Data handling
This page lists what Proxium stores about the calls of a project and how long it keeps the data. It also tells how you export or erase the data.
What Proxium stores for every call
For each attempt of a call, Proxium stores a record of what happened. The record has the time, the provider, the model, the outcome, the duration, the x-proxium-source and the request id. For each call that a provider answers, Proxium also stores the tokens and the cost.
These records do not hold the prompt or the answer. They are the base of the Overview and Requests screens, of your usage and of your bill.
Prompts and answers: the capture setting
Each project decides if Proxium stores the prompt and the answer of a call. The setting is Stored prompts and answers, in the Settings page of the console. It has three values.
| Value | What Proxium stores |
|---|---|
off | No prompt and no answer. The attempt records stay. |
errors | The prompt and the answer of an attempt that failed. Nothing of an attempt that succeeded. |
all | The prompt and the answer of every attempt. |
Memory is on by default and needs every call, so while memory is on, Proxium stores every call, whatever this setting says. With memory off, the setting applies, and any member of the project can change it.
When Proxium stores a call, it applies these limits:
- The request. Proxium stores each message of the request as a separate part, up to a size limit for each message. A message that the project already sent in the same month is stored once, and later calls point to it.
- The answer. Proxium stores the start of the answer, up to a size limit. If it cuts the answer, it marks the stored answer as cut.
- Each attempt. If Proxium tries a second provider, it stores the request and the answer of each attempt.
Every member of the project can read the stored prompts and answers on the Requests screen.
Memory
Memory is on for every project, new or old. Memory needs Stored prompts and answers at all, and the setting cannot be narrower while memory is on. A member can turn memory off. The setting then stays at all until a member changes it. Use project memory gives the steps.
For each successful chat, Messages or Responses call that memory keeps, Proxium also stores:
- The whole answer, as parts of the conversation, up to the size limit for each part. This limit replaces the smaller limit for the answer of these calls.
- The
x-proxium-sourceand the end user of the call:x-proxium-memory-subject, else theuserfield. - The text of the conversation, its title and its summary.
- The memories that come from it, with an embedding for each memory, and the facts of the knowledge graph.
The summary, extraction and embedding calls go through the models of your project. Your usage shows them with the source proxium-memory.
How long Proxium keeps data
By default, Proxium deletes nothing on a schedule. A project can set two retentions:
- Stored prompts and answers. In Settings › Stored prompts and answers, set Delete stored prompts and answers after to a number of days. Proxium then deletes the stored prompt and answer of each call older than that, with memory on or off. A call of a conversation that memory has not read yet stays until memory reads it. Leave the field empty to keep them.
- Memory. On the Memory screen, set Delete conversations after to a number of days. Once a day, Proxium then deletes the memory conversations older than that, and the memories that were corrected or removed before that time. Live memories stay. A conversation that memory has not read and learned from stays. Leave the field empty to keep everything.
- The response cache. Proxium keeps a cached chat or Messages answer for a while, whatever the capture setting. The response cache explains it.
The audit trail stays. The record of each call (who called, when, which model, the status and the cost) is not deleted by a retention. It stays until an erasure of the project deletes it. You cannot delete one call.
Calls stored before the retention existed. When a project sets a retention, Proxium first copies these stored prompts and answers to cold storage. Then it deletes them by the retention. It deletes a call only after it read the copy back and checked it. An erasure of the whole project also deletes these copies. An erasure of one end user does not reach them yet.
Keys
Virtual keys. Proxium shows a new virtual key once, when you create it. It stores a hash of the key and its first characters, so the console can name the key. After that, Proxium cannot show the key again. If you lose a key, create a new one.
Vendor keys. When you add your own provider key, Proxium encrypts it. The console does not show the key again.
Export a project
Open Settings and go to Export everything.
- Optional: set From (inclusive) and To (exclusive). Leave both empty to export all the data.
- Optional: select Include the stored prompts and answers. Only an owner can select it.
- Select Download.
The file is newline-delimited JSON. Each line names its table and holds one record. The export holds the usage, the endpoints and the settings of the project. For each virtual key, it holds the prefix, the label, the tier and the status, but not the hash. For each vendor key, it holds the provider and the dates, but not the encrypted key.
Without the checkbox, the export holds no prompt and no answer. It also holds none of the memory content: conversations, memories, pages and graph facts. Any member can make that export.
Proxium records every export: who asked, when, for which dates, and if the prompts and answers were included.
Erase a project
Only an owner can erase a project. Open Settings and go to Erase this project.
You cannot undo an erasure, and Proxium keeps no copy. Export the data first if you need it.
- Type the project name in Type project to confirm.
- Select Erase permanently.
Proxium deletes every prompt, answer, usage record, key, endpoint, setting and memory of the project, and the project itself. It deletes everything in one transaction, so all of it goes or nothing goes. The receipt gives the number of rows deleted from each table.
Exact-match entries of the response cache stay until they expire. Proxium cannot find them by project, because each key is a hash. The erasure deletes the virtual keys of the project, so nobody can read those entries.
Erase one end user
When one end user of your application asks to be forgotten, erase their subject. Any holder of a virtual key of the project can send DELETE /v1/memory/subjects/{subject}. In the console, an owner erases one at the bottom of the Memory screen, in Erase one user.
Proxium deletes the memories, the profile and the conversations of that end user. It also deletes the stored prompts and answers of every call that named that end user, whether memory kept the call or not. A message part that other calls also use stays, for example a shared system prompt. The audit record holds a SHA-256 hash of the subject, not the subject. Use project memory has the request.
A call names its end user with x-proxium-memory-subject or the user field. The erasure does not find a call that named no end user. A call that memory did not keep is found only if Proxium stored it after the erasure by end user started. A copy of a call in cold storage (see How long Proxium keeps data) stays after the erasure of its end user.