Privacy Policy

Last updated July 2026

1. What we collect

We collect the following categories of information: (a) Account information — your name and email address, provided via Clerk authentication; (b) Content — the prompts, chains, test cases, variables, and run outputs you create; (c) Usage metadata — run logs including model, provider, token counts, latency, and cost; (d) Billing identifiers — your Razorpay customer ID and subscription status; (e) Technical data — IP addresses, request IDs, and error logs for operating and securing the Service. We do not store raw payment card details.

2. LLM provider API keys

API keys you add for OpenAI, Anthropic, Google, or other LLM providers are encrypted at rest using Fernet symmetric encryption and stored in our database. They are decrypted only in memory at the moment your prompt or chain is executed and are never logged or transmitted to any party other than the corresponding LLM provider API endpoint. You can delete your keys at any time from Settings → Providers.

3. How we use your data

We use the data we collect to: deliver and maintain the Service; track your usage against your plan limits; process payments and manage your subscription; provide customer support; detect and prevent fraud, abuse, and security incidents; and send transactional emails (e.g. password resets, billing receipts). We do not use your prompts, chains, or outputs to train machine-learning models.

4. Data sharing

We share data with the following categories of third parties: (a) Authentication — Clerk processes your sign-in and stores your profile; (b) Payments — Razorpay processes subscriptions and notifies us of billing events; (c) LLM providers — when you execute a run, your prompt content is sent to the LLM provider whose key you configured; (d) Infrastructure — our hosting and database providers store your data on our behalf. We do not sell or rent your personal data to any third party for marketing purposes.

5. Data retention

Your account data, prompts, chains, and workspaces are retained for as long as your account is active. Run logs are kept to power your usage analytics and are automatically pruned after 90 days. When you delete a prompt, chain, or workspace, the associated data is deleted from our primary database within 30 days; backups may retain it for up to 60 additional days.

6. Cookies & tracking

We use session cookies set by Clerk for authentication. We do not use third-party advertising cookies. If Google Analytics 4 is enabled on your deployment, anonymized page-view data is sent to Google; you can opt out via browser settings or GA opt-out extensions.

7. Your rights

Depending on your jurisdiction, you may have the right to: access the personal data we hold about you; correct inaccurate data; request deletion of your data (right to erasure); object to or restrict certain processing; and receive a machine-readable copy of your data. To exercise any of these rights, use the Feedback button in the app (include your account email) or, if signed in, submit your request from there. We will respond within 30 days.

8. Security

We protect your data with TLS encryption in transit, Fernet encryption at rest for sensitive fields, and principle-of-least-privilege access controls. Our API keys are SHA-256 hashed at rest. We conduct periodic security reviews and monitor for anomalous access patterns. No system is perfectly secure; if you discover a security issue, please disclose it responsibly.

9. Children

The Service is not directed at children under 16. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us data, contact us and we will delete it.

10. Changes to this policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email or in-app notice at least 7 days before they take effect. Continued use of the Service after the effective date constitutes acceptance.

11. Contact

For privacy questions or to exercise your data rights, use the Feedback button in the app to reach us.