A statement such as “we do not store prompts” leaves several questions unanswered. It may describe the gateway's database while excluding its response cache, monitoring service, backups or upstream provider. Write down which component makes the claim and which data it covers.

Start with one representative request containing the kinds of content your clients actually use. Trace its prompt, attachments, tool arguments, retrieved context, response and operational metadata. Mark processing location, retention owner, access rights and deletion rule for each copy.

Distinguish routing location from inference location

A gateway in Europe can still route inference elsewhere. Opper's security overview, updated 5 October 2026, explicitly says upstream inference is not EEA-restricted by default. Its tracing and backup retention are separate considerations. Requesty's privacy policy also needs to be read at both router and upstream-provider scope.

For hosted routers such as OpenRouter, evaluate eligible endpoints, provider allowlists and fallback settings together. An approved first choice does not establish that an automatically selected fallback is acceptable. Retain a route configuration or vendor commitment covering the complete permitted set.

Logs and caches are separate storage choices

Leanroute's privacy policy distinguishes prompt database storage from response and semantic caches, which default to a 15-minute lifetime. A no-persistence option changes that behaviour. This is a documented design choice to evaluate, not a finding that the service is unsafe.

Cloudflare documents gateway logging with different handling for new customers from 24 September 2026 and earlier accounts. Identify which generation applies to your account before copying a retention limit from a comparison chart.

LangDB's retention documentation describes ClickHouse TTL cleanup through asynchronous merges. A retention deadline and physical deletion can therefore be different events. Ask how exports and backups are covered.

Read zero-retention claims at the correct layer

Vercel's security description separates gateway handling from provider ZDR arrangements and eligibility. ZenMux's Data Services controls change its own logging and related features; upstream processing still needs review. Hugging Face Inference Providers also distinguishes its request handling and metadata from provider policies.

Record whether a commitment covers prompt content, output, files, embeddings, tool calls, abuse monitoring and metadata. Ask whether enabling debugging, tracing, insurance or support access changes the commitment. Contractual terms and effective settings both belong in the evidence.

Technical detail: deletion and tenant boundaries

A retention change can stop new recording while leaving earlier copies to expire. Request the effective date, deletion job behaviour, backup lifecycle and export inventory. An organisation-wide setting may differ from a project-level setting.

For local inference, distinguish intentional prefix-cache sharing from accidental memory disclosure. The vLLM GGUF case concerns kernel output memory. Cache salting addresses a different mechanism. Neither can be represented by a single generic “private cache” tick box.

Questions for your evaluation

Use the privacy page of the worksheet. Attach a data-flow diagram, provider and subprocessor list, contract scope, retention settings and a deletion example. If evidence is missing, record that gap and an owner instead of inferring a favourable answer.

Applying this to OneVir

OneVir describes local and configured-provider execution paths. The implementation evidence record identifies retention-policy initialisation and history API documentation: invalid saved retention policy prevents service initialisation, and route retention can prohibit saved chat history.

Those observations cover named paths, not every data copy. Evaluate the chosen provider route, local history, files, observability exports and backups. Local execution can reduce upstream disclosure, but the operator still owns storage, access and deletion in the surrounding deployment.