Surp processes API requests to route AI inference, calculate prices, enforce budgets, settle optional x402 payments, and operate the service. Request metadata may include timestamps, route names, model choices, token counts, cost, response status, payer or account identifiers, and operational logs. Do not submit secrets or personal information in prompts unless the chosen model provider and your own policies permit it. Prepaid API keys are stored as protected credentials and must be kept secret by their holder. Wallet private keys are never requested or stored by Surp. Payment signatures are used only for the payment flow they authorize. Operational records are retained only as needed for accounting, abuse prevention, debugging, security, and legal obligations. Requests can pass through upstream model providers selected by the router, whose policies may also apply. Questions or deletion requests can be sent to hi@surp.ivc.lol. This page will be updated when material processing practices change.