Legal
Privacy policy
What we store, why, how long for, and how to get it back or delete it.
Draft, pending legal review. This describes accurately what the platform does today. It has not been reviewed by a lawyer, and the tax treatment it assumes is still being settled. Do not rely on it as a final statement of your rights.
What we store
Your email address and name, because you need to sign in and we need to be able to reach you. Your credit statement: every purchase, grant and spend. The modules you build, including the prompts you wrote and the files that were generated. Which devices are signed in, so you can spot one that is not yours.
We do not store your password. We store an Argon2id hash of it, which cannot be turned back into the password.
What we send elsewhere
When you run a build, your prompt and the relevant code are sent to a model provider: OpenRouter, and through it the model you selected. They process it to produce a response. This is the core of the service and cannot be switched off while using it.
Payments go to Stripe. We never see or store your card details.
That is the whole list. We do not sell your data, and there is no advertising network on this site.
How long we keep it
- Your account: until you delete it.
- Your credit statement and payments: seven years, then destroyed. This is a financial record and we are required to keep it even after you leave.
- Signed-in sessions: 30 days after they expire.
- Notifications: 90 days.
- Contact form messages: two years.
- Forum posts: indefinitely, but see below.
Deleting your account
You can delete your account from Settings. It removes your profile, every prototype and transcript, your notifications, your signed-in devices, and your provider key. The key is destroyed at the provider too, not just removed from our database.
Three things survive, and you are told which before you confirm:
- Your credit statement and payments. A financial record. It is detached from you (it no longer names your account) and destroyed after seven years.
- Forum posts you wrote. The text stays; your name comes off it.
- Records of administrative actions. If an administrator ever acted on your account, that record stays.
Getting your data
Settings has an export. It produces one file containing your profile, your full credit statement, every project with its files and transcript, and your notifications.
It contains no credentials: not your provider key, not a session token, not your password hash.
Cookies
Signing in sets one cookie, the session you are signed in with. It is httpOnly, which means the page cannot read it.
This website uses Google Analytics to count visits and see which pages are read. Google sets its own cookies (named _ga and _ga_...) and receives your page views, approximate location from your IP address, and device and browser details. We do not use it for advertising, and Google signals and ad personalisation are turned off. A browser that sends the Global Privacy Control signal is not measured. You can also stop it with Google's opt-out browser add-on or by blocking cookies in your browser.
Where your data is
Our servers and databases. Model requests go to OpenRouter and the provider you selected, which may be outside your country. That is inherent to using a hosted model.
Asking us
Email assista@cybrosys.com. If you want something we hold, or want it gone, say so and we will do it.