Last updated: July 13, 2026
Northern Inference Inc. ("we", "us", "our") is a Canadian company committed to data privacy and transparency. This policy covers both our website (northerninference.ca) and our API platform. We explain what data we collect, where it goes, and what your rights are.
Account and identity data:
API usage data:
Website and portal analytics:
Support data:
Our core product is routing inference requests to LLM providers. Where your data goes depends on the model route you select per request:
| Tier | Provider | Data Location | Jurisdiction |
|---|---|---|---|
| Tier 1: Self-Hosted Hardware (coming soon) | Your hardware, routed by NI | Your premises; prompts never leave your site | Yours |
| Tier 2: Sovereign Hardware (coming soon) | NI-owned, single-tenant bare metal | Canadian-owned data centre; no US-owned cloud in the path | Canada |
| Tier 3: Managed Cloud (live) | AWS Bedrock / Azure OpenAI in Canadian regions | Canada (ca-central-1 / Canada East); enforced at the routing layer and fails closed | Canada (US CLOUD Act applies to providers) |
| Tier 4: Global Access (live) | Provider-default and non-Canadian routes | US, EU, APAC, or multi-region; the exact route is disclosed on every response | Disclosed per request |
What Northern Inference sees: Your prompts and completions pass through our routing infrastructure in Canada (ca-central-1) in memory only, for the duration of routing. We do not persist request content by default. Chain of custody records (entity, jurisdiction, timestamp per hop, but not content) are stored for 90 days. The only ways content is stored are the three opt-in exceptions described in section 1: PII Substitution mappings (transient), the Audit and Compliance tier (redacted exchanges), and Content Debug Mode (full content, opt-in, described below).
What providers see: Each provider you route to receives your prompt and returns a completion, subject to their own privacy policies. Tier 3 providers (AWS, Microsoft) contractually commit to not using API data for training. Note that Microsoft Azure may store prompts and completions that are flagged for human abuse review, and Microsoft's primary documentation does not publish a maximum retention period for that storage; this does not apply where your deployment is approved by Microsoft for modified or zero abuse monitoring; AWS Bedrock does not retain your inputs or outputs after a request completes. Tier 4 routes use provider-default or non-Canadian residency; custody headers show the exact upstream provider, region, and jurisdiction for each request. Northern Inference's custody record reflects where we routed each request; once a request enters a provider, where inference runs and how the provider handles your data rests on that provider's own published documentation and commitments, which we cite per route in each model's data-use posture. We cannot independently execute inside a provider's infrastructure.
Prompt caching. To speed up repeated or long-context requests, Northern Inference and some providers use prompt caching, which temporarily stores a copy of the recurring portion of your prompt (the cached prefix) so it does not have to be re-processed on the next matching request. Any such cache lives in the same jurisdiction as the inference (a Canadian-resident route caches in Canada), is short-lived (typically a few minutes, set by the provider's cache time-to-live), and is automatically purged when it expires. Prompt caching does not change where your data is processed and does not add long-term retention; it is a transient, in-jurisdiction performance optimization. You can see whether a request used the cache in its usage record (cache-read and cache-write token counts).
The following third parties process data on our behalf:
| Sub-processor | Purpose | Data Location |
|---|---|---|
| Amazon Web Services | Infrastructure, database, storage, email (SES), LLM inference (Bedrock) | Canada (ca-central-1) |
| Microsoft Azure | LLM inference (Azure). Tier 3 (Canada East) and Tier 4 (global). | Canada (Canada East) for Tier 3; data may be processed outside Canada for Tier 4. |
| Google Cloud | LLM inference (Vertex AI). Tier 3 (Canadian data residency). | Canada (Montreal, northamerica-northeast1) |
| Stripe | Payment processing | United States |
| Google Fonts | Font delivery (website only) | Global CDN |
When enabled on your API key or per-request, our PII Substitution feature automatically detects personal information (names, emails, phone numbers, credit card numbers, IP addresses, locations) in your prompts and replaces them with realistic fictional substitutes before the request leaves our infrastructure. The originals are restored in the response you receive.
Content Debug Mode is an opt-in tool that lets Northern Inference support log the full content of your API prompts and responses to diagnose an issue (for example, a client configuration that makes a model misidentify itself). It is off by default and is never enabled silently.
We do not use third-party tracking cookies. Authentication uses Secure, HttpOnly session cookies backed by server-side session records.
We use browser localStorage for:
Under the Personal Information Protection and Electronic Documents Act (PIPEDA), you have the right to:
To exercise any of these rights, email privacy@northerninference.ca. We will respond within 30 days. For deletion requests, we will confirm deletion within 30 days of verifying your identity.
For questions about this privacy policy or our data practices:
Email: privacy@northerninference.ca
Northern Inference Inc., Ontario, Canada
We will post material changes to this policy on this page with an updated date and notify registered users by email at least 14 days before changes take effect.