Docs Use Eco

Privacy & keys

Where keys and data go, and what Eco keeps.

On this page

Learn where your key, messages, and route history go when you use Eco.

Bring your own key#

Eco uses your existing Orbio key and credits. There are no Eco accounts, balances, or generated Eco keys.

In the playground, Save key stores the key in this browser's localStorage. Eco does not save a server-side copy. The production website and API use HTTPS.

“Stays on your device” describes storage, not network use. Preview and chat send the key to the Eco API, which holds it for the request and forwards it to Orbio. Save checks the key's format; it does not prove that Orbio will accept it.

What stays in the browser#

DataStorage
Saved Orbio keylocalStorage for this website and browser.
Recent routesUp to 20 entries: mode, selected model, and timestamp only.
Current prompt, instructions, and replyPage memory, not localStorage.

Clear key removes the saved key. Clear history removes recent route metadata separately. Recent routes never include prompts, replies, or keys.

Avoid saving keys on shared devices. localStorage is accessible to scripts running on the same website origin.

What goes upstream#

The selected model receives the request through Orbio. When routing rules are uncertain, a classifier also receives a bounded conversation excerpt through Orbio. Preview can send that excerpt even though it does not generate your requested answer.

Eco does not log or persist prompt or completion bodies. It records limited request metadata, such as model choice, status, timing, and a truncated key hash. It does not log the raw key. The frontend has no third-party analytics installed.

These boundaries describe Eco. They do not guarantee zero retention by Orbio, model providers, or hosting infrastructure. Check their policies before sending sensitive data.

Keys in your application#

Keep the key in your application's private environment or another appropriate client secret store. Do not commit it or embed it in a public browser bundle. Eco's public API URL is configuration, not a secret.

For shared public applications, keep your application's key handling on a trusted server. The Eco playground's personal BYOK pattern should not expose one shared key to visitors.

Next: Installation & usage or FAQ.