USDF and trust
Data handling and retention.
What's stored for a request, what never is, and how long each is kept.
On this page
Three kinds of record, each for billing or for proof:
| Record | What it holds |
|---|---|
| Account and key records | Account identifiers, linked wallet details, key labels, limits, and the hash that validates each key. |
| Usage records | Per request: its id, channel, model, provider and endpoint, whether it streamed, the prompt, completion and cached token counts, the cost, the price sheet version, the status, and the settlement batch that pays for it. |
| Settlement and proof records | Settlement digests and transaction hashes, the price sheet archive, and the inputs needed to recompute a charge or a reserve figure yourself. |
Prompt text, completion text and tool call arguments. The usage table has no column for them.
A request's content goes to the provider that serves it. The gateway writes it nowhere beyond that call, with one exception: a batch job's result is kept 7 days after the job ends, so it can be fetched.
What the provider does with the content is published per route, as that route's data_policy in GET /v1/pricing. It is there before the request is ever sent.
A key in no-logs mode keeps prompt text, completion text and tool arguments out of every write path: the database, a log line, an alert. Error paths are included. Every Private-tier key is in no-logs mode.
- Still recorded: token counts, cost, model, latency and status. They make a charge billable and checkable against the usage log.
- A no-logs request is marked as such on its own row.
- Set it per key on the dashboard, or as the default for every key the account creates. See Spend caps, allowlists and pause.
A private request runs on attested hardware. It is tied to that provider's own signed receipt for it, archived with its hash.
See Security for what serving it needs, and Private inference for which models have an attested route today.
| Record | Kept for | Why |
|---|---|---|
| Usage rows | Indefinitely. Never deleted. | Each is a leaf in the public usage log, anchored onchain. Removing one would break a proof someone already holds. |
| Batch job results | 7 days after the job ends | Then the result expires. Its status, cost and receipt stay. |
| Unclaimed USDF links | Until expiry: 30 days, or less if the sender sets it | Then the amount goes back to the sender. |
| Statements | As long as the account exists | One per month, as CSV, PDF or JSON. |
| Account and key records | As long as the account exists | A revoked key's record stays, so past usage stays attributable in the activity log and statements. |
| Private attestation receipts | Archived. Never deleted. | Kept for verification. |
Anyone, with no key, can read a request's receipt:
- Its model, provider and endpoint.
- Its token and cost figures, the price sheet version and the status.
- For an x402 or MPP payment, the payment itself.
Prompt and completion text are never published, because they are never stored. To read a receipt and check it against the log, see Receipts and verification. The same figures are live on Transparency.
Every receipt is public at GET /x402/v1/receipts/{id}.