What we store
Your e-mail address and display name. Your password, only as a one-way Argon2id hash. For each sign-in session: when it started, the IP address and the browser name it came from.
Your workspaces, projects and members. Your API keys, only as a hash and a short prefix so that you can recognise them; the full key is never stored after it is shown to you.
For every API request: which key made it, the model and route that served it, the number of input, output, cached and reasoning tokens, its cost in Coin, the time it took, its status and any error code.
Your Coin ledger, top-up invoices and payment confirmations, and an audit trail of administrative changes to your account.
What we do not store
The text of your prompts and of the answers is not logged by default and is not kept in our database. It passes through the gateway to the model provider and back.
We do not store card numbers; top-ups are paid by QRIS. We run no advertising or tracking scripts.
Who else sees your content
Your prompts are sent to the model provider that serves your request, through a router run by the operator. That provider's own terms and privacy rules apply to the content. Do not send anything you are not allowed to share with such a provider.
Cookies
We set a session cookie and a CSRF cookie so that you stay signed in safely, and cookies that remember your language and theme. We set no other cookies.
How long we keep it
Ledger, payment and audit records are financial records and are kept. Usage records are kept so that your charges can be explained. Ended sessions are kept as a record of past sign-ins.
To ask for a copy of your data or for your account to be closed, use the contact page. Financial records may have to remain even after an account is closed.
Security
Passwords are hashed, API keys are stored as hashes, sessions can be ended from Settings, and administrator actions need a second factor and are written to an audit log. No system is perfectly secure; tell us at once if you suspect a problem.
Questions about this page: use the contact page. Contact