Last updated 2026-08-24
Privacy
The short version. Your provider API keys never reach our servers. Roz's memory lives on your hardware. But when you dispatch a job to a remote worker, that job's prompt and its output pass through — and are stored on — our relay. If that matters for a piece of work, run it on a local worker and it never leaves your machine.
What stays on your hardware
- Your provider API keys. Workers call OpenAI, Anthropic, Ollama and the rest directly, using keys held on the machine running the worker. The dashboard never receives them.
- Roz's memory. The local brain, its routing patterns and learned behaviour are stored on your device.
- Anything you run on a local worker. A job dispatched to a worker on your own machine does not transit our servers.
What we store
- Job prompts and job output. When you dispatch through the relay, the text of the job and the text of the result are written to our database so the job can be routed, retried, streamed to you, and shown in your history. We are a content host for those job bodies. Saying otherwise would be untrue.
- Account data. Email address, password hash, tenant and team membership.
- Operational metadata. Worker names and capability tags, dispatch timestamps, model and cost-tier chosen, token counts, job status, and an audit trail of privileged actions.
- Billing records. PayPal subscription and order identifiers. We never see or store your card details; PayPal handles payment entirely.
What we do not do
- We do not sell your data, and we do not share it with advertisers or data brokers.
- We do not read the content of your prompts or outputs across tenants, and we do not use your job content to train models.
- We do not track you across other websites.
Who else sees it
The AI providers you route to see the prompts you send them, under their own terms — that relationship is directly between you and them, on your own key. Our hosting provider stores the database on our behalf. PayPal processes payments. Nobody else.
Retention and deletion
Job records persist so your history stays useful. Ask us to delete your account and we will remove your account, your workers, and your job records — prompts and outputs included. One person reads that mailbox and will confirm when it is done.
Self-hosting
ModelReins can be run entirely on your own infrastructure, in which case none of the above applies to us because we are not in the path at all.
Contact
Questions, deletion requests, or anything that reads wrong here: [email protected]. ModelReins is operated by MEDiAGATO LLC.