Data policy
What Line Three will keep: no content.
The policy Line Three holds itself to. Amazon Bedrock, the model provider, follows AWS’s own terms, quoted under Where your request is processed.
The short version
- Your promptsNot kept.
- The answersNot kept.
- Training by Line ThreeNever.
- KeptAccount, billing, keys, usage records. Full list.
-
What passes through
When you call Line Three, your request will carry your key, the model you chose, and the messages you send. The answer will carry the model’s reply. Both will pass through Line Three’s gateway and through Amazon Bedrock, the AWS service that runs the model that answers. Line Three’s gateway and its usage records run in Asen Technology’s own AWS account, in the AWS US West (Oregon) Region (us-west-2), the same region where Amazon Bedrock answers your requests. The gateway calls the Amazon Bedrock Runtime API (bedrock-runtime) there, using in-region inference, not cross-region inference profiles, so requests are processed in that one region. Besides AWS, no other company is in Line Three’s request path, apart from DNS and certificate providers, which never see request content. No third-party CDN will be in the request path.
Some editors relay your request through the editor maker’s own servers before it reaches the endpoint you set. If yours does, that company is in your request path too. Check your tool’s documentation.
-
Where your request is processed
In the United States. Line Three is designed to send every request to Amazon Bedrock in the AWS US West (Oregon) Region (us-west-2), through the Amazon Bedrock Runtime API (bedrock-runtime), using in-region inference, not cross-region inference profiles. The statements below are AWS’s statements about that service; the logging one applies specifically to the bedrock-runtime endpoint Line Three will call.
What AWS states about Amazon Bedrock. These are AWS’s terms, not Line Three’s promises:
- By default, Amazon Bedrock does not store model inputs or outputs, and no operators of the service can access them. AWS lists the models whose traffic it may keep for up to 30 days for abuse detection; none of Line Three’s launch models is on that list. AWS may also store and review image inputs flagged as apparent child sexual abuse material; Line Three’s launch models take text only. AWS: Amazon Bedrock abuse detection (another website)
- The model providers, such as OpenAI and NVIDIA, have no access to Amazon Bedrock logs or to prompts and completions. AWS: Amazon Bedrock data protection (another website)
- AWS and the model providers do not use Amazon Bedrock inputs or outputs to train models. AWS: Amazon Bedrock FAQs (another website)
What Line Three commits to. Line Three will not turn on Amazon Bedrock’s model invocation logging. AWS leaves it off by default, and it covers calls through the bedrock-runtime endpoint, which is the one Line Three will use (AWS: model invocation logging (another website)). Line Three will use only models that are not on AWS’s list of models whose traffic it may keep for abuse detection; each model’s AWS page lists abuse detection as not supported on bedrock-runtime. If AWS changes how it retains data for a model, we stop routing to that model at once and tell you within 2 business days.
Model ids: you send Line Three’s ids (openai.gpt-oss-120b, nvidia.nemotron-super-3-120b, nvidia.nemotron-nano-3-30b); the gateway is designed to send AWS’s bedrock-runtime id for each, as listed on each model’s AWS page.
A CUI tier on AWS GovCloud (US) is planned. Until it exists, do not send CUI.
-
What we keep
Line Three will keep what it needs to run an account, bill for it and keep it secure, and nothing else:
Records Line Three will keep, and for how long Record What it holds Kept for Account Your organization’s name and the contact details of its administrators. While the account is open, then as billing law requires Billing Prepaid credit, balances and refunds, monthly caps, monthly charges, payments, purchase orders and invoices. As tax and billing law requires Keys Each key’s name and a one-way hash of the key. The key itself is shown once and never stored. Until you delete the key Usage For each request: the time, the key, the model, tokens in and out, and the response status. 13 months, for billing disputes, or 90 days if your administrator chooses Connection logs The source IP address and time of each connection, to the API and to this website. 30 days, for security Contact-form messages What you typed into the contact form, the time it arrived and its reference number. 13 months, then deleted automatically Line Three is designed to store no prompt or response content: not in logs, not in backups, not for debugging. Key names will appear in usage records, so name keys with a code, not a client, patient or matter name.
Each month your administrators can download a CSV file for each key, or one for all keys, with one row per day and model: the date, the key’s name, the model, tokens in, tokens out and the cost. When you close your account, you can export your usage records first, and we delete them, with every key name, within 30 days. Invoices and payment records are kept only as tax and billing law requires.
