Provider disclosure
Every outside hand on the path.
A provider appears here because it can touch a request, an account, a payment, or an operational error - not because its logo belongs in a trust strip.
Provider matrix
| Provider | When invoked | What it can receive | What it does not receive |
|---|---|---|---|
| Cloudflare | Every hosted request | Network and request metadata needed to serve the site; server API payloads for optional lanes | Free local-Read writing |
| Clerk | Only when accounts are configured or used | Authentication, session, and account data | Free local-Read writing and source-free analysis results |
| Polar | Only for paid access or checkout | Checkout, customer, subscription, and entitlement data | Writing, evidence cards, and model output |
| OpenRouter | Only after explicit model-comparison consent | The previewed bounded evidence bundle and routing metadata | The raw whole document and account payment data |
| Selected inference provider | Only through the one pinned OpenRouter request | The same bounded request needed to produce the selected comparison | Fallback traffic, tools, plugins, and unpreviewed document context |
| Sentry | Only for configured server-side errors | Error type, route, environment, release, and source-free operational context | Request bodies, browser-local writing, account identity, and client-session replay |
Model route contract
The browser cannot choose a provider route, prompt, or fallback. The server selects an audited profile, makes one non-streaming attempt, requests no provider data collection, and accepts output only when its cited evidence and provider receipt pass local validation. Provider status is NOT ASSESSED if the live route doctor has not executed.
Retention claims
Phraseless can constrain what it sends and what it stores itself. It cannot convert a provider’s policy into a broader factual guarantee. Zero Data Retention and no-training labels therefore apply only to the exact verified route and time window named in a receipt. If that receipt is absent or stale, the feature stays unavailable or reports NOT ASSESSED.
Edge-log receipt
Status: NOT ASSESSED
Cloudflare’s controlled application, edge, access-log, and observability stores have not yet produced a witnessed receipt proving the absence of retained IP, account, stable device, and source-derived values. Until then, Phraseless does not call free feedback anonymous.