Legal

Privacy

Updated 11 October 2026

Effective date: 11 October 2026

This page says what OSPA Labs collects to run Fuse, why, and what we do not keep. The data page covers processing when you send your users' requests through the proxy.

Account

We store:

We use this to run the account, send security mail, and tell you when a ceiling warns or blows.

Projects and keys

We store project names, ceilings, which models are on, and your provider API keys. Those keys are encrypted. The dashboard can show the last four characters. We cannot show you the key again, and we do not use your provider keys for our own traffic.

Fuse keys are stored only as a hash. The full key is shown once, when you create it.

Requests

For each proxied call we keep metadata: time, endpoint, model, token counts, estimated cost, status, and a request id. We do not store prompt text, response text, or file contents. IP addresses are not written to the database. A short-lived counter may use an IP only to slow failed logins and form spam. That counter is memory, and it expires.

The proxy has to read a request in order to forward it. That content stays in memory for the length of the call and is then dropped.

Payments

Paddle is the merchant of record. Paddle collects payment details. We receive subscription status, plan, and a customer id so the dashboard knows whether the proxy may run. We do not store card numbers.

Email

We send mail for sign-in, password links, ceiling alerts, and support replies. The address you give us is the address we use.

Cookies

The marketing site uses Google Analytics to see which pages are opened. That is a statistics cookie from Google, not an advertising cookie. The dashboard session cookie is separate and only keeps you signed in.

Who else handles data

Cloudflare runs the proxy and can see connection data the way any edge network does. The database host stores the records above. Paddle handles billing. Our mail host delivers email. A longer list is on the data page.

How long

Account and project data stay until you delete them or close the account. Usage metadata stays so the spend ledger and the request log remain accurate for the periods you configured. You can ask support to delete an account. We will remove the account, projects, keys, and sessions. Billing records Paddle must keep are Paddle's.

Your requests

You can ask for a copy of your account data, a correction, or deletion, from the support page. If a law where you live gives you other rights, write to us the same way.