engyglm-5.3 and glm-5.3-flash are now live

Privacy policy

Zero data retention: engy does not store your prompts or your model outputs, and never uses them for training. This page states exactly what is and is not kept, and which models the commitment covers.

Effective 2026-08-16 · contact [email protected]

What we never store

Prompts, completions, tool-call arguments and results, images, embeddings: the content of your requests and responses. Content passes through the gateway to a GPU worker, is processed in memory, and is gone when the response is delivered. No request or response content is ever used to train, fine-tune, or evaluate models.

Which models this covers

The commitment above is enforceable on hardware engy operates, so it is scoped to the models engy serves itself. Those models are marked ZDR on /pricing.

qwen3.6-35b-a3b is the exception. It is routed across public, permissionless miners on the engy network: independent operators, on hardware without confidential computing, who hold administrative access to their own machines. They accept a no-retention policy as a condition of serving traffic, but engy cannot technically guarantee non-retention on machines it does not control. Treat that model as unsuitable for data you are unwilling to expose to a third-party operator. The terms state this as a contractual matter.

What we store

datapurposeretention
usage metadata per request: timestamp, model, token counts (prompt / cached / completion), cost, latencybilling, capacity planning, the usage view in your dashboardkept while your account exists
account data: email, salted password hash, API key hashes and prefixes, credit balanceauthentication and billingkept while your account exists; deleted on request
operational logs: connection metadata and error events, no message contentdebugging, abuse preventionrotated on a short schedule

Integrity audits

engy is a verified-inference network: a sample of responses is cryptographically audited to prove the exact advertised model produced the output. An audit record stores the response's token IDs and the verification result, never the prompt. Audit records are purged within 30 days.

Processing path

Requests reach us through Cloudflare (TLS termination and DDoS protection; Cloudflare processes traffic per its own policies). For ZDR models, inference runs on GPU workers we operate; those workers hold request content in memory only and keep no copy. qwen3.6-35b-a3b instead reaches independent operators, as described under which models this covers.

Your rights

Email [email protected] to delete your account and its stored data, or to ask anything about this policy. Material changes to this policy will be posted on this page with a new effective date.