Privacy
Last updated 24 August 2026.
The short version: Modavio stores your account identity, your key hashes, and a metered record of each request. It does not store your prompts or the model’s replies.
What is stored
- Account — the identifier, email and display name supplied by ChatGPT sign-in.
- API keys — a SHA-256 hash, a non-secret prefix, and the last four characters. Never the key itself.
- Usage records — timestamp, request id, requested route, delivered model, token counts, cost and status.
- Ledger and payments — credit purchases, reserves, settlements and releases.
What is not stored
- Message content, system prompts, tool definitions or model responses. These are relayed and not retained.
- Card details. Payments are handled by Stripe; Modavio receives only a session reference and an amount.
What is forwarded
The content of your request is forwarded to the upstream Fleet in order to answer it, together with Modavio’s own server-side credential. Your Modavio key is never forwarded, and the upstream credential is never returned to you. Unrecognised fields in your request body are dropped rather than relayed.
Logging
Operational logs are structured and redacted: values that look like credentials or hashes are masked before a line is written. Upstream error text is truncated and redacted before it appears in any log or response.
Retention and deletion
Ledger entries are append-only and retained for financial-record purposes. To request deletion of an account and its usage history, contact the operator through the account you signed in with.
Third parties
Sign-in is provided by OpenAI (ChatGPT), payments by Stripe, and hosting by Cloudflare. Each processes data under its own privacy policy. Modavio runs no analytics or advertising trackers.