Legal
How VarunSH handles your data. This is a template and should be reviewed by counsel before production use.
Account details (email, name), authentication metadata, and API usage metadata: tokens, latency, status codes, model and provider identifiers, and a salted hash of your IP for abuse prevention.
Prompt and response bodies are never persisted by default. We record only the metadata required for usage accounting and security.
Provider credentials are encrypted at rest and never returned to the browser, included in logs, or exposed in API responses.
We use a single httpOnly session cookie for authentication. No third-party advertising cookies are set.
You can revoke API keys at any time and request account deletion. Deleting your account cascades to your keys, sessions, and usage records.