USDF and trust

Data handling and retention.

What's stored for a request, what never is, and how long each is kept.

On this page

Three kinds of record, each for billing or for proof:

RecordWhat it holds
Account and key recordsAccount identifiers, linked wallet details, key labels, limits, and the hash that validates each key.
Usage recordsPer request: its id, channel, model, provider and endpoint, whether it streamed, the prompt, completion and cached token counts, the cost, the price sheet version, the status, and the settlement batch that pays for it.
Settlement and proof recordsSettlement digests and transaction hashes, the price sheet archive, and the inputs needed to recompute a charge or a reserve figure yourself.

Prompt text, completion text and tool call arguments. The usage table has no column for them.

A request's content goes to the provider that serves it. The gateway writes it nowhere beyond that call, with one exception: a batch job's result is kept 7 days after the job ends, so it can be fetched.

What the provider does with the content is published per route, as that route's data_policy in GET /v1/pricing. It is there before the request is ever sent.

A key in no-logs mode keeps prompt text, completion text and tool arguments out of every write path: the database, a log line, an alert. Error paths are included. Every Private-tier key is in no-logs mode.

  • Still recorded: token counts, cost, model, latency and status. They make a charge billable and checkable against the usage log.
  • A no-logs request is marked as such on its own row.
  • Set it per key on the dashboard, or as the default for every key the account creates. See Spend caps, allowlists and pause.

A private request runs on attested hardware. It is tied to that provider's own signed receipt for it, archived with its hash.

See Security for what serving it needs, and Private inference for which models have an attested route today.

RecordKept forWhy
Usage rowsIndefinitely. Never deleted.Each is a leaf in the public usage log, anchored onchain. Removing one would break a proof someone already holds.
Batch job results7 days after the job endsThen the result expires. Its status, cost and receipt stay.
Unclaimed USDF linksUntil expiry: 30 days, or less if the sender sets itThen the amount goes back to the sender.
StatementsAs long as the account existsOne per month, as CSV, PDF or JSON.
Account and key recordsAs long as the account existsA revoked key's record stays, so past usage stays attributable in the activity log and statements.
Private attestation receiptsArchived. Never deleted.Kept for verification.

Anyone, with no key, can read a request's receipt:

  • Its model, provider and endpoint.
  • Its token and cost figures, the price sheet version and the status.
  • For an x402 or MPP payment, the payment itself.

Prompt and completion text are never published, because they are never stored. To read a receipt and check it against the log, see Receipts and verification. The same figures are live on Transparency.

Every receipt is public at GET /x402/v1/receipts/{id}.