Skip to content
HomeHome
DE
WhatsAppMailPhone
← All articles
Seven free AI APIs and what they may do with your prompts
KI

Seven free AI APIs and what they may do with your prompts

Photo: cottonbro studio / Pexels

Which free AI API stores your prompts, which one trains on them and where may humans read along? Seven providers compared as of 21 September 2026, including Google's special rule for Europe and a practical rule for businesses.

Eric MengeAuthorEric MengeOwner & web developer at EMIT Solution
Published
Reading timeca. 8 min

In short

  • According to Google's Gemini API Additional Terms of Service, effective 23 March 2026, users in the European Economic Area, Switzerland and the United Kingdom get the data rules of paid usage even on the free quota. Their prompts are not used for product improvement and are kept for 55 days for abuse detection.
  • Mistral may use inputs and outputs from the free mode of Mistral Studio for model training by default, as of 21 September 2026. You can switch this off in the admin panel under Privacy, separately from the toggle for the Vibe chat app.
  • Of 21 free models on OpenRouter on 21 September 2026, five ran on an endpoint with zero data retention. For eight of them, the provider's default policy as listed by OpenRouter allows training on prompts.
  • Hetzner, Groq, Cloudflare and Scaleway do not use prompts from their free tiers for training, according to their own documentation. Hetzner does not store content at all, but names no data processing agreement for its experiment.

For this comparison I read the terms of service, privacy notices and documentation of seven providers on 21 September 2026, all of which offer an AI API you can use for free. Comparing the limits, meaning how many requests per minute or per day you get, is quick work. For a business, another question matters more. Who may store your prompts, who may read them, who may train a model on them and what changes once you pay?

In July I introduced Hetzner’s free inference API, which has a very short answer to these questions. Other providers need more words. At Google the answer even depends on where you are.

Seven free AI APIs at a glance

The table summarises what the providers themselves write. Where information is missing, it says “not stated”. DPA stands for data processing agreement, the contract under Article 28 of the EU’s General Data Protection Regulation (GDPR) that obliges a service provider to process personal data only on your instructions. If you work with customers in the EU, you need one before any personal data reaches a provider.

Provider What is free Storage of content Training Human review Location DPA
Google Gemini API Quota per model and project, limits only visible in AI Studio outside the EEA used for product improvement, inside the EEA 55 days for abuse detection outside the EEA yes, inside no outside the EEA yes, inside only when abuse is suspected no fixed region via the paid rules, in the EEA also when free
Hetzner Inference everything while it is an experiment; 10 requests per minute per key no content, only timestamps and token counts no no EU (according to Hetzner) not mentioned in the docs
Mistral (free mode) Studio API with the lowest limits 30 days for abuse detection yes, can be switched off not stated EU (default) yes
OpenRouter (:free) 20 requests per minute, 50 per day, 1,000 after buying 10 credits OpenRouter only after opt-in, providers vary by model varies by provider not stated varies by provider, EU routing only for enterprise yes (OpenRouter), providers separate
Groq (free plan) e.g. gpt-oss-120b with 1,000 requests and 200,000 tokens per day not by default, up to 30 days for errors and abuse no not stated USA yes
Cloudflare Workers AI 10,000 neurons per day no, unless you add a storage service no not stated not stated yes
Scaleway Generative APIs the first 1,000,000 tokens, once zero data retention, up to 2 weeks on errors no only on errors and abuse Paris yes

Two names that often appear on lists of free AI APIs are missing here. GitHub Models has been fully retired since 30 July 2026, according to GitHub. Cerebras, according to its own documentation, no longer offers a permanently free tier, only a starting credit of 5 dollars that expires after 30 days and requires a payment method on file.

At Google, your location decides the data rules

In its Gemini API Additional Terms of Service, effective 23 March 2026, Google distinguishes between unpaid and paid services. For unpaid services, Google uses prompts and responses to improve and develop its products and machine learning technology. Human reviewers may read and annotate inputs and outputs after the data has been disconnected from the account, API key and project. Google itself advises against sending sensitive, confidential or personal information through the free quota.

Directly below sits the sentence that matters for anyone in Europe. If you are in the European Economic Area, Switzerland or the United Kingdom, the data rules from the section on paid services apply to you even when you pay nothing. According to the wording, this covers “all Services, including Google AI Studio and unpaid quota in the Gemini API”.

