifies the datacenter for a specific model or endpoint, requests to that endpoint are processed in that location. See our Sub-processors page for the infrastructure providers involved.
6. What We Do Keep: Request Metadata
To operate, bill, and secure the Services, we record request metadata for each API call: request ID; timestamp; API key identifier; account identifier; model identifier; service tier; input, cached, reasoning, and output token counts; latency and time-to-first-token; response status code and error type; client IP address; and cost. Request metadata does not contain Customer Content. We retain it for [[13 months]] for billing, usage reporting, capacity planning, and abuse prevention, and then delete or aggregate it, unless a longer period is required to resolve a dispute or to comply with law.
7. Limited Exceptions
We capture or retain Customer Content only in the following cases:
- Support you request. If you ask us to troubleshoot a specific problem and give us prior written permission (for example, by email from an account administrator), we may capture the specific requests identified in your permission. We use that data only to resolve the issue, restrict access to the engineers working on it, and delete it within thirty (30) days after the issue is resolved.
- Legal requirements. Where we are required by applicable law or a binding order to preserve specific data, we will do so only to the extent required and, where legally permitted, will notify you.
- Asynchronous and batch jobs. If you use batch or asynchronous processing (where offered), your input files and results are stored encrypted until results are delivered and then deleted within [[seven (7) days]] after the job completes or expires, or earlier if you delete them. These jobs are never used for training.
8. Safety and Abuse Prevention
Because we do not retain Customer Content, we do not review it. We detect and respond to abuse using request metadata, account signals, rate patterns, and reports from third parties (support@kurrens.ai). [[We do not run automated content classifiers on Customer Content.]] If we are required to screen content for a specific model under its license, we will state this on that model’s page, and screening will occur in memory without retention.
9. Model Developers’ Policies
The models we serve are open-weight models that we run ourselves; the model developers’ own data retention policies for their hosted APIs do not apply to requests you send to Kurrens.
10. Changes
We will not make changes to this Data Policy that reduce your protections without at least thirty (30) days’ prior notice by email and on this page. Any such change will apply only to requests made after it takes effect.
11. Contact
Questions about this Data Policy: support@kurrens.ai Governing law and dispute resolution: as set out in our Terms of Service.