Privacy
Updated 11 October 2026
Effective date: 11 October 2026
This page says what OSPA Labs collects to run Fuse, why, and what we do not keep. The data page covers processing when you send your users' requests through the proxy.
Account
We store:
- your email address, and a password hash if you set a password
- a Google account identifier if you sign in with Google
- session records so you stay signed in
We use this to run the account, send security mail, and tell you when a ceiling warns or blows.
Projects and keys
We store project names, ceilings, which models are on, and your provider API keys. Those keys are encrypted. The dashboard can show the last four characters. We cannot show you the key again, and we do not use your provider keys for our own traffic.
Fuse keys are stored only as a hash. The full key is shown once, when you create it.
Requests
For each proxied call we keep metadata: time, endpoint, model, token counts, estimated cost, status, and a request id. We do not store prompt text, response text, or file contents. IP addresses are not written to the database. A short-lived counter may use an IP only to slow failed logins and form spam. That counter is memory, and it expires.
The proxy has to read a request in order to forward it. That content stays in memory for the length of the call and is then dropped.
Payments
Paddle is the merchant of record. Paddle collects payment details. We receive subscription status, plan, and a customer id so the dashboard knows whether the proxy may run. We do not store card numbers.
We send mail for sign-in, password links, ceiling alerts, and support replies. The address you give us is the address we use.
Cookies
The marketing site uses Google Analytics to see which pages are opened. That is a statistics cookie from Google, not an advertising cookie. The dashboard session cookie is separate and only keeps you signed in.
Who else handles data
Cloudflare runs the proxy and can see connection data the way any edge network does. The database host stores the records above. Paddle handles billing. Our mail host delivers email. A longer list is on the data page.
How long
Account and project data stay until you delete them or close the account. Usage metadata stays so the spend ledger and the request log remain accurate for the periods you configured. You can ask support to delete an account. We will remove the account, projects, keys, and sessions. Billing records Paddle must keep are Paddle's.
Your requests
You can ask for a copy of your account data, a correction, or deletion, from the support page. If a law where you live gives you other rights, write to us the same way.