Legal · v1.0 · 2026-09-01
AI & Model Data Usage Policy
What happens to a prompt after GTWY routes it to a model provider.
1. What this covers
GTWY is a gateway: your application's requests pass through gtwy-node and gtwy-ai (see the Security Whitepaper) and are routed to whichever AI provider your configuration selects. This policy describes what happens to a prompt, completion, or document once it reaches that provider — separately from how GTWY itself stores and secures your data, which is covered in the Security Whitepaper and the DPA.
2. Default position: no training on your data by GTWY
GTWY does not use customer prompts, completions, or documents to train its own models — it does not operate general-purpose foundation models. Whether a specific third-party provider trains on request data depends on that provider's own API terms, summarized below; where a provider offers an enterprise or zero-retention tier with different terms, ask your GTWY contact to confirm which tier your account is routed through.
3. Connected providers
Every provider gtwy can route a request to, and what GTWY uses it for:
| Provider | Used for |
|---|---|
| OpenAI | Chat completion, embeddings, image generation |
| Anthropic | Chat completion & batch inference |
| Google Gemini | Chat completion & multimodal inference |
| Groq | Low-latency inference routing |
| Grok (xAI) | Chat completion |
| Mistral AI | Chat completion |
| Deepgram | Speech-to-text transcription |
| OpenRouter | Routes to additional third-party models |
| NeevCloud | GPU inference hosting |
| Moonshot AI | Chat completion |
| DeepSeek | Chat completion, reasoning |
| MiniMax | Chat completion, reasoning |
| NotDiamond | Automatic model routing across providers |
The current, authoritative list — including additions and removals with their 30-day notice under the DPA — is maintained on the Trust Center.
4. Retention in transit
Prompts and completions are held only long enough to complete the request and to satisfy the conversation-history and observability features your configuration has enabled; retention windows for that history are configurable per account and described in the Security Whitepaper's Data Security section. GTWY does not separately archive a copy of every provider response beyond what your account's own history settings request.
5. Sensitive content
Do not route personal data you are not authorized to share, or categories of sensitive data (health, biometric, financial account credentials) through a model provider whose terms do not permit it. GTWY does not screen prompt content before routing it.
6. Provider-side sub-processing
Each AI provider is itself a subprocessor under the DPA and is bound by its own data processing terms with GTWY. Questions about a specific provider's training or retention policy beyond what's summarized here should be directed to [email protected], which can share the relevant provider agreement on request.
7. Changes to this policy
Adding or removing a provider follows the same 30-day customer notice as any other subprocessor change under the DPA. This page is updated in step with that list.
Last updated 2026-09-01.