Blank price tag on a string against a dark blue background Photo: Miguel Á. Padriñán / Pexels

The paid section spells out what that means. Prompts and responses are not used for product improvement, and processing follows Google’s Data Processing Addendum, under which Google acts as a processor. Logging only happens to detect abuse, for 55 days according to Google’s abuse monitoring page. People only see this data when safety filters have flagged content. There is no fixed location, and data may be cached in any country where Google maintains facilities.

The pricing page still marks the free quota with a flat yes in the row on product improvement. The special rule for Europe only appears in the terms.

For readers outside these regions, the picture is the reverse. There the free quota really is paid for with your data, and only a billing account switches off product improvement and human review.

The European rule has a catch. The same terms allow only paid services for apps that are made available to users in the EEA, Switzerland or the UK. For your own tests and prototypes, the free quota is enough. Once a chatbot on your website or a customer portal with Gemini behind it is open to other people, Google requires a project with an active billing account. Google does not publish the exact free limits as a table, they are shown per project in AI Studio and are explicitly not guaranteed.

Mistral and OpenRouter allow training, but you can switch it off

Mistral states openly in its help centre that inputs and outputs from the free mode of Mistral Studio may be used to train its own models. This is agreed at sign-up and can be switched off at any time. The toggle sits in the admin panel under Privacy, in the section Anonymous improvement data. It is independent of the toggle for the Vibe chat app, so if you only flip one of them, training stays on for the other. For training, Mistral acts as an independent controller under its data processing agreement unless you have opted out. That is one more reason to flip the switch before the first real record goes through.

Separately, Mistral keeps API inputs and outputs for 30 days for abuse monitoring, according to its privacy policy. Zero data retention is only available with pay-as-you-go, on request with a justification and at Mistral’s discretion. Data is hosted in the EU by default. Whether the training toggle flips by itself when you move to pay-as-you-go is not clear from the help centre. Checking the setting is quicker than any interpretation.

Hands on an open laptop in the dark Photo: Sora Shimazaki / Pexels

OpenRouter does not run models itself but forwards requests to many providers. According to its documentation, OpenRouter only stores prompts and responses if you explicitly turn on logging. What happens at the model provider is governed by that provider’s own policy.

On 21 September 2026 I counted what this looks like for the free models, using OpenRouter’s public API. There were 21 models with the suffix :free, each served by exactly one provider. For five of them, that endpoint appears on OpenRouter’s zero data retention list. For eight, the provider belongs to those whose default policy allows training on prompts according to OpenRouter’s provider list, among them five Nemotron models from Nvidia. 14 of the 21 models run with providers headquartered in the USA, two in China, and for five the list names no headquarters. Individual endpoints can have a different policy than the provider as a whole. Where the situation is unclear, OpenRouter says it treats an endpoint as if it retains and trains.

The privacy settings have separate toggles for paid and free models. If you switch off training for free models, OpenRouter stops routing requests to providers that train. The affected free models are then simply no longer available to you. Routing that keeps data inside the EU is only offered on the enterprise plan.

Hetzner, Groq, Cloudflare and Scaleway do not train

According to its documentation, Hetzner stores neither requests nor responses, only timestamps and token counts for usage tracking and future billing. That is the leanest data rule in this comparison. The documentation for the experiment mentions no DPA, and there is no service level agreement either. Hetzner also explicitly advises against production use. Each key may send 10 requests, 4 million input tokens and 100,000 output tokens per minute. It stays free as long as the status is experimental, and Hetzner will announce any change in advance by email.

Groq does not retain prompts by default, according to its documentation. Exceptions are troubleshooting and suspected abuse, then for up to 30 days. Zero data retention can be switched on under Data Controls, and according to Groq that option is open to all customers. The services agreement rules out training on inputs and outputs unless you explicitly permit it. Retained data sits in Google Cloud storage in the USA, with standard contractual clauses covering the transfer.

Cloudflare uses Workers AI content neither to train the models on offer nor to improve its own or third-party services, unless you explicitly consent. Content is only stored if you add a storage service such as R2 or KV yourself. The free allowance is 10,000 neurons per day, Cloudflare’s own compute unit, which different models consume at different rates. The Workers AI documentation does not name a server location.

