Privacy Policy
Last updated 13 September 2026
This describes what the hosted gateway collects and what happens to it. It is short because the service collects little, and we would rather tell you plainly what that little is than bury it.
The program itself runs on your machine. Your editorial files, your drafts and your archive live on your own computer and in your own repository, not with us.
1. What we collect
Who you are. Signing in with GitHub gives us your name, email address and avatar. We store those, the session behind your browser, and the API keys issued to your installations.
What you spent. Every request through the gateway records which capability it used, how many tokens it involved, how many credits it cost, how long it took, whether it succeeded, and when. This is exactly what the receipts and the spend page are drawn from, so the figures we bill against are the ones you can read.
Your subscription. Which plan you are on, whether it is active, and when the cycle turns. Administrative actions on accounts are written to an audit log.
Your address, briefly. Sign-in and rate limiting see the IP address your request arrives from, which is how a flood is stopped before it costs everyone else.
2. What we do not collect
We never see your card. Payment details go to Polar and stay there. We receive the fact that a payment succeeded and what it was for, and nothing that could be used to charge you again.
We do not track you across other websites, we run no advertising, and we sell nothing about you to anyone.
3. What your newsroom sends through us
To write an article, the gateway carries the prompt and its sources to a model provider and carries the answer back. To draw a cover it does the same with a picture model. To search the web it passes the query to a search vendor. That content passes through the gateway in order to be answered.
We keep the measurements of those requests, described above. We do not keep the article text as a matter of course, and nothing in the gateway is used to train anything of ours.
4. Who else sees it
Polar is the merchant of record. It handles checkout, tax and the customer portal, and holds the payment details we never see.
Model providers. Requests are relayed to Vercel AI Gateway and OpenRouter, which in turn reach the model that answers.
Cloudflare hosts the gateway, its database and its caches, and runs the embedding model used to search your archive by meaning.
Search vendors. Web search is answered by TinyFish, Brave or Exa depending on the depth of the search, and the query reaches whichever one answers it.
Beyond these, and beyond what the law requires of us, nobody.
5. Zero data retention
There is a setting that asks every upstream provider to retain nothing and to train on nothing. Turn it on and it applies to every request your account makes.
We pass that instruction on. We cannot audit another company's servers, so what we can promise is that the request is made, not that we have inspected their compliance.
6. How long we keep it
Usage records stay for as long as the account exists, because they are the record of what you were charged and you are entitled to check them. Backups of the database are kept for thirty days and then dropped.
Close your account and we delete what identifies you. We may keep the bare record of payments where we are required to, which is a transaction and an amount rather than anything about what you wrote.
7. Cookies and sessions
The site sets a cookie so that being signed in survives a page load. That is its whole purpose. There are no advertising or analytics cookies, so there is no consent banner to dismiss, because there is nothing to consent to.
Installations of the program do not use cookies at all. They hold an API key on the machine you signed in from.
8. Your control over your data
You can see what we hold from the dashboard: your account, your subscription, every request and what it cost. You can revoke any installation key there, and you can cancel or change a plan through the billing portal.
Ask us for a copy of what we hold, or for it to be corrected or deleted, and we will do it.
9. Changes to this policy
If what we collect changes, this page changes with it and the date at the top moves. Where a change is material we will tell account holders rather than relying on you to re-read it.
10. How to reach us
Every account can reach us from the account dashboard, which is the surest way to be answered about your own subscription, since we can see the account you are writing about.