OpenWeightsTerminal

Updated 2 October 2026

Privacy

No chat logs. Prompts are erased when a host picks them up. Replies are erased 10 minutes after they finish. We keep only token counts for billing.

What we keep, what we erase, and where the code does it.

What we keep

  • Each job leaves a billing record: the API key id, the model, token counts, timestamps, status, and which host ran it.
  • That record does not hold your prompt or the reply.
  • Payments and payouts are recorded for the ledger.
  • To stop abuse, the guest chat counts requests per IP address in server memory. That count is not written to the database.

What we never keep

  • No chat logs. No transcripts.
  • Your prompt is erased from our database the moment a host picks up the job.
  • If no host picks it up within 3 minutes, the job fails and the prompt is erased.
  • The reply is erased 10 minutes after the job finishes, read or not.
  • We don’t log request bodies. No request logging is set up, and our API code doesn’t log prompts.
  • A guest chat lives in your browser tab. Close the tab and it’s gone.

What the host sees

  • The host runs the model, so its machine reads your prompt in plain text while the job runs. There is no way around that today.
  • We can’t see inside a host’s machine. We can’t stop a host from logging what it runs.
  • Our server also handles your prompt on its way to the host.
  • The pool has no hardware attestation (TEE) yet.
  • If something must never leave your device, run the model on your own machine.

Run locally instead →

Paying without an identity

  • API keys need no account. No email, no name, no phone number.
  • You can pay with shielded ZEC. The payment is matched by a memo, not by who you are.
  • USDC on Base is public on chain. Use ZEC if you want the payment unlinked from you.
  • Sign-in with X is optional. It only syncs and recovers your keys.

How each claim is enforced

Every rule above is in public code. You can read it yourself.

ClaimHowSource
Prompt erased when a host picks up the jobclaimJob sets prompt = '' in the same query that hands the job to the host.pool-jobs.core.ts
Prompt erased after 3 minutes with no hostreleaseStale fails the job and blanks prompt and output (STALE = 3 minutes).pool-jobs.core.ts
Reply erased 10 minutes after the job finishesreleaseStale blanks output once the job is 10 minutes past finished, read or not (READ_TTL).pool-jobs.core.ts
Billing keeps metadata onlyAfter the text is blanked, the job row holds key id, host id, model, token counts, timestamps and status.0003_pool_jobs.sqlpool-jobs.core.ts
No request-body loggingwrangler.toml configures no observability or Logpush. API handlers don’t log prompts.wrangler.tomltry.ts
Guest chat stays in your tabThe conversation is React state only. Nothing is written to browser storage.use-try-chat.ts
Redaction happens in your browserPlaceholders are swapped in before the request is built. The map never leaves the tab.redact.ts
Keys without an accountopenCaller mints a key without a user id.pool-ledger.core.ts
Shielded ZEC paymentsZEC quotes are a shielded address and a memo; the desk settles by memo.CODE-WIKI.md0014_pool_rails.sql
Encrypted prompts, once every host has a keycreateJob seals the prompt to each live host’s key; only a matching host can claim it.prompt-seal.tsPRIVACY-ARCHITECTURE.md

What’s coming

Encrypted prompts at restLive

Prompts waiting for a host are stored encrypted once every host serving that model has upgraded (the ow CLI with a key, or the browser host). Otherwise they're stored as today until a host picks them up. An API caller can require this by sending owt.sealed: true in the request body, or the header x-owt-sealed: 1, and gets a 409 sealed_unavailable error instead of a plaintext fallback. The host still decrypts and sees the prompt. Replies are not encrypted.

In-browser redactionLive

The guest chat replaces emails, phone numbers, card numbers, IBANs, US SSNs, IP addresses, crypto addresses and API keys with placeholders like [EMAIL_1] before sending. The originals stay in your tab and are put back into the reply. It is on by default.

It works on patterns. It can’t find names, street addresses or other plain words, so leave those out. Inside code blocks it only removes secrets. Private network addresses like 192.168.1.20 are left as they are.

Redaction runs in the guest chat on this site. The API and the ow CLI send exactly what you give them.

How it fitsTermsAsk an open model.