Fibre optic cables in a server rack Photo: Brett Sayles / Pexels

Scaleway applies zero data retention by default according to its privacy notice for the Generative APIs and does not use content for training. Only when requests disrupt the service, for example with a server error returning status code 500, does Scaleway keep the full content for up to two weeks to investigate. The models run in a data centre in Paris. Only the first 1,000,000 tokens and 60 minutes of transcription are free, though, and regular billing starts after that. Scaleway is therefore more of a trial allowance than a free tier. For an overview of AI APIs hosted in Germany and the EU, see my comparison of EU-hosted AI APIs.

What changes when you pay

At four of the seven providers, a paid account changes nothing about data usage. Hetzner has no paid version yet. Groq, Cloudflare and Scaleway treat data the same whether you pay or not, so money only buys higher limits there.

The difference is stark at Google outside the EEA. There the billing account decides whether prompts feed into product improvement and whether humans may read them. Inside the EEA the data rules are already at paid level for free, and money mainly unlocks the right to run apps for other people. At Mistral, pay-as-you-go opens the door to zero data retention, while training stays a matter of the toggle. At OpenRouter, the paid variant of a model is a separate catalogue entry with its own endpoints and therefore potentially its own rules.

Regardless of plan, three of the seven providers reserve the right to keep content for abuse detection. Google does so for 55 days, Mistral and Groq for up to 30 days. How this looks at the large US providers and where exceptions exist is covered in my article on zero data retention at AI providers.

A practical rule for businesses

Through a free AI API I only send content that would not matter if strangers read it. That includes public website copy, your own product descriptions, code without credentials and made-up examples. It does not include customer enquiries with names, email addresses, contracts, employee data or anything that looks like a password or key.

A prototype does not need real customer data. Twenty invented enquiries that sound like your real ones show just as well whether a classification or a summary works. The workflow stays the same, you only swap the data later. Because many of these providers understand the OpenAI format, switching providers later is usually a matter of changing the base URL.

Before real personal data flows, I check three things. Is there a DPA? How long is content kept? Is training excluded or switched off? According to their documents, Groq, Cloudflare and Scaleway cover all three points on the free tier already. At Mistral only the flipped toggle is missing, at Hetzner the contract. At Google inside the EEA the data rules fit, but an app with real users still needs a paid project.

One last point that is easy to miss. Settings apply per account or organisation. If someone on the team creates their own account for a quick test, it starts with the defaults again, which at Mistral means training switched on.

If you are building a prototype on a free AI API right now and want to work out which provider is suitable for running it with real customer data, feel free to get in touch.

FAQ

Does Google use my prompts from the free Gemini API for training?+

It depends on where you are. Outside the EEA, Switzerland and the UK, Google uses prompts and responses from the free quota to improve its products, and human reviewers may read them. Inside those regions, the Gemini API Additional Terms apply the paid data rules to free usage as well, so prompts are not used for product improvement. For apps that are made available to other people in the EEA, however, Google requires a paid project.

Which free AI API does not store my prompts?+

Hetzner stores neither requests nor responses according to its documentation, only timestamps and token counts. Scaleway applies zero data retention by default and only keeps content for up to two weeks when errors occur. Groq retains nothing by default, reserves logs of up to 30 days for troubleshooting and abuse and can be switched to zero data retention. Cloudflare only stores Workers AI content if you add a storage service yourself.

Can I send customer data through a free AI API?+

Before personal data flows, three things should be settled: a data processing agreement, a known retention period and training that is excluded. According to their documents, Groq, Cloudflare and Scaleway cover all three on their free tiers. Hetzner lacks the agreement, and at Mistral you first have to switch off training. For prototypes, made-up test data is perfectly sufficient.

Does a paid account change how my data is used?+

At Hetzner, Groq, Cloudflare and Scaleway it does not, money only buys you higher limits there. At Google outside the EEA, the billing account decides whether prompts feed into product improvement. At Mistral, pay-as-you-go opens the door to zero data retention on request, while training is still governed by its own toggle.

Want to know more?

In a free intro call we discuss how you can use these topics for your company. Not a sales pitch, but an honest assessment.

Book a free intro call