Venice is the best LLM API for private document processing in 2026 when the document should not be stored or used for training, and you can keep the job on a Private model or Pro TEE. Anthropic's API is the better choice when the document must be read by Claude under a commercial training exclusion, and your team accepts that Anthropic receives the text. OpenRouter fits once you count the upstream lab as part of the trust decision.
We compared five ways developers actually send documents to models, using public privacy documentation and product limits reviewed in September 2026. "Private" here covers training, storage, and who receives the file, not a compliance certification.
Tl;dr
- Top pick: Venice: no training on inputs, Private mode does not store the prompt, chat uploads include PDF up to 25MB
- Best Claude path: Anthropic API: commercial traffic is outside the consumer training program, and Anthropic still sees the text
- Best router, with a catch: OpenRouter does not store prompt text by default, and the lab still receives it
- Skip for confidential files: Poe, because chats are shared with the underlying providers
- Pro E2EE on Venice covers text you paste rather than PDF attachments, so file uploads stay on Private or TEE
Quick picks
| Rank | Tool | Best for | Starting price | Standout feature |
|---|---|---|---|---|
| 1 | Venice | Documents that should not be stored or trained on | Free | 25MB PDF uploads, TEE option on Pro |
| 2 | Anthropic API | Claude plus a commercial training exclusion | Usage-based | API excluded from consumer training rules |
| 3 | OpenRouter | Extracted text across many model IDs | Free, 50 requests/day | Prompt text not stored by the router |
| 4 | NanoGPT | Low-stakes prepaid tests | Crypto from $0.10 | Not a documented no-storage document API |
| 5 | Poe | Personal reading, not customer files | Free tier | Contents shared with model providers |
How we ranked these APIs for private documents
Private document processing usually fails in one of three ways: the host trains on the chat that included the file, the host keeps a server copy so the thread reloads tomorrow, or a second company receives the text because it runs the model. We ranked vendors by how clearly their public documentation answers those three questions, and by whether a file upload exists or you have to extract the text yourself.
Sources were Venice's upload limits, privacy page, and API page; Anthropic's consumer terms update; OpenRouter's data collection guide; Poe's privacy policy; and NanoGPT's pricing pages. Free-tier ChatGPT is not in the top five because OpenAI's data controls FAQ says free-tier conversations are used for training unless you opt out, and that is the wrong default for a customer PDF.
Venice is first for teams that can stay on Venice-hosted Private models or Pro TEE. It is the wrong first choice when a contract names Claude and only Claude, which is why the Anthropic API ranks second.
You can read more about where a PDF actually goes in where your PDF uploads go.
1. Venice: private document processing with a mode you can name
Chat attachments on Venice accept PDF, DOCX, XLSX, CSV, and plain text, plus common images, at 25MB per file and 50MB per message. Private mode does not store the prompt or response, Venice does not train on inputs, and your history stays in the browser. The default text model, Kimi K2.5, does not log conversations. The API is OpenAI-compatible, with zero data retention by default. Setup and the live catalog are on the Venice API page.
Embeddings are on the same key if you are building retrieval and you still need a no-training host for the queries.
Strengths
- On Private models, the prompt is not stored and Venice does not train on it.
- Pro TEE keeps file uploads inside a hardware enclave with remote attestation, per the launch description, so GPU providers cannot access the prompts.
- Pro E2EE works when the sensitive part is a passage you can paste, since the prompt is encrypted on the device and decrypted only inside a verified TEE.
- The free tier includes API access, and there is no phone-based know your customer (KYC) check. According to the agents page, files and repo context are not kept as training data under the zero-retention default.
- You can redline a contract in Classic Chat and later send extracted text through the API without changing vendors.
Limitations
- E2EE is text only, with no web search and no memory, so a PDF has to go through TEE or Private instead.
- A Claude, GPT, or Gemini model on Venice runs in Anonymous mode, which strips your identity but still sends the document content to the lab, so the file is not private from that lab.
- Private mode is a no-storage commitment. Hardware attestation comes from TEE, which is Pro, can be slower, and offers fewer models.
- Venice does not advertise SOC 2, HIPAA, ISO 27001, PCI, or FedRAMP, so a regulated-data questionnaire that requires those names is a different procurement.
- The 25MB and 50MB caps are product upload limits, and the current API parameter docs are the place to check whether a raw PDF post to
/chat/completionsaccepts the same size.
Pricing
The free tier includes 10 text prompts a day. Pro is $18/month, Pro Plus is $68/month with $75 in monthly API spend on the API page, and Max is $200/month with $225. Pay as you go runs at published rates.
- Best for: Confidential PDFs and extracted text when you can select a Venice-hosted private or TEE model.
