Legal
Privacy policy
What we collect, and the rather longer list of what we do not. Every line here is written against what the platform actually does, not what a template says.
Last updated 10 September 2026
The short version
A summary, so you know what you are reading. The sections below are the ones that count.
- We keep no prompts and no model responses. The request log is metadata only.
- No analytics, no advertising trackers, no session recorders. None, on any page.
- Two cookies, both for staying signed in, both set only after you sign in. That is why there is no consent banner.
- Your records live on infrastructure in Pakistan. Inference on Global routes runs outside it; PK NPU-native routes do not.
- We do not train on your data, and we do not sell it.
Who we are
paranine (“P/9”, “we”) operates the P/9 gateway: an OpenAI-compatible API in front of open-source models, run from Pakistan and billed in rupees. This policy covers this website, the documentation site and the platform dashboard.
We are based in Pakistan. For anything on this page, including a request to see, correct or delete what we hold, write to info@paranine.com.
What we do not do
It is shorter to start here, and each of these is a statement about the code rather than an intention.
- We do not keep your prompts or the model’s replies. They are not written to the request log. The gateway records metadata about a request, never its content.
- We do not train models on your data. We could not do so from the request log even if we wanted to, because the text is not in it.
- We run no analytics and no advertising trackers. There is no Google Analytics, no tag manager, no product-analytics SDK, no session recorder and no advertising pixel on any page of this site.
- We do not sell your data, and we do not share it for anyone else’s advertising.
- We do not read your API traffic for any purpose other than serving and billing it.
What we collect
- Account details
- If you sign in with Google, we receive the profile details carried in your Google sign-in token: your name, your email address and your profile picture. If your account was provisioned directly instead, we hold the email address it was created with and the password set for it. You also choose an organisation name and a project name.
- Request metadata
- For each API call: the time, the route you asked for and the model that served it, the project and the API key used, the endpoint and method, the HTTP status and termination reason, latency and time-to-first-token, token counts, cost in rupees, whether the call ran on your own provider key, the calling client’s user-agent string, and any
X-P9-Meta-*tags you attach yourself. This is what the dashboard shows you under Logs. - Administrative events
- Sign-ins, API key creation and revocation, renames and credit deposits, recorded with the acting user and a best-effort source IP address. This log is append-only, so that you can audit your own organisation.
- Billing records
- Credit added to your balance and spend settled against it.
- What you send us
- If you fill in an enquiry form or email us, we keep what you wrote and your contact details so we can reply.
Your prompts and the model’s responses are not in any of the above. If you need a record of them, keep it on your side.
Where your data is held
The gateway, the control plane, the request telemetry, the activity log and the billing records run on infrastructure in Pakistan. Your keys, your organisation’s records, every request’s metadata and every billing record are processed and stored there.
Where the inference itself runs depends on the route. Routes marked PK NPU-native serve from Ascend NPUs inside Pakistan. Routes marked Global pass through to upstream providers outside Pakistan, which means the content of those requests leaves the country and is handled under that provider’s own terms. The catalogue marks which pool every route belongs to, and the data residency guide sets it out in full.
If a workload must not leave Pakistan, use PK NPU-native routes. That is a choice you make per route, and the catalogue tells you which is which.
Who else touches it
The complete list of third parties involved in running this site and platform.
- Only if you choose to sign in with Google. Google sends us a signed token saying who you are: your name, email address and profile picture. It is an identity token and nothing more, so it gives us no access to your Gmail, your Drive or anything else in your Google account, and no ability to act there on your behalf.
- Resend
- Our email delivery provider. When you submit an enquiry form, the contents are sent through Resend so they reach our inbox.
- A spreadsheet
- Enquiries are also appended to a spreadsheet we keep, so a request does not get lost in a mailbox.
- Upstream model providers
- For routes in the Global pool only, and only the content of that request, in order to serve it. PK NPU-native routes do not involve them.
There is nobody else. In particular there is no advertising network, no data broker and no analytics vendor in this list, because there is none in the product.
How long we keep it
Account records, organisation details and billing records are kept for as long as your organisation exists with us, and afterwards for as long as we need them to meet tax and accounting obligations.
Request metadata and activity events are kept so that you can audit your own usage and so that we can bill accurately and investigate faults.
We have not fixed a retention window for telemetry yet. Rather than publish a number we do not hold ourselves to, we are saying so plainly: when the window is set, it will be stated here and the date at the top will change. In the meantime you can ask us what we hold about your organisation, and ask us to delete it.
Your choices
Write to info@paranine.com and we will act on any of the following. We will confirm you control the account before we do, and we will not charge you for it.
- Ask what we hold about you or your organisation, and get a copy of it.
- Correct anything that is wrong.
- Delete your account and its data. Note that this ends the service: without an organisation record there is no balance and no keys.
- Ask us to stop emailing you. We send no marketing email you have not asked for.
You can also revoke any API key yourself from the dashboard at any moment. Revocation takes effect on the next request made with that key.
Security
The site is served over HTTPS only and instructs browsers to refuse an unencrypted connection. API keys are shown once, at creation, and only a SHA-256 hash of the key is stored: we cannot recover a key for you, only issue a new one and revoke the old.
No system is beyond compromise, and we will not pretend otherwise. If a breach affects your data, we will tell you what happened, what was affected and what we did about it, without waiting to be asked.
If you find a security problem, please write to info@paranine.com before disclosing it publicly. We will not pursue anyone who reports a genuine issue in good faith.
Children
This is a product for businesses and developers, and it is not directed at children. We do not knowingly collect data from anyone under 18. If you believe a child has created an account, tell us and we will remove it.
Changes to this policy
When this policy changes, the date at the top of the page changes with it. If a change materially affects what we collect or who we share it with, we will tell account holders directly rather than relying on you to re-read the page.
This policy is governed by the laws of Pakistan. If you use P/9 from somewhere with its own data protection law, that law may give you rights this page does not list; nothing here is meant to take them away.
Questions about anything on this page: info@paranine.com. The other documents are Privacy, Terms and Refunds.