Legal

Privacy policy

What we collect, and the rather longer list of what we do not. Every line here is written against what the platform actually does, not what a template says.

Last updated 10 September 2026

The short version

A summary, so you know what you are reading. The sections below are the ones that count.

  • We keep no prompts and no model responses. The request log is metadata only.
  • No analytics, no advertising trackers, no session recorders. None, on any page.
  • Two cookies, both for staying signed in, both set only after you sign in. That is why there is no consent banner.
  • Your records live on infrastructure in Pakistan. Inference on Global routes runs outside it; PK NPU-native routes do not.
  • We do not train on your data, and we do not sell it.
01

Who we are

paranine (“P/9”, “we”) operates the P/9 gateway: an OpenAI-compatible API in front of open-source models, run from Pakistan and billed in rupees. This policy covers this website, the documentation site and the platform dashboard.

We are based in Pakistan. For anything on this page, including a request to see, correct or delete what we hold, write to info@paranine.com.

02

What we do not do

It is shorter to start here, and each of these is a statement about the code rather than an intention.

  • We do not keep your prompts or the model’s replies. They are not written to the request log. The gateway records metadata about a request, never its content.
  • We do not train models on your data. We could not do so from the request log even if we wanted to, because the text is not in it.
  • We run no analytics and no advertising trackers. There is no Google Analytics, no tag manager, no product-analytics SDK, no session recorder and no advertising pixel on any page of this site.
  • We do not sell your data, and we do not share it for anyone else’s advertising.
  • We do not read your API traffic for any purpose other than serving and billing it.
03

What we collect

Account details
If you sign in with Google, we receive the profile details carried in your Google sign-in token: your name, your email address and your profile picture. If your account was provisioned directly instead, we hold the email address it was created with and the password set for it. You also choose an organisation name and a project name.
Request metadata
For each API call: the time, the route you asked for and the model that served it, the project and the API key used, the endpoint and method, the HTTP status and termination reason, latency and time-to-first-token, token counts, cost in rupees, whether the call ran on your own provider key, the calling client’s user-agent string, and any X-P9-Meta-* tags you attach yourself. This is what the dashboard shows you under Logs.
Administrative events
Sign-ins, API key creation and revocation, renames and credit deposits, recorded with the acting user and a best-effort source IP address. This log is append-only, so that you can audit your own organisation.
Billing records
Credit added to your balance and spend settled against it.
What you send us
If you fill in an enquiry form or email us, we keep what you wrote and your contact details so we can reply.

Your prompts and the model’s responses are not in any of the above. If you need a record of them, keep it on your side.

04

Cookies, and why there is no banner

This site sets two cookies, and only after you sign in: p9_access_token and p9_refresh_token. They hold your session, which is the only thing they do. Signed out, browsing the marketing pages, the blog or the documentation, this site sets no cookies at all.

Both are strictly necessary: without them you could not stay signed in. Consent rules in the jurisdictions that have them exempt exactly this category, which is why you are not being asked to dismiss a banner. If we ever add a cookie that is not strictly necessary, we will ask first, and this section will say so.

The dashboard playground also keeps the API key you paste into it in your browser’s session storage, so it does not ask again on every reload. That stays in your browser and is cleared when you close the tab.

Signing out clears the session cookies. You can also clear them in your browser at any time; the only effect is that you will be signed out.

05

Where your data is held

The gateway, the control plane, the request telemetry, the activity log and the billing records run on infrastructure in Pakistan. Your keys, your organisation’s records, every request’s metadata and every billing record are processed and stored there.

Where the inference itself runs depends on the route. Routes marked PK NPU-native serve from Ascend NPUs inside Pakistan. Routes marked Global pass through to upstream providers outside Pakistan, which means the content of those requests leaves the country and is handled under that provider’s own terms. The catalogue marks which pool every route belongs to, and the data residency guide sets it out in full.

If a workload must not leave Pakistan, use PK NPU-native routes. That is a choice you make per route, and the catalogue tells you which is which.

06

Who else touches it

The complete list of third parties involved in running this site and platform.

Google
Only if you choose to sign in with Google. Google sends us a signed token saying who you are: your name, email address and profile picture. It is an identity token and nothing more, so it gives us no access to your Gmail, your Drive or anything else in your Google account, and no ability to act there on your behalf.
Resend
Our email delivery provider. When you submit an enquiry form, the contents are sent through Resend so they reach our inbox.
A spreadsheet
Enquiries are also appended to a spreadsheet we keep, so a request does not get lost in a mailbox.
Upstream model providers
For routes in the Global pool only, and only the content of that request, in order to serve it. PK NPU-native routes do not involve them.

There is nobody else. In particular there is no advertising network, no data broker and no analytics vendor in this list, because there is none in the product.

07

How long we keep it

Account records, organisation details and billing records are kept for as long as your organisation exists with us, and afterwards for as long as we need them to meet tax and accounting obligations.

Request metadata and activity events are kept so that you can audit your own usage and so that we can bill accurately and investigate faults.

We have not fixed a retention window for telemetry yet. Rather than publish a number we do not hold ourselves to, we are saying so plainly: when the window is set, it will be stated here and the date at the top will change. In the meantime you can ask us what we hold about your organisation, and ask us to delete it.

08

Your choices

Write to info@paranine.com and we will act on any of the following. We will confirm you control the account before we do, and we will not charge you for it.

  • Ask what we hold about you or your organisation, and get a copy of it.
  • Correct anything that is wrong.
  • Delete your account and its data. Note that this ends the service: without an organisation record there is no balance and no keys.
  • Ask us to stop emailing you. We send no marketing email you have not asked for.

You can also revoke any API key yourself from the dashboard at any moment. Revocation takes effect on the next request made with that key.

09

Security

The site is served over HTTPS only and instructs browsers to refuse an unencrypted connection. API keys are shown once, at creation, and only a SHA-256 hash of the key is stored: we cannot recover a key for you, only issue a new one and revoke the old.

No system is beyond compromise, and we will not pretend otherwise. If a breach affects your data, we will tell you what happened, what was affected and what we did about it, without waiting to be asked.

If you find a security problem, please write to info@paranine.com before disclosing it publicly. We will not pursue anyone who reports a genuine issue in good faith.

10

Children

This is a product for businesses and developers, and it is not directed at children. We do not knowingly collect data from anyone under 18. If you believe a child has created an account, tell us and we will remove it.

11

Changes to this policy

When this policy changes, the date at the top of the page changes with it. If a change materially affects what we collect or who we share it with, we will tell account holders directly rather than relying on you to re-read the page.

This policy is governed by the laws of Pakistan. If you use P/9 from somewhere with its own data protection law, that law may give you rights this page does not list; nothing here is meant to take them away.

Questions about anything on this page: info@paranine.com. The other documents are Privacy, Terms and Refunds.