Privacy
Privacy Policy
This page describes Seldon's current product behavior for customer data. It should be reviewed by counsel before broad marketing or customer contracting.
Last updated: July 9, 2026
Audit retention
We retain customer API data for audit, billing, reliability, security, debugging, and product operation.
No resale
We do not resell customer prompts, outputs, traces, cached responses, or API traffic.
No generalized training
We do not use customer prompts, outputs, traces, or cached responses to train generalized AI models.
BYOK handling
BYOK provider keys are used for the request and are not stored by Seldon.
Data We Process
Seldon may process account, authentication, workspace, API key metadata, billing, usage, routing, trace, request, response, cache, support, and security records. API key metadata can include names, prefixes, status, limits, and timestamps; raw keys are shown only at creation or reveal time.
API traffic can include prompts, inputs, outputs, model choices, provider choices, token counts, latency, costs, headers needed for routing, request identifiers, error details, and trace records. Trace payload capture redacts sensitive headers and secret-like values before storage.
Why We Retain Data
We retain API data and operational records to bill accurately, operate and secure the router, debug incidents, investigate abuse, support customers, improve product reliability, maintain audit trails, and power Seldon features such as Calls & usage, Live Audit, cache visibility, and compiled-path analysis.
Retention And Deletion
Current default trace payload retention is 90 days. Dashboard trace detail is currently limited to a 30-day availability window, and payload references are shown only to workspace admin or owner roles when payloads have not expired.
When enabled for a workspace, Trace Explorer can show private trace metadata and, for workspace owners or admins, bounded already-redacted request/response content. Seldon retrieves that content server-side; the browser is not given storage references or signed URLs. Users without that role receive an availability state, not payload content. Trace Explorer metadata exports exclude prompts, responses, tool arguments, end-user identifiers, and storage references.
Live Audit may retain privacy-bounded daily aggregate evidence after raw trace payloads expire so an API key can show its retained audit history. Those derived records contain counts, costs, token and evidence-health totals, and limited workflow summaries; they do not contain prompts, completions, trace identifiers, payload references, raw schemas, tool arguments, or API-key secrets. A separately retained private Audit evidence generation can hold exact trace membership and bounded selection codes for up to the configured evidence window (90 days by default); it does not copy payload content. Derived audit history is deleted with its workspace; a revoked API key remains labelled in its workspace history unless the workspace is deleted.
Some records may be retained after a deletion request where needed for billing, audit, security, legal, dispute, backup, or abuse-prevention purposes. Deletion and export requests can be sent to Seldon support using the contact channel in your account or customer agreement.
Providers And Subprocessors
Seldon routes requests to configured model providers and uses infrastructure, authentication, billing, analytics, and support vendors to operate the service. Model providers receive the request data needed to complete the selected model call. See the Subprocessors page for the current public vendor table.
Cookies And Analytics
Seldon may use cookies, hosted platform telemetry, and web analytics to operate the site, understand aggregate product usage, detect abuse, and improve reliability. We do not use those tools to resell customer API traffic.
Product analytics uses PostHog Cloud US to capture selected site and product behavioral events with pseudonymous WorkOS user and workspace identifiers. Seldon does not send customer API traffic content (prompts, outputs, traces, or tool payloads) to PostHog.
Privacy Rights
Depending on where you are located, you may have rights to access, correct, delete, or export certain personal information, or to object to certain processing. We will respond according to applicable law and the relevant customer agreement, while preserving records required for audit, security, billing, legal, and operational purposes.