Legal

Privacy policy

Last updated: August 2, 2026

What we collect

  • Account details: email, optional name, hashed password.
  • API keys you create (we store a hash and a short prefix — not the full key after creation).
  • Session metadata from builder requests tied to your account (intent summaries, status, timestamps).
  • Basic usage signals such as last API key use.

How we use it

We use this information to authenticate you, provide the product, show your dashboard, and keep the service secure and reliable.

Storage and security

Passwords and API keys are hashed. Session access uses short-lived signed tokens stored in your browser. Transmit credentials only over trusted networks.

Sharing

We do not sell your personal data. We may use infrastructure providers (hosting, databases) solely to operate the service.

Your choices

  • Revoke API keys at any time from the dashboard.
  • Sign out to clear the local session token.
  • Contact us to request account deletion or data export for your account email.

Contact

Questions about privacy: reach out via the email associated with your account request, or the support channel listed in your workspace docs.