Operating
What hosted llamay keeps
A model running on your own machine never sends your text anywhere. This page
is about the other kind: a hosted model, used from the apps, Studio or an API
key against app.llamay.com. In short, llamay keeps what a call
cost and not what it said.
Local models
A model you pulled runs in the llamay process on your machine. The prompt and the answer stay there; no llamay service is involved, and no account is needed. Everything below applies only to hosted models.
Who processes the text of a hosted request
- llamay's service, a Cloudflare Worker, receives your messages, adds the instruction and any memory your app sent with the turn, and forwards them. It holds them for the length of the request.
- Cloudflare Workers AI runs the model, reached through Cloudflare AI Gateway. Cloudflare's Workers AI data usage terms say it does not use customer content to train models or to improve its services, and does not make it available to other customers.
- Search providers, only when a turn searches the web: the search query goes to public search services (Bing, DuckDuckGo, Google News, Stack Exchange, Hacker News, Wikipedia), and pages the model reads are fetched from their sites.
- Connectors you added, only when you added them: the tool calls the model makes to a connector go to that connector's server.
What is not kept
The text of your prompts and of the answers. The service does not write a hosted request's messages or its answer to any of its storage. Every call to the model asks AI Gateway to log metadata only — model, token counts, cost, duration, status — and not the request or response body. Memory works the same way: your app sends its memory file with the turn, the service says what is worth adding, and your app writes the file; the service keeps no copy.
One exception, below: when a conversation grows past what the model can read, the older part is replaced by a summary, and that summary is kept for thirty days so the next turn does not pay to write it again.
What is kept, and for how long
| What | What is in it | How long |
|---|---|---|
| Usage ledger | Rows for each hosted call — its reservation and its settlement: the model, the amount reserved and charged, the tokens used, and the time — and for each top-up, with its order reference. No text. Also this month's token total and hourly totals for the last day, which is what a plan's allowance is checked against. | The last 500 rows per account; the totals until they roll over. All of it until the account is deleted. |
| Compaction summaries | A summary, written by the model, of the earlier part of a conversation too long for the model's context. Only for conversations that long; a request can send "compact": false to be refused instead. | Thirty days from when it was written, or until the account is deleted. Included in the data download. |
| Your account | The sign-in provider's id for you, your username and display name, your plan, and when the account was made. | Until the account is deleted. |
| Sessions | A SHA-256 hash of each sign-in token, with the account, username and organisation it belongs to. Never the token. | Ninety days. A deleted account's sessions are refused at once. |
| API keys | A SHA-256 hash of each key, its label, its first few characters, and when it was made and last used. Never the key. | Until you revoke it or delete the account. |
| What you sync | Conversations, memory and attention state your apps sync to your account, and files you put in the drive. Stored under your account's own prefix; Studio asks before it syncs your conversations. | Until you delete them or the account. A deletion is checked again an hour later for anything still uploading. |
| AI Gateway log | Metadata for each call: model, token counts, cost, duration and status. No text. | Held by Cloudflare under the gateway's log settings and Cloudflare's log retention. |
| Service logs | Errors the service reports, and Cloudflare's request metadata. The service does not log message text. | Held by Cloudflare under Workers Logs retention. |
Your sign-in details are held by the sign-in provider and orders and invoices by the payment provider, as Your hosted account describes. A message sent through the contact form is kept for ninety days.
Getting it back, and getting rid of it
Download my data gives you everything in the table that llamay holds — ledger, summaries, account, key labels and every synced object. Delete my account deletes it: keys are revoked, synced objects, summaries, the ledger and seats are deleted, and the sign-in is removed. What remains is a marker saying an account was deleted and when, with nothing about you, for ninety days.
A deployment of the sync service on your own Cloudflare account keeps what this page describes, under your account's settings — including which AI Gateway it uses and how long that gateway's logs are kept.