1. Summary
2. Data we process
| Data | Why | Stored? |
|---|---|---|
| Prompt and response content (text, images, tool calls) | To forward your request to the upstream model and return the answer | No, processed in transit only |
| API key (as a SHA-256 hash) and its label | To authenticate requests | Yes, until the key is deleted |
| Request metadata: timestamp, model, API key used, HTTP status, token counts, latency, whether streaming was used, and a short upstream error message when a request fails | Per-model usage analytics, capacity planning, debugging and abuse prevention | Yes |
| IP address and user agent | Handled by our hosting provider for delivery and security | Only in the hosting provider's short-lived logs |
| Administrator's Discord ID, username and avatar | To sign the administrator into the admin panel | Only in a signed browser cookie (7 days) |
3. Upstream AI providers
When you call a model, the content of your request is sent to the provider that serves it. That provider processes it under its own terms and privacy policy, which may include retaining data for a limited period for abuse monitoring, or (for some providers or plans) using it to improve their models. Each model's page lists the answers the administrator has recorded about these practices; see Model disclosures.
4. Infrastructure providers (sub-processors)
- Vercel Inc.: hosting and serverless execution of the website and API.
- Supabase Inc.: database for configuration, hashed API keys and usage metadata (EU region, Frankfurt).
- Discord Inc.: sign-in for the administrator only.
- The upstream AI provider(s) of the model you call (see each model's page).
5. Cookies
Public pages set no cookies. The admin panel uses one strictly necessary, HTTP-only session cookie and a short-lived OAuth state cookie during sign-in. There are no analytics or advertising cookies.
6. Retention
Usage metadata is kept while the related API key exists and may be deleted earlier on request. When a key is deleted, its usage records are de-linked from it.
7. Your rights
Depending on where you live (for example under the GDPR), you may have the right to access, correct, delete or export personal data about you, to object to or restrict processing, and to complain to your data protection authority. Contact the administrator on Discord to exercise these rights. For data held by an upstream AI provider, you may also need to contact that provider directly.
8. Security
Traffic is encrypted with TLS. Upstream provider credentials are encrypted at rest with AES-256-GCM, API keys are stored only as hashes, and the database is not reachable from browsers.