> ## Documentation Index
> Fetch the complete documentation index at: https://docs.withmethod.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Privacy: where run data goes

> What a Method sends to the Method account, to model providers, and what stays on your computer.

A Method has a **definition** (the `.method` file and its scripts) and **runs**. A run has a **run record** (steps, status, timing, cost) and **run content** (inputs, outputs, prompts, check evidence, and result files).

Two settings control run content:

* `run_data` in the `.method` file: `account` (default) or `device`.
* **Keep run content on devices**, an organization setting on the dashboard's Account page. It is off by default. When it is on, every run in the organization works as `run_data: device`, and the Method server refuses a run record that contains content.

| Data | `run_data: account` (default) | `run_data: device`, or organization setting on |
| - | - | - |
| Definition (`.method` file, scripts, files in the package) | Saved in the Method account when you are signed in. | Same. The definition is always saved. |
| Run record (steps, status, timing, model and token counts, cost) | Saved in the Method account. | Saved in the Method account. |
| Run content (inputs, outputs, prompts, check evidence, result files) | Saved in the Method account. | Stays on the computer that ran it. The dashboard shows "Run content is kept on" that computer. |
| Hosted model requests (`call` and `agent` steps without your own key) | The step's prompt and inputs go through Method to OpenRouter and then to the model provider. | Same. A model step must send its inputs to the model. |
| Classifier requests (`classify` steps without your own key) | The step's inputs go through Method to OpenRouter and then to Typesafe (Jev). | Same. |
| Method server logs | Request ID, organization, model, status, duration, and token usage. No prompts, inputs, or outputs. | Same. |
| Local run folders | Each run writes a folder on your computer: `.method-runs/` in the project for local files (you delete these), and `~/.cache/method/runs/` for saved Methods and background runs. Secret values are replaced with `[REDACTED]` in every run file. | Same. |

## Model and classifier requests are private by default

The Method server adds two OpenRouter provider options to every hosted model request and every classifier request. A client cannot turn them off:

* `data_collection: "deny"`: only providers that do not train on or sell the request.
* `zdr: true`: only providers with zero data retention.

If no provider of the selected model meets these rules, the request stops with `model_not_private`. Choose another model. There is no per-Method opt-out at this time.

With your own OpenRouter key (`method config model-key`), every hosted model request (the Method's own models too) and every classify request goes directly from your computer to OpenRouter with your key. Your computer adds the same two options to each hosted model request. See [Pricing](/guides/pricing).

## What we checked

We checked these facts on 2026-10-09 with a test OpenRouter key:

* `deepseek/deepseek-v4.1-flash` (the default hosted model) works with both options. OpenRouter routed it to a provider that meets them.
* `openai/gpt-6-luna` works with both options.
* A model with no provider that meets the options (for example `qwen/qwen3.8-flash`) is refused by OpenRouter. Method returns `model_not_private`.
* The classifier endpoint (`/api/v1/systemone`) accepts and checks the same options. Jev 1.13 is listed by OpenRouter as a zero data retention endpoint, and requests with the options succeed.

## What we did not check

* OpenRouter's own handling of requests (its logs and retention). OpenRouter publishes its policy; Method did not verify it.
* That each provider keeps its zero data retention promise. Method relies on OpenRouter's provider list.
* Local agents (`{agent: codex}` or `{agent: claude}` models, or `--agent`) and your scripts. They send data where they are set up to send it.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.