Skip to main content

Data handling

This page lists what proxium stores about the calls of a project and how long it keeps the data. It also tells how you export or erase the data.

What proxium stores for every call​

For each attempt of a call, proxium stores a record of what happened. The record has the time, the provider, the model, the outcome, the duration, the x-proxium-source and the request id. For each call that a provider answers, proxium also stores the tokens and the cost.

These records do not hold the prompt or the answer. They are the base of the Overview and Requests screens, of your usage and of your bill.

Prompts and answers: the capture setting​

Each project decides if proxium stores the prompt and the answer of a call. The setting is Stored prompts and answers, in the Settings page of the console. It has three values.

ValueWhat proxium stores
offNo prompt and no answer. The attempt records stay.
errorsThe prompt and the answer of an attempt that failed. Nothing of an attempt that succeeded.
allThe prompt and the answer of every attempt.

A new project starts with errors. An older project can have all, so check the setting of each project. Any member of the project can change it.

When proxium stores a call, it applies these limits:

  • The request. proxium stores each message of the request as a separate part, up to 256 KB for each message. A message that the project already sent in the same month is stored once, and later calls point to it.
  • The answer. proxium stores the first 32 KB of the answer. If it cuts the answer, it marks the stored answer as cut.
  • Each attempt. If proxium tries a second provider, it stores the request and the answer of each attempt.

Every member of the project can read the stored prompts and answers on the Requests screen.

Memory​

Memory is off for a new project. When a member turns it on, proxium sets Stored prompts and answers to all. The setting cannot be narrower while memory is on. When memory goes off again, the setting stays at all until a member changes it. Use project memory gives the steps.

For each successful chat, Messages or Responses call that memory keeps, proxium also stores:

  • The whole answer, as parts of the conversation, up to 256 KB for each part. This limit replaces the 32 KB limit for these calls.
  • The x-proxium-source and the end user of the call: x-proxium-memory-subject, else the user field.
  • The text of the conversation, its title and its summary.
  • The memories that come from it, with an embedding for each memory, and the facts of the knowledge graph.

The summary, extraction and embedding calls go through the models of your project. Your usage shows them with the source proxium-memory.

How long proxium keeps data​

proxium deletes nothing on a schedule, with two exceptions.

  1. Memory retention. If a project sets Keep conversations for, proxium deletes once a day the memory conversations older than that number of days. It also deletes the memories that were corrected or removed before that time. Live memories stay. This deletion does not touch the stored prompts and answers on Requests.
  2. The response cache. proxium keeps a cached chat or Messages answer for 3600 seconds, whatever the capture setting. The response cache explains it.

All other data stays until an erasure deletes it: the attempt records, the usage, the stored prompts and answers, and the memories. You cannot delete one call. You can erase one end user or the whole project.

Keys​

Virtual keys. proxium shows a new virtual key once, when you create it. It stores a SHA-256 hash of the key and the first 12 characters, so the console can name the key. After that, proxium cannot show the key again. If you lose a key, create a new one.

Vendor keys. When you add your own provider key, proxium encrypts it with AES-256-GCM. The console does not show the key again.

Export a project​

Open Settings and go to Export everything.

  1. Optional: set From (inclusive) and To (exclusive). Leave both empty to export all the data.
  2. Optional: select Include the stored prompts and answers. Only an owner can select it.
  3. Select Download.

The file is newline-delimited JSON. Each line names its table and holds one record. The export holds the usage, the endpoints and the settings of the project. For each virtual key, it holds the prefix, the label, the tier and the status, but not the hash. For each vendor key, it holds the provider and the dates, but not the encrypted key.

Without the checkbox, the export holds no prompt and no answer. It also holds none of the memory content: conversations, memories, pages and graph facts. Any member can make that export.

proxium records every export: who asked, when, for which dates, and if the prompts and answers were included.

Erase a project​

Only an owner can erase a project. Open Settings and go to Erase this project.

warning

You cannot undo an erasure, and proxium keeps no copy. Export the data first if you need it.

  1. Type the project name in Type project to confirm.
  2. Select Erase permanently.

proxium deletes every prompt, answer, usage record, key, endpoint, setting and memory of the project, and the project itself. It deletes everything in one transaction, so all of it goes or nothing goes. The receipt gives the number of rows deleted from each table.

Exact-match entries of the response cache stay until they expire, after 3600 seconds. proxium cannot find them by project, because each key is a hash. The erasure deletes the virtual keys of the project, so nobody can read those entries.

Erase one end user​

When one end user of your application asks to be forgotten, erase their subject. Any holder of a virtual key of the project can send DELETE /v1/memory/subjects/{subject}. In the console, only an owner sees Erase one of your users in Settings.

proxium deletes the memories, the profile and the conversations of that end user. It also deletes the stored prompts and answers of the calls that memory kept for that end user. A message part that other calls also use stays, for example a shared system prompt. The audit record holds a SHA-256 hash of the subject, not the subject. Use project memory has the request.

The erasure finds the calls through memory. It does not erase a call that named no subject, or a call that memory did not keep.