Privacy & