Skip to content

Privacy note

Version 2026-09-22.

Who is responsible: Kirill Balakhonov. This is a personal project. You can contact me onLinkedIn.

What is collected and why

API and MCP access: API keys are stored only as hashes, with an account ID, label, creation time and revocation time. Requests use the same processing and text retention as the web tool. Request IDs, input hashes, progress and saved results let you retrieve an existing run without processing the text again. The local MCP client keeps active results in memory and does not save texts or keys to disk itself. Remote MCP supports OAuth and agent claim codes. Connection records include the app name, permissions, account ID, expiry and revocation status. OAuth grant data is stored in Cloudflare KV. Claim handles and agent access tokens are stored as hashes; claim codes use a keyed hash. The browser confirmation page checks your signed-in account before granting access. Background jobs keep the draft in Cloudflare Durable Object storage while it waits or runs, then remove that temporary copy. The D1 text and result records follow the tool's retention policy above. You can revoke agent connections on the integrations page.

Where it lives

Purchases: Stripe processes the payment details you enter at checkout. This site stores the checkout email, an account-linked purchase reference, payment status and the number of purchased characters used or refunded. The checkout email connects the purchase to an account and allows access from another browser. Card details do not enter this site's database or analytics. This information is used to provide the purchased service, reconcile payments and handle refunds.

Form data is stored in a Cloudflare D1 database owned by me and is not sent to marketing platforms as raw form records. The hashed contact identifiers described above may be shared with OpenAI for ad measurement. Processors: Cloudflare (hosting, bot protection), PostHog (aggregate analytics), OpenAI (ad measurement), OpenRouter (model routing), GMICloud, Phala, DeepInfra, CoreWeave, Baseten and Together (model inference) and Resend (magic-link emails). The rewrite demo stores aggregate daily run counters, per-browser and per-account run counters, and registered emails in D1.

Retention and your rights

Form records are kept while the related experiment or update list is active, at most 24 months. You can ask at any time what is stored about you, ask for correction, or ask for deletion. Message me on LinkedIn and it will be removed within 7 days. Every update email (if you opted in) will include an unsubscribe method.