How we store, encrypt, and delete your data — in the open.
Prompt and response plaintext is stored encrypted with AES-256-GCM.
All traffic is TLS-encrypted, protecting plaintext in transit and at rest.
Records live in Cloudflare’s Tokyo region. The operator is a US entity under SCCs.
API keys are stored hashed. The plaintext is shown once, at issue time.
Emails, card numbers, phone numbers, and API keys are masked before sending.
Kept for your plan’s retention period, then auto-deleted. Accounts delete instantly.
Storage runs on Cloudflare (Tokyo region), AI inference on OpenAI / Anthropic / Google / Mistral, and payments on Stripe.
Aligned with GDPR and Japan’s APPI, with SCCs and flows for deletion, disclosure, and correction. A DPA is available on request.