Buyer's guide · vendor-neutral

Subscription, API, or your own model?
Read the part they bury.

Pricing pages compare seats and tokens. They don't compare what happens to your data after the request lands. Here's how the three ways of buying AI really differ on retention, retraining, and sovereignty — the clauses that live in the terms of service, not the marketing.

You control it Possible, with effort or contract The provider decides
Three ways to buy AI

Same model, very different terms.

The exact same frontier model can reach your team three ways. What changes between them isn't the weights — it's the contract sitting underneath, and who is allowed to do what with the text you send.

Consumer chatbot subscriptions

ChatGPT · Claude · direct from the provider

Buying a frontier lab's own consumer or team chat product — ChatGPT, Claude, and the like — directly. Easiest to adopt, hardest to govern: defaults are written for consumers, and the strongest data protections usually sit behind the enterprise contract you didn't sign.

Convenience over control

Provider API endpoints

pay-per-token · DPA available

Calling the model over its API. Generally the cleanest commercial defaults — no training on inputs, shorter retention — but the guarantees depend on the tier you're on and the data-processing agreement you negotiate.

Good defaults, read the tier

Self-hosted / your own model

open weights · your infrastructure

Open-weight models running on hardware you control — your VPC, your region, or on-prem. The data never reaches a third party, so retention, retraining, and residency stop being clauses and become facts you can prove.

Control, at the cost of ops
The honest comparison

What each model does with the text you send.

Generalised across the major providers — not any single one. Always confirm against the current terms for the exact product and tier you're buying; defaults change, and the enterprise contract usually rewrites the consumer one.

Dimension
Consumer subscriptionChatGPT · Claude, direct
API endpointpay-per-token
Self-hostedbest for sovereignty
CudatorChat & Platformgoverned
Training on your data
Are your prompts and outputs used to improve future models?
Consumer subscriptionOn by default, oftenConsumer tiers frequently train on chats unless you find and flip the opt-out. The toggle is per-account, easy to miss, and resets expectations no one in the org agreed to.
API endpointGenerally excludedMost providers contractually exclude API traffic from training by default — but the wording is the promise. Confirm it's "will not," not "may, unless you opt out."
Self-hostedNever leaves youThere is no upstream to train on it. The weights are static unless you fine-tune them yourself, on your own data, on your own hardware.
CudatorNever — routed, not sharedCudator routes to API tiers that exclude training or to self-hosted models. Your text is never a training input, by policy.
Data retention
How long is your content stored after the request completes?
Consumer subscriptionStored indefinitelyHistory is the product — conversations persist in your account until you delete them, and copies may linger in logs and backups well beyond that.
API endpointDays, for abuse checksA short retention window (commonly ~30 days) for trust-and-safety review is typical. Zero-retention is often available — but only on request, and sometimes only on higher tiers.
Self-hostedExactly what you setRetention is a config value you own. Keep everything, keep nothing, or keep it for the precise window your regulator requires — and prove it.
CudatorZero-retention by defaultRetention is a workspace dial — default zero, or the exact window your regulator requires. Enforced, not requested.
Human review
Can a person at the provider read flagged content?
Consumer subscriptionYes, for safetyTrust-and-safety teams and their contractors may review flagged conversations. Reasonable for moderation — uncomfortable for confidential business data.
API endpointLimited / waivableReview is usually narrower and tied to the retention window; zero-retention agreements typically remove it. The default still allows it.
Self-hostedNo outside eyesThe only people who can read it are the ones you already employ. There is no provider-side moderation pipeline to opt out of.
CudatorNo third-party eyesGoverned traffic carries no provider moderation pipeline; sensitive workloads route to infrastructure you control.
Sovereignty & residency
Which country's laws and infrastructure govern the data?
Consumer subscriptionWherever they hostYou rarely choose the region. Data typically lands in the provider's home jurisdiction, exposing it to cross-border transfer and foreign disclosure law.
API endpointSome regions offeredA handful of providers offer regional endpoints or in-region processing. Coverage is partial, model availability lags, and it's on you to pin every call to it.
Self-hostedYour region, periodIt runs where you put it. One jurisdiction, one legal regime, no transfer to argue about with an auditor.
CudatorPinned by policyResidency is a routing rule — bind a workspace to approved regions or self-hosted models; out-of-region credentials aren’t in the pool.
Deletion guarantees
When you delete, is it actually gone everywhere?
Consumer subscriptionEventually, mostlyDeleting a chat removes it from your view; backups, safety logs, and anything already absorbed into a trained model are a different story.
API endpointPer the DPAYour data-processing agreement defines deletion timelines and certificates. Strong on paper — but you're trusting a process you can't directly observe.
Self-hostedYou hold the diskDelete means delete, on storage you administer. No third-party backup to subpoena, no derived model to worry about.
CudatorEnforced & provableDeletion and retention are governed and logged, with an exportable trail — not a “commercially reasonable” promise.
Audit & transparency
Can you prove what happened to a given request?
Consumer subscriptionLittle to noneThere's no per-request log you can hand an auditor. You get a chat history, not an evidence trail.
API endpointBuild it yourselfThe API gives you the hooks; the logging, attribution, and retention of that trail is your engineering team's job to build and keep.
Self-hostedTotal visibilityEvery request passes through your stack, so you can log model, region, and payload handling end to end — the audit trail is yours by construction.
CudatorRequest-level trailEvery call is logged with model, region, and cost. The governed timeline is an evidence trail you can hand an auditor.
Portability & lock-in
How hard is it to leave or switch models?
Consumer subscriptionHighTied to one vendor's app, account model, and feature set. Switching means re-training people and exporting whatever the product lets you.
API endpointMediumStandardised request shapes help, but prompts, tools, and quirks are tuned per model. Re-pointing isn't free.
Self-hostedYou own the stackOpen weights run anywhere you can stand up a GPU. No vendor can deprecate the model out from under you.
CudatorOne endpoint, every modelRoute across every provider and your own models through one interface. No single vendor to be locked into — or deprecated by.
Cost & operational effort
What does it really take to run?
Consumer subscriptionLowest effortFlat per-seat price, zero infrastructure. Predictable for finance, instant for users — which is exactly why governance gets skipped.
API endpointPay per tokenNo servers to run; cost scales with usage and can surprise you at volume. Light ops, moderate spend discipline required.
Self-hostedReal infra to runGPUs, scaling, and on-call are yours. The control is total; so is the responsibility — best justified by volume or compliance.
CudatorSeat price, zero infraSubscription simplicity — per-seat Chat or usage-based Platform — with none of the GPUs or on-call of self-hosting.
The bottom line

There's no single right answer — only the one that matches your data.

Convenience, cost, and control trade off against each other. The mistake isn't picking the wrong one — it's picking by price and discovering the data terms after the data's already gone.

  • Match the tier to the data, not the demo

    Public, low-stakes content can ride a subscription. Regulated or confidential data shouldn't.

  • Read the clause, not the marketing page

    "Will not train" beats "you can opt out." The defaults are what govern you until you act.

  • Keep the sovereign workloads sovereign

    If a regulator could ask "where did this go?", the answer should be a fact you can prove — not a vendor's promise.

Stop choosing once for everything

Route each request to the model its data deserves.

Pin regulated workloads to self-hosted models, send the rest to the cheapest endpoint, and keep one audit trail across all of it. Retention, residency, and retraining become rules you set — not terms you accept.

Vendor-neutral · this page describes the market in general, not any one provider