Data handling and retention
What the service keeps, for how long, where, who can read it and what you control.
We keep nothing except while we process it
Your content stays with us only for the length of a request, or for the life of a job or session that you start. Templates and dictionaries that you save stay until you delete them. We have no interest in your data. We do not use it to train models or for any purpose of our own.
What we keep and for how long
The table lists what the hosted API stores, where and for how long.
| Data | Where | How long |
|---|---|---|
| Direct requests: text, images, audio and mappings | Memory of the processing servers | Only while the request runs. A request that names an API session adds its new replacements to that session. |
| Job source and job request: the input that a job reads and the options that you send | Encrypted job storage | Until the job run ends |
| Upload | Encrypted job storage | Until the last job that reads it ends. With the keep option: 24 hours, extended by every job that reads it. An upload that no job reads: 24 hours. |
| Job results: protected output, entities, redacted files and the mapping on request | Encrypted job storage | 24 hours after you start the job, or until you delete the job |
| API session: a replacement map with the original values | Encrypted session storage | The time to live that you set: one hour by default, at most 24 hours from creation, or 7 days with extended sessions |
| Retry fingerprint: a hash of the Idempotency-Key and the request, without readable content | Memory of the API server; for jobs, encrypted job storage | Direct requests: until the next restart of the service at the latest. Jobs: at most 24 hours after you start the job. |
| Receipt of a hosted MCP tool: a keyed hash of the request identifier and the input, without readable content | Service database | With the usage records, to prevent double charging |
| Saved templates and dictionaries | Encrypted in the service database | Until you delete them; backup copies age out within 14 days |
| Usage records: request reference, counts, tier and time, without content | Service database | While the account needs them for balances, billing and legal duties |
| Backups: account records and saved configurations, no request content | Encrypted backup storage | 14 days |
Service logs contain no request content, no mappings and no API secrets. Reporting counts requests by category and stores no content.
Where we process it
- The hosted API runs on STACKIT in Germany.
- Speech recognition and audio redaction run on a second STACKIT server in Germany. Its processing containers have no network access, and it keeps no copy of a recording.
- We do not move your content out of the European Economic Area. Connections that you configure, for example to your own storage or key service, follow your instructions.
- With an offline installation, all processing stays on your infrastructure.
Who can read it
- Only your account can read your jobs, uploads and sessions through the API. Another account gets 404.
- Uploads, job sources and job results of the native API v2 are encrypted with a separate key for each customer. A file of one customer cannot be decrypted with the key of another customer.
- The job request, jobs of the other APIs and sessions use authenticated encryption that is bound to the job or session and to your account. Saved templates and dictionaries are encrypted.
- Innovius staff do not read customer content in routine operation. Administrative access to the servers is restricted, and staff are bound to confidentiality.
- Billing and email providers do not receive your API content.
What you control
| Goal | How |
|---|---|
| Keep nothing on the server | Send direct requests without an API session. Only the response carries the result. |
| Remove job results before the 24 hours end | DELETE /v2/jobs/{id} |
| Read one upload in several jobs | POST /v2/uploads?keep=true |
| End a session early | DELETE /v2/sessions/{id} |
| Keep a session longer than 24 hours | Ask support (info@innovius.ai) to enable extended sessions for your account. New sessions can then live up to 7 days. |
| Restore values without a map on the server | Ask for the mapping in the response and store it in your application. |
| Remove saved templates and dictionaries | Delete them through the compatibility API that created them. |
| Keep all content on your own servers | Run the offline installation. |
Legal documents
The data processing agreement and the privacy notice are binding. This page summarises them.