docs

Data retention

What the API keeps

Read from the code that writes the data, not from a policy written beside it. Every window on this page is this deployment's own setting, read when you opened it.

A request to the API (chat completions, messages, responses, embeddings, images, audio) writes no prompt and no answer to Antimatter's database unless you ask it to. What is kept is the bill: model, token counts, cost and timings.
The response cache (10 minutes), resumable streams (10 minutes) and flight recorder capture (24 hours by default) hold content, each switched on by you, per request or per key, and each swept when its window ends.
The /chat playground saves your threads, batch jobs keep their lines and answers, and the Telegram bot keeps a short history. Each is below with how long and how to remove it.

Where your content can be stored

Everything in Antimatter that can hold the text of a prompt or an answer. Nothing else does: no log line prints a prompt, and there is no analytics script on the site.

Response cache

A hash of the request and the answer it got. Not the prompt.

when
A request sends x-antimatter-cache: on. Non streaming requests only, never on your own provider key.
kept
10 minutes, then swept. The prefix index beside it holds hashes only, 30 minutes.
remove
Do not send the header. Entries expire on their own; they are keyed by hash, so erasure cannot find them and they age out instead.

Semantic cache

An embedding of the prompt and the answer.

when
Off on this deployment: no embedding model is configured.
kept
30 minutes, then swept.
remove
Leave it off on the key. Erasure deletes your rows.

Resumable streams

The streamed answer, so a dropped connection can pick up where it left off. Not the prompt.

when
A keyed streaming request sends x-antimatter-resumable: 1.
kept
10 minutes after the last write, then swept.
remove
Do not send the header. Erasure deletes them.

Flight recorder capture

The full request body and the full answer, for replay and debugging, up to 128 KiB each.

when
You turn capture on for a key on the dashboard. Off for every key until then; never for anonymous or keyless traffic.
kept
24 hours by default, set per key from 1 hour to 30 days. A change to the window, shorter or longer, applies to what is already stored.
remove
Delete a capture, or erase the account. Turning capture off stops new captures; the ones already taken stay until their window ends.

Playground threads

Your messages in /chat and the reply to each.

when
Always, while you use /chat: the page saves the thread so it is there when you come back.
kept
Signed in: until you delete the thread. Anonymous: 30 days after the last message.
remove
Delete the thread in /chat, or erase the account. The API never writes here.

Batch jobs

The uploaded JSONL file, each line's request and each line's answer.

when
You create a batch through /v1/files and /v1/batches.
kept
No window yet: until the account is erased.
remove
Deleting the input file removes the upload, but each line's copy of its request and its answer stay with the batch until erasure. A batch made with an organization's key stays with the organization.

Telegram

The recent conversation with the bot: your messages and its replies.

when
You link a Telegram chat to your account.
kept
The last 12 messages, each for at most 24 hours after it was sent, and each cut at 8,000 characters.
remove
/new or /unlink in the chat, or erase the account.

Shares, saved prompts, presets

What you chose to save or share.

when
You save or share it.
kept
Until you delete or revoke it.
remove
Delete or revoke it, or erase the account.

What is kept about requests

No text, but enough to bill, rate limit and answer for the service. Windows of zero mean the record is not swept.

  • Usage records: per request, the model, token counts, cost, status, timings, the key, the upstream's error message when there was one (cut to 200 characters) and, if you send one, your x-antimatter-session label. No prompt, no answer, no IP address. Kept 400 days.
  • Traces: the same metadata as spans, for the flight recorder and OpenTelemetry export, with any error message cut to 500 characters. Kept 7 days. This deployment pushes them to no collector.
  • Autopilot decisions: which world was chosen and why, for signed in accounts. Kept 30 days.
  • Sign in: your wallet address is your account. Sessions last 30 days. The IP address of a sign in is kept only as a keyed digest, for the abuse rules, and pruned 30 days after it was last seen.
  • Rate limits: an anonymous request is counted against its IP address. Where the operator shares the limiter between instances, that address is written to the database as the counter's key for the length of its window, about a minute.
  • Audit log: notable acts on an account (a key minted, a deposit claimed, a member invited) with the IP address that made them, in plain text. Not swept on this deployment: it is the account's own record, and it is in the export.
  • The ledger: deposits, charges and credits. Kept for good, because money has to add up; erasure detaches it from you.

What the upstream sees

A prompt has to reach a model to be answered. It goes to the upstream that serves the world you chose: OpenRouter and the model's maker behind it, or OpenAI or Anthropic directly where the operator connected them. Their retention and training policies apply to what they receive, under the operator's account with them, or under yours when you bring your own provider key.

Antimatter does not send a no training or zero retention flag on your behalf, and it removes routing fields such as provider from requests before they leave, so one cannot be passed through either. Read each maker's policy before sending what you would not want kept.

Export and erasure

The dashboard exports everything held about your account as one file. Erasing the account deletes your threads, keys, captures, traces, autopilot decisions, personal batches, resumable streams, Telegram link and history, shares, prompts, presets, settings and the digests of your sign in addresses. Keys of an organization are revoked, and its batches stay with it. A thread written in /chat before you signed in was never tied to the account; it goes 30 days after its last message.

What stays, and why: ledger rows and usage records stay with your identity cut from them, because the books and the operator's margin have to add up; audit rows of your own acts lose your identity and their address, while a row of an admin acting on the account keeps the account's number. Transaction references stay so a deposit cannot be claimed twice. The free allowance already spent, an open abuse flag or a freeze, and a referral stay under a SHA-256 digest of the wallet address so erasing refills nothing; the digest is not keyed, so anyone who knows the address can match it. A response cache entry cannot be found by account and ages out within 10 minutes, plus the hour the sweep may take. A funded account is told what it forfeits before it can be erased.

How windows are kept

An hourly sweep deletes what has passed its window, so a row can outlive it by up to an hour. The operator sets these windows; the numbers here are the ones in force now. For what each request costs, see pricing; for the headers named here, the docs.

Antimatter