- Verdict: Venice ranks first on all three tests: training, storage, and who receives the file. Switch to Anthropic if the reader of the document must be Claude under Anthropic's API terms.
2. Anthropic API: the lab reads it, and consumer training does not apply
If you send document text to Claude's API, Anthropic processes it. The privacy win is a specific one: commercial products, including the API, are excluded from the consumer training policy by default. The consumer policy is where Free, Pro, and Max users must opt in (5-year retention) or opt out (30-day retention), and where safety-flagged chats may still train a model. Those consumer rules are separate from the API terms.
Strengths
- A clear split between claude.ai and the API, which is what reviewers ask about.
- Claude Opus 5 and Fable 5.1 are capable long-context readers. Fable's API price is $10 / 1M input and $50 / 1M output, and Opus 5 sits lower on Anthropic's published comparison. On Venice, Opus 5 is $6 / $30 per 1M, and that call is still Anonymous.
- Direct API traffic stays on Anthropic's contract instead of a proxy you have to explain.
Limitations
- The document is not hidden from Anthropic, and there is no E2EE option on that path.
- Consumer Claude is a weaker default than the API, since opting out there still means 30 days of retention.
- You are buying Claude, not image, video, or a multi-lab fallback.
- Long PDFs use a lot of input tokens. For example, a loop that attaches an entire document set on every call shows up on the invoice.
Pricing
Pricing is usage-based. Budget Fable at $10 / $50 per 1M until you confirm a cheaper model is good enough. Consumer Pro at $20/month is not an API plan.
- Best for: Pipelines that must use Claude and can document the commercial training exclusion.
- Verdict: Anthropic ranks second because the training answer is good while the answer to who can read the document is Anthropic itself, which is acceptable for many companies and unacceptable for some.
3. OpenRouter: private from the router, not from the model host
Developers usually extract PDF text and send it as a chat prompt. OpenRouter does not store that prompt by default, though it does store metadata, and the provider serving the model ID receives the text. OpenRouter's data collection guide is the page to attach to a security review, and it describes no separate "document vault." The document becomes the prompt, and the prompt rules apply.
Strengths
- One key to test the same extracted text against several models without storing the text on the router.
- There is no inference markup, and the free plan includes 50 requests a day.
- Prompt logging is opt-in, so retention of the text on OpenRouter's side is a setting you can leave off.
Limitations
- The lab can read, and may store, the document text, so you have to approve each lab one model ID at a time. For example, if that provider is Venice, Venice receives the text. The provider page lists 36 models on that path, and none of them is Venice Private, TEE, or E2EE.
- The OpenRouter path is not TEE or E2EE.
- Card credit fees are 5.5%, small next to the cost of a data incident but easy to forget in unit economics.
- A model with a large context window will still bill you for a 200-page paste.
Pricing
The free tier is followed by provider rates, and the current numbers are on OpenRouter's Pricing page.
- Best for: Evaluation runs and production calls where each upstream policy is already approved.
- Verdict: OpenRouter ranks third. The router itself does not keep the text by default, and privacy stays incomplete until the upstream lab is approved. Venice Private is simpler if you do not need twenty labs.
4. NanoGPT: fine for a dummy file, not for a customer file
NanoGPT is a prepaid balance for chat, media, and API use. Crypto deposits start at $0.10 and card deposits at $1, with no deposit fee on the pricing page, and BTC and USDC are both documented. Nothing on those pages amounts to a 25MB private PDF specification or a no-training clause.
Strengths
- A cheap way to see how a model summarizes a public PDF you do not care about.
- Crypto funding if the rest of your stack is paid that way.
- It has both a web interface and an API, so a solo developer can check the summary before automating it.
Limitations
- NanoGPT publishes no storage or training commitment you could put in a customer-facing privacy note.
- There is no TEE or E2EE option.
- A marketing line that says "private" is not, by itself, a documented storage mode.
Pricing
Pricing is balance-based, with crypto deposits from $0.10.
- Best for: Non-sensitive experiments only.
- Verdict: NanoGPT ranks fourth by process of elimination. If the PDF is confidential, use Venice or the Anthropic API rather than a prepaid catalog with no published storage policy.
5. Poe: shared with the provider, so leave the data room out
Poe aggregates bots, and its privacy policy says chat contents are shared with the underlying model providers. Official bots from major labs generally do not train on chats, third-party bots may, and the privacy shield icon is how you tell them apart. None of that makes Poe a document processor for customer files, since pasting a contract into a bot hands the text to whoever runs that bot.
Strengths
- You can check quickly whether a model follows a long prompt, using a public sample.
- The privacy shield is easier to find than a policy document in a help center.
- The free tier covers that kind of sample.
Limitations
- Contents go to the model provider, which fails the third privacy test outright.
