Legal
Data retention
Since 9 October 2026, System1 Models operates under the name Decision Models (decisionmodels.io). References to System1 Models and system1models.ai in this document mean Decision Models and decisionmodels.io; nothing else changes.
Last updated: 7 October 2026
Request content (both tiers)
The Peer-to-Peer tier first uses spare EU capacity, with lower priority than EU-tier requests. When that capacity is busy, Peer-to-Peer requests may use on-demand GPU capacity rented through Lium (lium.io). Independent third-party providers operate the GPU hardware in various countries, including outside the EU/EEA. Processing outside the EU happens only for API keys whose customer has explicitly enabled the "Allow worldwide processing" switch. Without that opt-in, Peer-to-Peer requests stay on EU capacity and may be queued or rejected with a retryable error when busy. EU-tier requests always stay in the EU and have priority. Existing customers keep EU-only processing unless they opt in for the individual key. Request and response content is not stored on any node (zero payload retention). The existing 30-day sub-processor notice remains applicable.
| Both tiers | |
|---|---|
| Content of requests and responses (state, questions, images, probabilities) | Not stored. Held in volatile memory while the request runs. Never written to logs, databases, disk or other persistent storage. |
| Technical prefix cache | Intermediate values of recent requests may stay in GPU memory until overwritten by later requests, at the latest until the server restarts, to speed up similar requests. Never persisted, never readable through the API, isolated per model instance. |
| Image URLs you send | Fetched once by our gateway; neither the URL nor the image is logged |
Retry protection (optional Idempotency-Key) |
For 24 hours: a keyed (HMAC) digest of the request body, the request ID, status and usage receipt. No content, no answer. |
| Suitable for personal data | EU processing: under our DPA. Worldwide opt-in: only with an adequate transfer basis for your use; see DPA section 7 |
| Used to train models | No |
Data we keep as the service provider
| Data | Retention |
|---|---|
| Usage records (request ID, time, key ID, model, tier, token count, decisions, latency, status, price) | 13 months in detail, then aggregated per day, model and tier |
| Server and security logs with IP addresses | 14 days, longer only for individual entries needed to investigate a specific incident |
| Account data | While the account exists; deleted within 30 days after closure |
| Sign-in links | 15 minutes |
| Abuse-prevention hashes for promotional credit (only while the launch offer is active) | 24 months |
| Invoices and accounting records | 8 to 10 years as required by § 257 HGB and § 147 AO |
| Support emails | Normally 3 years after the end of the year of last contact |
| Encrypted database backups (no request content) | Rolling 30 days |
| Website statistics (cookie-free Umami; no IP addresses stored) | 24 months at most |
Details and legal bases: Privacy Policy.