Ordinary run text is processed to answer your request and is not stored in the site’s long-term business tables or analytics.
Identity and sign-in
Anonymous use relies on a signed, random first-party visitor identifier. If you sign in with Google or request a magic link by email, Neon Managed Better Auth stores account and session records in the database's neon_auth schema. The site maps the verified account subject to an internal principal and links this browser's visitor principal so quotas cannot be repeatedly reset by signing out.
Runs and usage ledger
When Live is enabled, your supplied state and questions are sent from the server to Vercel AI Gateway and the selected Jev provider. Run metadata—including recipe version, hashes, status, timing, token usage, credit consumption, and safe error codes—may be retained for 30 days. A short-term encrypted result supports idempotency for 15 minutes and is physically cleaned within 24 hours. Usage and financial ledger summaries are retained for at least 90 days; pending reservations are retained until reconciled.
Abuse prevention
A signed first-party visitor ID and a short-window HMAC of network information are used for quota and rate limiting. The service does not put raw input text, browser fingerprints, or plain IP addresses into analytics properties.
Shares
Nothing is published automatically. An unlisted share is public to anyone holding its link and is not private. Shares expire after seven days by default and can be revoked with a separate deletion credential. Custom inputs, questions, and evidence are excluded unless explicitly selected in the preview.
Third parties
Vercel hosts the app and AI Gateway; Neon stores operational metadata, account data, and sessions. Google processes OAuth sign-in, and Brevo delivers transactional sign-in email. Their platform logs and retention policies are separate from this application’s database policy.
Your choices
You can use all content, illustrative fixtures, editing, and exports without submitting a Live run. Clearing the visitor cookie creates a new browser identity, but network limits and the shared service budget still apply. Do not submit secrets, confidential records, regulated personal data, or material you are not allowed to process.