Skip to content

ADR-0033: Query Intent runs on Gemini Flash's paid tier, and zero retention was not available

Status: Accepted — amends ADR-0031, which stands Date: 2026-09-08

Decisions

D-75 The Query Intent tier runs on Gemini 3.8 Flash, on the paid tier

Model id gemini-3.8-flash, owner's choice of provider. The free tier is excluded on the grounds in D-76.

D-76 ADR-0031's zero-retention requirement is not met, is not meetable, and is replaced by a narrower requirement that is

The no-training half stands and is binding: submitted text must not be used to improve the provider's products, which the paid tier commits to and the free tier explicitly does not. The zero-retention half is withdrawn, because no option available to this effort provides it. Prompts are logged by the provider for a limited period for safety, abuse detection and legal compliance. That exposure is stated here rather than left implied.

D-77 Spend is capped in this project's own server, and reaching the cap disables the tier rather than degrading anything else

The cap is a number the owner sets. On reaching it the Query Intent tier is switched off and Routing serves the Routing Floor alone — the same state as no signal, which D-66 specifies and Seam 5 already tests. Reaching the cap is logged and visible, never silent.

D-78 The Query Intent endpoint is rate-limited per client address, and the provider key never leaves the server

D-60 removed accounts, so the endpoint is unauthenticated by construction and has no per-user identity to limit against. A per-address limit is therefore the only fairness control the design permits, and without it a single caller can exhaust the global cap and deny the tier to everyone.

Context

ADR-0031 specified what the Query Intent tier may receive and return and deliberately named no provider, recording the choice as a Declared Gap. The owner selected Gemini Flash.

Prices were read from the provider's own pricing page on 2026-09-08, not recalled: gemini-3.8-flash at $0.75 per million input tokens and $3.75 per million output tokens, rising to $1.50 and $7.50 on 2027-01-01. At this workload — a short question in, a small structured intent out — that is roughly $0.0009 per query, or about $4.50 across the whole prototype, and about $9 if the work runs past the price change. Seam 5 runs on recorded intent, so the fixture costs nothing; live calls are demonstrations and the needs study only.

Cost therefore decides nothing here. Every candidate — Claude Opus 5 at $5/$25 per million, Sonnet 5 at $2/$10, Haiku 4.5 at $1/$5, Gemini Flash at $0.75/$3.75 — sits inside a $30 spread on an effort whose real cost is measured in person-days (D-58). The decision was the owner's on other grounds and is recorded as such.

What the price check turned up instead was a broken requirement. D-69 asked for zero retention and no training. The free tier uses submitted content to improve the provider's products, which would make a needs-study participant's question into a third party's training data. The paid tier does not train on submitted text but does retain prompts briefly for safety and compliance. Zero retention exists only on the enterprise platform, by contractual amendment for eligible customers — which is precisely the class of thing ADR-0001 rules is stubbed and named rather than assumed.

So D-69 was written as a requirement nobody had checked against a real provider. The repository's rule is that a contradiction with an accepted ADR is raised rather than implemented over, and the honest resolution is to narrow the requirement to what is true and to name what is left exposed.

Decision

The Query Intent tier calls gemini-3.8-flash on the paid tier from this project's own server. The no-training requirement stands; the zero-retention requirement is withdrawn as unmeetable and the residual exposure is stated. Spend is bounded by a cap the owner sets, enforced server-side, whose effect on reaching it is to disable the tier — a state the design already specifies and tests. The endpoint is rate-limited per address because there are no accounts to limit against, and the provider key stays on the server.

Rejected options

  • The free tier — rejected. It saves about $4.50 across the prototype and pays for it by making the questions Handlers type during a safety needs study into a third party's training corpus. This is the option D-69's surviving half exists to forbid.
  • Claude Opus 5, Sonnet 5 or Haiku 4.5 — the prices above were fetched and presented; the owner chose Gemini Flash. Recorded so that a future reader does not read this ADR as a claim that the others were unavailable or unaffordable. They were neither.
  • Enterprise zero-data-retention terms on the provider's cloud platform — rejected as unreachable. It requires a contractual amendment and an eligible enterprise account, which is a company-only resource under D-01.
  • Dropping the Query Intent tier and shipping the Routing Floor alone — rejected. It is coherent, costs nothing and leaks nothing, and it re-decides ADR-0031 in exchange for a privacy improvement that $4.50 and an honest disclosure already buy.
  • Provider-side budget alerts as the cap — rejected. Budget alerts notify; they do not stop. On an endpoint with no authentication that is a receipt for the overspend, not a control against it.
  • A global cap with no per-address limit — rejected. One caller exhausts the shared budget and denies the tier to every real user, which is a denial of the feature during exactly the demonstration it exists for.
  • Leaving the cap number in this ADR — rejected. D-30's discipline applies: the spec does not invent numbers it has no basis for. The measured expectation is recorded; the ceiling is the owner's.

This ruling may not be re-decided

If a change contradicts this ADR: stop and raise it. Do not implement over it.

Specifically: do not move to the free tier because the paid tier requires a billing account; do not raise the cap as a reflex when the tier switches off, since switching off is the designed behaviour and the app remains fully usable; do not put the provider key in the client, where a Corpus-holding browser would carry it to every device; and do not read D-76 as permission to relax a requirement that turns out to be inconvenient — it is permission to state one that turned out to be impossible.

Consequences

The residual exposure, stated plainly. Question text leaves the device. It carries no identity, because there are no accounts (D-60) and no history is sent (D-09). It carries no Corpus content, because ADR-0031's main clause is untouched — no Source Span, SDS Section, Curated Translation or document ever crosses. What is exposed is what a Handler typed, which ADR-0031 already noted is health-adjacent — "สารเคมีเข้าตา" is a sentence about a person's eye. It is retained briefly by the provider for safety and compliance and is not trained on. That is the whole of it, and it is a smaller exposure than the requirement asked for.

What becomes easy. The cap is genuinely safe to set aggressively, because ADR-0031 made the tier optional before this decision existed. There is no cap value at which the app stops working.

What becomes hard. A needs-study participant technically discloses their question to a third party. If that becomes a consent question during fieldwork, the answer is in this section rather than needing to be constructed under pressure.

Dated facts. The prices above were true on 2026-09-08 and one of them changes on 2027-01-01. Re-read them before quoting them.

Coverage

UpstreamLanded inEvidenceNote
R-17D-75the named AI Chatbot technology resolved to a specific model on a specific tierADR-0031 resolved its shape; this resolves its provider
R-19D-77the claims carry no thresholds and "cannot be read off the source", so a number the spec needs comes from the owner — which is what D-77 rules about the capsharpened by ADR-0044; the earlier wording stretched R-19 into a claim about benefit metrics