Data
Updated 11 October 2026
Effective date: 11 October 2026
This page is the data processing summary for Fuse. It is what a customer needs when their own users' requests pass through the proxy. It sits next to the privacy page, which covers your OSPA Labs account.
Roles
You decide which apps call Fuse and which provider keys are stored. For the content of those API requests, you are the one who determines the purpose. OSPA Labs processes that content only to forward the call and to enforce the ceiling. For your account, billing status, and the dashboard, OSPA Labs decides the purpose.
What passes through
- the HTTP request your app sends to the Fuse proxy, including prompts and model parameters
- the provider response, including streamed tokens
- usage figures the provider returns, which become the cost on the ledger
Prompt and response bodies are not written to the database or to application logs.
What is stored
- encrypted provider API keys, bound to the project
- ceilings, enabled models, and Fuse key hashes
- usage events: time, endpoint, model, token counts, cost, status, request id
- alert records when a warning or a block fires
Why
Forwarding is required to provide the proxy. The ledger is required to stop spend at the ceiling you set and to show the dashboard. Alerts are required to tell you when a threshold is hit. We do not use request content to train models or to advertise.
Sub-processors
- Cloudflare, for the proxy worker and the edge in front of the dashboard
- the database host that stores the Fuse records
- Paddle, for subscriptions
- the email provider configured for Fuse mail
Your own provider (OpenAI, Anthropic, Google, Mistral, xAI, or a gateway you configure) receives the forwarded request under your contract with them. They are not our sub-processor.
Security
Provider keys are encrypted with AES-256-GCM. A data key wraps each secret, and a master key that is not in the database wraps the data key. Dashboard actions that change a key or a ceiling are tied to your session. The proxy refuses a request when it cannot check the ceiling.
Retention and deletion
Usage events stay for the life of the project so monthly and daily ceilings and the request log stay true. If you delete a project, its keys, ceilings, and usage rows go with it. Closing the account removes the projects. Ask on the support page if you want the account removed and cannot do it yourself.
Questions
Security and data questions go to the support form. Include the account email. Do not paste provider API keys or Fuse keys into the message.