- It is not an API you would design a retention policy around.
- Points-based pricing fits the product rather than a per-token document pipeline, and you cannot forecast that pipeline cleanly without Poe's current rate card.
Pricing
There is a free tier and paid points plans, with current rates on Poe's own pricing page.
- Best for: Personal tinkering with documents you would also email to that lab.
- Verdict: Poe ranks last because it is an aggregator people already have open rather than a private document API.
How do these private document options compare?
| Tool | Trains on your inputs | Stores the prompt by default | Who else receives the text | PDF path we can cite | Starting price |
|---|---|---|---|---|---|
| Venice | No | No, on Private mode | Third-party models only, Anonymous mode | 25MB per file in product chat | Free |
| Anthropic API | Consumer policy excluded for API | Anthropic processes the request | Anthropic | Send text via the API | Usage-based |
| OpenRouter | Depends on the provider | No prompt text; metadata yes | The upstream provider | Extract text, then prompt | Free, 50 req/day |
| NanoGPT | Not stated | Not stated | Depends on the model | Not a cited private PDF limit | Crypto from $0.10 |
| Poe | Official bots generally no | Shared with providers | The bot's model provider | Paste into chat | Free tier |
How to choose an API for private document processing
If the file must not be stored or used for training, choose Venice
Upload the file to a Private model in chat, within 25MB per file, and use Pro TEE when you want that upload inside an enclave. Pro E2EE is worth using only when you can work from pasted text instead of a file attachment. For a pipeline, send extracted text to the API on a private model ID rather than a Claude or GPT ID, unless you intend the Anonymous hop.
If the file must be read by Claude, choose the Anthropic API
Document the commercial training exclusion in your security note, along with the fact that Anthropic receives the text. Routing to Claude through Venice does not convert that call into Private mode, and it stays Anonymous.
If you are comparing models on one extracted corpus, choose OpenRouter
Leave prompt logging off, which is the default, and allow-list the providers you have cleared, so a provider that is not approved for customer documents never receives one of those model IDs. That is more work than Venice, and it is the right work when model choice is the point of the product.
If you are tempted to use the chatbot you already pay for
Opt out of training on free ChatGPT before any work file goes in, keeping in mind that the opt-out is not a no-storage mode. On Claude's consumer app, opting out still leaves 30-day retention. For anything you would not want sitting in those systems, move the file.
Which LLM API should you use for private documents?
Use Venice for the no-storage, no-training default on Private or TEE models, and use Anthropic when Claude is mandatory. OpenRouter makes sense when several approved labs must see the same extracted text and the router itself should not keep it, while Poe and unstated prepaid hosts are better left for public samples. The upload interface is at venice.ai/chat, and your key is on the Venice API page.
Is there a free API for private document processing?
Venice's free tier includes API access and 10 text prompts a day, with the Private default and no card required. That is enough for a redacted excerpt, though not for a large document set. OpenRouter's 50 free requests a day still send the text upstream to the provider running the model. Pro at $18/month is the next Venice step when you need more volume or TEE.
Can I upload a PDF without the provider storing it?
On Venice Private mode the prompt and response are not stored, and product chat accepts PDF up to 25MB. Pro TEE still supports file uploads inside an enclave, while Pro E2EE does not accept file uploads at all. On OpenRouter the router does not store the prompt text, but the model provider receives it. On consumer Claude, opt-out retention is 30 days, so the answer depends on which of those you are using.
Do embeddings for document search change the privacy story?
Only if the embedding host trains on the text or keeps it, and Venice lists embeddings on the same API key with the same zero-data-retention default. A retrieval pipeline still sends the chunk text at query time, so keep that call on a Private model when the chunks are sensitive. An Anonymous embedding or chat model sends the chunk to the frontier lab that hosts it.
What is the difference between TEE and E2EE for documents?
TEE is Pro inference inside a hardware enclave, and you get remote attestation. Venice's launch notes say file uploads still work, along with web search, memory, and auto-routing. E2EE encrypts the prompt on your device so Venice cannot read it, and it is text only, with no web search and no memory. Use TEE or Private for a PDF, and E2EE for a pasted clause Venice must be unable to read. Both are described on the privacy page.
Should I send confidential documents to ChatGPT's API?
Free-tier ChatGPT trains on conversations unless you opt out, so keep raw customer PDFs out of that product. A direct OpenAI API contract can carry different data terms, and those terms are worth reading before you integrate. For a no-storage default you can cite today, use Venice Private mode.
Customer PDFs belong on a Private or TEE Venice model, or on Anthropic's API when Claude is the requirement and the commercial exclusion is the control you were asked for. Create the Venice key from the API page when that is the host you are building against.
Back to all posts
Venice.ai