Legal & Trust Center
BYOK Data Handling
Version 1.0 describes how Ethen works today. It has not yet taken effect: passages shown in italics are still being decided, and the document will show an effective date once it is final. Earlier text is listed in the version history.
This document explains bring-your-own-key (BYOK) in Ethen. BYOK means using your own account with an AI Model Provider, authenticated by an API key you supply, instead of Upcube's account. It covers the current availability of BYOK, how Ethen is designed to store and use customer keys, how requests are routed, who bills and retains what, and who is responsible when something goes wrong. Above all, it explains what BYOK does not change. It applies to individuals and Organizations considering BYOK. Read it with the Privacy Policy and the Subprocessors list.
On this page
- Current availability
- What BYOK is, and what it is not
- How Ethen is designed to store your key
- How requests are routed
- Billing
- Provider logging, retention and terms
- Questions to settle with your provider before using BYOK
- Supported providers
- Rotating and revoking keys
- If a key is exposed
- Organizations
- Responsibilities at a glance
- Related policies
- Contact
- Version history
Current availability
BYOK is not currently available in Ethen. Every model request in Ethen Chat and Ethen Studio today is sent using Upcube's own accounts with Model Providers, either directly or through a routing service. Ethen has no screen for entering your own provider key, and the secure key-storage system described below is not switched on in production.
This document describes how BYOK is designed to work, so that you can evaluate it before it is released. When BYOK becomes available, this document will be updated to describe the released behavior, including the providers it supports, before you can use it.
What BYOK is, and what it is not
With BYOK, you give Ethen a credential for your own account with a Model Provider. When you use a model covered by that credential, Ethen sends the request to the provider using your key instead of Upcube's. The provider then treats the request as yours: it bills your account, applies your account's settings, and handles the data under your agreement with it.
BYOK changes whose provider account a request runs through. It does not change how Ethen itself handles the request. In particular, none of the following shortcuts is accurate:
- "BYOK means zero retention." It does not. Ethen still stores your conversations as described in the Data Retention Policy, and the provider retains data according to your agreement with it.
- "BYOK means fully private." It does not. Your Prompts still pass through Ethen's servers, which add conversation context, apply safety and usage controls, and save the result.
- "BYOK means Ethen never processes my request." It does not. Ethen receives your Prompt, builds the request, sends it to the provider and receives the Output, as it does for every request.
How Ethen is designed to store your key
The BYOK design follows these rules:
- Server-side only. You enter your key in Ethen's settings, and it is sent to Ethen's servers. It is never stored in your browser or included in pages Ethen sends to you.
- Held in a managed credential vault. The key itself is stored in a dedicated secrets vault, not in Ethen's ordinary database tables. Ethen's database keeps only a reference to the vault entry, an optional label, and the first and last few characters of the key, so you can recognize it. Ethen refuses to accept new keys when no vault is configured; this is one reason BYOK is not available today.
- Used only to authenticate your requests. Ethen retrieves the key on its servers at the moment it calls the provider for your request, and uses it only for that purpose.
- Not shown again. After you save a key, Ethen shows only its label and partial characters, not the full key.
Upcube staff with privileged access to Ethen's production systems could, in principle, use those systems to retrieve stored keys. Access to production systems is limited, as described in the Enterprise Security document. If your organization's rules do not allow a third party to hold your provider key, do not use BYOK.
How requests are routed
When BYOK is available and you use a model covered by your key:
- You send a Prompt in Ethen.
- Ethen's servers authenticate you, apply usage and safety controls, and add the conversation context needed for the request.
- Ethen sends the request to the provider, authenticated with your key.
- The provider processes the request under your account and returns the Output.
- Ethen shows you the Output and saves it in your conversation, as for any request.
Models and features not covered by your key continue to use Upcube's accounts. Supporting services that do not involve your key, such as web search, are unaffected by BYOK.
Billing
When a request runs on your key, the Model Provider bills your account directly under your agreement with it. Those charges are separate from anything Upcube charges, and Upcube does not refund them. Ethen does not currently charge for use; if paid plans are introduced, the Refund & Cancellation Policy will explain how BYOK usage interacts with Ethen pricing.
Set spending limits and alerts in your provider account. Ethen's own usage limits do not cap what your provider can bill you.
Provider logging, retention and terms
When your key is used, the provider handles the request under your agreement with it. That agreement determines:
- whether and for how long the provider logs or retains requests;
- whether the provider may use them for abuse monitoring or other purposes;
- which data-processing terms, data-residency options and zero-retention features you have arranged.
Upcube does not control these settings and cannot change them for you. Review your provider's terms before using BYOK, and configure your provider account to match your requirements.
Questions to settle with your provider before using BYOK
BYOK places your agreement with the Model Provider at the center of how your data is handled. Before you use it, confirm with your provider:
- whether requests and outputs are logged, for how long, and who can access the logs;
- whether the provider may use your requests to train or improve its models, and how to opt out;
- whether zero-data-retention or modified-abuse-monitoring options are available to your account, and whether they apply to the models you will use;
- where requests are processed, and whether you can restrict the region;
- what data-processing terms apply to your account;
- how spending limits and alerts work, and how quickly a key can be revoked.
Ethen does not change any of these settings. They apply to requests made with your key as they would to any other use of your provider account.
Supported providers
No providers are supported for BYOK today, because BYOK is not available. When it launches, this section will list each supported provider and the models a key unlocks.
Rotating and revoking keys
When BYOK is available, you will be able to replace or remove a stored key in Ethen's settings. Removing a key stops Ethen from using it for new requests.
To be sure a key can no longer be used anywhere, revoke it in your provider account as well. That is the only step that invalidates the key itself. Rotate keys regularly, and immediately if you suspect exposure.
If a key is exposed
If you believe a key you gave Ethen has been exposed or misused:
- Revoke the key in your provider account. This stops all use immediately.
- Remove it from Ethen and add a new one if you want to keep using BYOK.
- Review recent usage and billing in your provider account.
- Tell us through the contact options in the Legal & Trust Center if you believe the exposure involved Ethen.
If Upcube becomes aware of a security incident affecting stored keys, it will act as described in the Enterprise Security document.
Organizations
When Organization features and BYOK are both available, an Organization's administrators are expected to be able to supply keys for a Workspace and decide which models members may use with them. Members using a Workspace key will be using the Organization's provider account, under the Organization's agreement with that provider. The Organization is responsible for managing those keys and the terms that apply to them.
Responsibilities at a glance
| Upcube | You (or your Organization) | The Model Provider | |
|---|---|---|---|
| Storing the key securely in Ethen | Yes | — | — |
| Keeping the key secret before it is entered, and revoking it if exposed | — | Yes | — |
| Ethen's handling and retention of conversations | Yes | — | — |
| Provider-side logging, retention and data use | — | Through your agreement with the provider | Yes |
| Charges for requests made with your key | — | Yes | Bills you |
| Spending limits and alerts | — | Yes, in your provider account | Provides the controls |
Contact
Dedicated contact channels for privacy, security, legal, support and abuse reports are being set up and will be listed here before Ethen's policies take effect.
Version history
| Version | Date | Status | Summary of changes |
|---|---|---|---|
| 1.0 | October 5, 2026 | Not yet in effect | States that customer BYOK is not currently available and describes the designed key-handling model and its limits. |
| 0.9 | September 2026 | Superseded | Earlier public-preview text. Archived. |