Compute Desk

Inference Privacy Policy

Effective 15 September 2026 · Last updated 15 September 2026

This Privacy Policy explains how The Compute Index, Inc., operating as Compute Desk, handles information when it serves model inference. It covers requests routed to Compute Desk by OpenRouter or another aggregator (the Inference Service).

It states the commitment at the center of how we run inference: we do not read your prompts, we delete them within 24 hours, and we never use them to train anything.

Our role

Compute Desk operates inference as a service. When an aggregator routes a request to us, we run it against the model you selected on GPU capacity we control and return the output to the aggregator, which returns it to you. We do not build, train or fine-tune the models we serve; we host models published by their developers under those developers' licenses.

The aggregator holds your account, your payment details and your usage history. We receive only the request content it forwards and the technical data needed to serve it. Under data protection laws such as the EU and UK GDPR, the aggregator or its customer determines why your content is processed, and we act as a processor or sub-processor on its instructions. Under the California Consumer Privacy Act, we act as a service provider. We do not have a direct relationship with you and cannot identify you from what we receive.

What we receive

Request content

The prompts, system instructions, messages, documents, images and any other inputs the aggregator forwards, and the outputs the model generates in response.

Request metadata

The technical data generated by each request, such as the model called, timestamp, input and output token counts, latency, request status, the aggregator identifier that authenticated the request, and the IP address the request arrived from. That address belongs to the aggregator, not to you.

Communications

If you or an aggregator contact us, we keep a record of that correspondence.

We do not knowingly process information about anyone under 18. The Inference Service is a business service and is not directed to consumers.

How we handle request content

Request content is processed in memory to generate the output. Our serving stack writes request content to operational monitoring logs, which we use to detect faults and confirm the service is behaving correctly. We delete those logs within 24 hours of the request. After that point no copy of your prompt or output exists on any Compute Desk system.

Within that window, the following applies:

We do not read prompts or outputs

No Compute Desk employee or contractor views request content in the ordinary course of operating the service. Monitoring works on automated signals such as error rates, latency and malformed responses. Access to the logs is limited to the engineers who operate the service, is granted on a least-privilege basis, and is recorded. An engineer inspects request content only when investigating a specific service fault or security incident, and only to the extent needed to resolve it.

We do not train on your content

We do not use prompts or outputs to train, fine-tune, evaluate or otherwise improve any model, and we do not make them available to any model developer or third party for that purpose.

We do not run content moderation

Abuse detection operates on request metadata such as volume, rate and error patterns, not on the content of requests.

We do not sell or share request content

We do not use it to build market intelligence or any other product, and we do not keep it in backups, databases or caches that outlive the 24-hour monitoring window.

If a court order or other valid legal process compels us to disclose content, we will comply only to the extent required and, where the law permits, tell the aggregator first. Because we delete request content within 24 hours, we will normally have nothing to produce.

How we use request metadata

We use request metadata to operate, meter and secure the Inference Service: to route requests, to measure capacity and performance, to compute usage for settlement with aggregators, to detect abuse and enforce rate limits, and to meet legal and accounting obligations. We also use aggregate metadata (total tokens served, latency distributions, error rates) to plan capacity and improve the service. Aggregate metadata contains no request content.

Legal bases for processing (EU, EEA and UK)

We act as a processor or sub-processor for request content, so the controller determines the legal basis. We process on documented instructions under a data processing agreement with the aggregator, which we can provide on request.

Where we are the controller, for correspondence and settlement records, we rely on contract, legitimate interests in operating and securing the service, and legal obligation.

How we share information

We use third-party providers to deliver the Inference Service. They process information on our instructions, under contract, and only as needed to provide their service to us.

GPU compute and data center hosting

The hardware that runs inference is procured from third-party infrastructure providers under written agreements. Request content passes through their systems on machines we control, on the same terms described above.

Control plane hosting

The systems that authenticate requests, route them, hold monitoring logs and record metadata run on cloud infrastructure providers.

Error monitoring

Records diagnostic information about failures, subject to the same 24-hour deletion.

Aggregators

We return the model output to the aggregator that sent the request and share usage metadata with it for settlement. We do not share request content with anyone else.

Legal and safety

We may disclose information if required by law or legal process, or to protect the rights, safety and security of Compute Desk, our customers or others.

Where we process

Compute Desk is a US company. Inference, and the systems that route requests and hold monitoring logs, run in the United States, the European Union, the United Kingdom or India, depending on the model and available capacity. Where a request originates in the EU, EEA or UK and is processed outside those territories, we rely on Standard Contractual Clauses, the UK International Data Transfer Addendum or another recognized transfer mechanism under our data processing agreement with the aggregator. Aggregators that offer region-restricted routing can direct requests to specific locations under that agreement.

Retention

Request content

Deleted within 24 hours of the request.

Request metadata

Retained for 12 months for settlement, abuse detection and capacity planning, then deleted or aggregated. Settlement records are retained for the period tax and accounting law requires.

Communications

Retained for as long as needed to resolve the matter and meet legal obligations.

Your rights

Direct requests about your personal information to the aggregator you use. It holds your account and can identify your usage; we cannot. We will assist it as our processing agreement requires. Individuals in the EU, EEA and UK may lodge a complaint with their local data protection authority. Under the CCPA, we do not sell or share personal information as those terms are defined.

Because we delete request content within 24 hours, requests to access or delete prompts and outputs will normally find nothing to act on.

Security

We encrypt data in transit, including between the request gateway and the GPU nodes that run inference. We authenticate every request. Access to serving infrastructure and monitoring logs is limited to the engineers who operate the service and is granted on a least-privilege basis with credentials that are logged. Inference nodes run in dedicated environments we control; they are not shared with other Compute Desk services.

We continue to build out our security program as the company grows. We do not currently hold formal certifications such as SOC 2, and we will update this policy if that changes. No method of storage or transmission is completely secure, and we cannot guarantee absolute security.

Changes to this policy

We may update this policy as the Inference Service and our practices evolve. When we make material changes, we will update the effective date above and notify the aggregators we serve. Continued use after a change means you accept the updated policy.

Contact us

The Compute Index, Inc. (Compute Desk)

Nodal Exchange and Compute Desk to launch Compute Futures