Legal

Data Retention Policy

Last updated September 29, 2026

What we keep, for how long, and what happens when that time is up. The rule is simple: we keep the least we need and delete it when we no longer need it. Your requests and Wity's answers are never logged, written to disk or used for training.

Scope#

This policy covers data held by AlphaNimble Technologies LLP for the Wity website, Playground, console and API. It adds detail to our Privacy Policy, which uses the same terms. Where a signed agreement with you sets different periods, that agreement applies.

Your content#

API requests and responses
in memory · gateway and GPU server
Held in memory while the request is processed. The model server may also keep recent requests in a temporary in-memory cache to answer repeats faster. Later requests overwrite it, and it is cleared when the server restarts. Never written to disk, logged, backed up or used for training. This includes images and the text Wity generates or thinks.
Session context
in memory · when sessions arrive
Held while the session is open, and deleted when it ends or expires.
Playground runs
same as API requests
The Playground sends your runs through the API, so the same rules apply. The console also keeps your draft and up to 200 recent runs in your own browser's local storage. We never receive that copy. You delete it in the console or by clearing your browser storage.

Records we keep#

Operational records
database · Railway
One row per API or console call: key, account, time, endpoint, status, question count, reasoning setting, token counts, latency and cost. No text or images. Kept while your account is open, so you can see and reconcile your usage. Deleted within 30 days of your account being deleted.
API keys
database · Railway
A one-way hash, the first few characters and the key's name and dates. Revoked keys are kept with your account so past usage stays traceable. Deleted with your account.
Account details
Clerk and database · Railway
Email address, organisation, Google profile details if you use Google sign-in, and sign-in history. Kept while your account is open, and deleted within 30 days of a verified deletion request. We do not close accounts for being inactive.
Payment and credit records
database · Railway, and Razorpay
Top-up amounts, currency, status, Razorpay order and payment IDs, and credit grants and expiries. Kept for 8 years after the end of the financial year they relate to, as Indian accounting and tax law requires, even if you delete your account. Razorpay keeps its own payment records under its own policy.
Correspondence
our email
Emails with you, including support requests. Kept for 1 year after the last message in the conversation, unless they are needed for a billing dispute or legal claim.

Logs, analytics and backups#

Playground rate limit
in memory · Vercel
Your IP address and a run count. Held in memory only, never written to disk, and cleared when the server restarts.
Hosting logs
Vercel and Railway
Our hosting providers keep platform logs, such as the time, path and status of a request, and sometimes the IP address. They never contain request or response bodies. They are kept under our providers' retention settings and used only to run and secure the Service.
Application logs
Vercel and Railway
Our own servers log errors and service events, such as a failed payment check or a database outage. They never contain Content. They are kept under our providers' retention settings and used only to fix faults.
Site analytics
Vercel
Pseudonymous page-view and page-load events, without cookies. Visitors are counted with a hashed identifier that changes every day, so events cannot be linked to you. Kept under Vercel's retention settings.
Database backups
Railway
Deleted records can stay in database backups until those backups are deleted. Backups are used only to recover from failures.

Deleting your data#

Requests through other platforms#

Requests that reach Wity through a platform we have an agreement with, such as an API marketplace, follow the same rules: their content is never logged, written to disk or used for training. We keep only the operational records described above, under the platform's account. The platform's own retention is covered by its own policies.

Reviews and changes#

We review this policy at least once a year, and whenever we change how or where we store data. We will post changes here and update the date above. If a change means we keep your data longer, we will email account holders before it takes effect.

Questions about this page? Write to info@alphanimble.com.