> ## Documentation Index
> Fetch the complete documentation index at: https://docs.sqwish.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Data residency

> Where a request goes, which machines see it, and what is kept afterwards.

DecisionOne is run by Sqwish Labs in the United Kingdom. The [privacy page](https://console.sqwish.ai/privacy) is the list of what is collected and how long it is kept. The [terms](https://console.sqwish.ai/terms) say you own what you send, and that an answer is a probability you choose what to do with. This page is the path of one request.

## Where a request goes

A call to `https://console.sqwish.ai` uses TLS. Cloudflare's network is in front of the API. Its tunnel carries the request, encrypted, to the API, and it does not store the body.

The API sends the request to a GPU that can serve the model you asked for. That hop is on the private network. A caller on the public internet cannot open a connection to a GPU. The GPU reads the context and the questions, returns a probability for each allowed answer, and sends that score back to the API.

The models are decision models in five sizes, from Fat to Dot. The place of the caller does not choose the GPU. A pool serves the sizes it has ready, in Europe where a GPU provider there can take the work. If no pool can serve the model you asked for, the call fails in the usual way. Read `error.retryable` in [API behavior](/api#what-does-this-status-code-mean). Serving a smaller size when the one you asked for is down is a different switch. That is [fallback](/guides/models-and-fallback). The answer's `model` field is the size that scored it.

## What happens to the text

You own the context, the questions and the files you upload. You allow Sqwish Labs to store and process them to run the service for you. They are not used to train the models offered to anyone else. A model fine-tuned on your data can be called only by your account.

With `store` left off, the API answers and discards the content. The playground always leaves `store` off, and it refuses a request that asks to keep one.

Set `store: true` when you want a learning copy, so you can send feedback on that decision later. The copy and the feedback are deleted after 90 days. A dataset you have already built from that feedback is a dataset, and it follows the dataset rule below.

## What is kept, and where

| What | Where it lives | How long |
| - | - | - |
| The content of a request, when `store` is off | Not kept after the answer | Discarded once the score is returned |
| A kept decision and its feedback, when `store: true` | The learning copy for your account | 90 days, then deleted |
| Counts of decisions and tokens, by day and model, with response times and error rates | The usage page, and the basis of a bill | Daily totals stay with the account |
| Request metadata: id, time, endpoint, requested and served models, outcome, fallback or error, decision and token counts, server time | Recent history | 90 days. This record has no prompt and no answer |
| A dataset you upload, and a model fine-tuned on it | Your account | Until you delete it, or until the account is closed |
| Server logs: IP address, browser details, time | The API hosts | Used to keep the service secure and to apply rate limits |
| HTTP-only session, access, refresh and CSRF cookies, and a browser identifier | Your browser | Keep you signed in, protect browser requests and prevent referral abuse. There are no advertising or analytics cookies |

A successful answer can also be returned again for the same `Idempotency-Key` and the same body, for 24 hours, so a retry does not run or charge a second time. That replay is not the learning copy. After 24 hours the key will not run the decision again. [API behavior](/api) is that rule. [Feedback](/guides/feedback) is the learning copy.

## Who else handles it

Each provider does one job, under contract:

| Provider | What it does | Where |
| - | - | - |
| Cloudflare | The network in front of the API | In front of the service |
| DigitalOcean | The API servers, and database backups | Servers in the Netherlands |
| Microsoft Azure | Encrypted file backups | United Kingdom |
| Temporal | Fine-tuning, labelling and prompt-tuning jobs | The job runner |
| GPU providers | Running the models | In Europe where that is possible |
| Supabase | Verifying your email, and the administrator authenticator | The sign-in service |
| Stripe | Payments, receipts, refunds and saved payment methods | The payment service |
| Resend | Account and service emails | The email service |

Prompt tuning and teacher labelling send the rows for that step to the language model provider doing the work. Today that is Microsoft Azure or DigitalOcean.

Personal data is not sold. Some of these providers process data outside the United Kingdom and the European Economic Area. Where they do, the basis is an adequacy decision or standard contractual clauses.

## Closing an account, and backups

Account data stays while the account is open. After you close it, it is deleted within 30 days, except what the law requires to be kept.

Backups are encrypted and are used only to recover the service. A monthly copy is kept for 12 months, so something you deleted can remain in a backup for up to a year.

The terms make no promise of uptime unless that is agreed in writing. They are governed by the law of England and Wales.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.