-
Training
Line Three will never use your prompts or answers to train or improve a model, and will keep none to train on. AWS’s own statement on training is under Where your request is processed.
-
Who can see what
Your account administrators will see your keys and your usage. At Line Three, every administrative account will use multi-factor authentication, and every access to account, billing and usage records will be written to an append-only access log, available on request for your own review. The content of your requests will only pass through the gateway. No one at Line Three reads it; the gateway decrypts it in memory only to forward it. Afterwards there is nothing to see, because we won’t keep it.
-
Subprocessors
Every subprocessor, what it does and where Who What it does Where Amazon Web Services (AWS) Hosting for Line Three’s gateway and usage records, in Asen Technology’s own AWS account, and model inference through the Amazon Bedrock Runtime API. US West (Oregon) Card payment processor, named at launch Card payments only. It never sees prompts or answers. Named with the processor Email provider for contracting@ and notices@, named at launch Carries mail to and from those two addresses only. It never sees API requests or form messages. Named with the provider None: Asen Technology’s own servers This website, the contact form and the alerting that tells a person a message has arrived run on servers Asen Technology owns and operates itself. No hosting company is involved, and no third party receives what you write in the form. United States We are responsible for our subprocessors’ handling of your data as if it were our own. We give account administrators 30 days’ notice before we add or replace a subprocessor. If you object, you can end the agreement before the change takes effect.
-
Data processing summary
The data processing agreement (DPA) terms, in plain words. They are part of the Terms; a signed DPA comes with any negotiated agreement.
- Roles
- Your organization controls its data. Line Three processes it only to answer your requests, run your account and bill you.
- Instructions
- We process your data only as the Terms, this policy and your use of the API direct.
- Content
- Prompts and answers will pass through and will not be stored. The records we keep, and for how long, are under What we keep.
- Subprocessors
- Listed above, with 30 days’ notice of any change, a right to object, and our responsibility for them.
- Security
- Multi-factor authentication on every administrative account, an append-only access log, and encryption in transit on every hop.
- Breach notice
- Within 72 hours of confirming an incident that affects your records, and no later than 7 days after discovering it.
- Legal demands
- At least 7 days’ notice where the law allows; the full rules are under Legal requests.
- Location
- The United States, for Line Three’s gateway, records and this website. The card processor and email provider are in the table above.
- At the end
- Export your usage records, then we delete them, with every key name, within 30 days. Details under What we keep.
- Evidence
- Ask for the evidence behind any statement here and we answer in writing. No on-site audits.
-
Legal requests
If Line Three receives a legal demand for customer data, it can produce only what it will keep: the records listed under What we keep. AWS’s records are governed by AWS’s terms.
What you should keep yourself. If you need a record of what was sent or received, for public-records law, a litigation hold or your own file, keep it on your side. Line Three won’t have it.
- What we can disclose
- Only what we keep: the records listed under What we keep. We will keep no prompts or answers, so we will not be able to disclose them.
- Notice to you
- If an authority demands your information, we give you at least 7 days’ notice before we respond, where the law allows it, and ask the authority to seek it from you directly. At your request, we assert any privilege you hold. AWS may receive demands directly, under its own terms. If we are barred from telling you at first, we tell you once the bar ends.
- Challenging demands
- We disclose only what a valid legal demand requires. We challenge a demand that is overbroad or not legally valid.
- Foreign governments
- We refuse demands from foreign governments unless a U.S. court or U.S. law compels us to comply.
- Transparency report
- Each January, starting in January 2028, we publish a transparency report on the data policy page: how many legal demands we received for customer records in the previous year, and how many we answered.
- Governing law
- Requests are handled under U.S. law. For U.S. federal government customers, U.S. federal law governs this agreement. For state and local government customers, the law of your own state governs this agreement, and disputes go to the courts of your state. For everyone else, the Terms name the governing law.
-
Security incidents
Your notices contact is the person and email address your organization names for legal notices when it opens an account. Until it names one, notices go to your account administrators.
If we confirm a security incident that affects your records, we tell your account administrators and your notices contact within 72 hours of confirming it, and in any case no later than 7 days after we discover it: what happened, which records it touched, and what we are doing about it. We keep you updated until it is closed.
-
Changes to this policy
We publish any change here, with its date and a new version number, at least 30 days before it takes effect, and tell account administrators and your notices contact by email. A change never applies to content, because we will keep none. Questions: use the contact form.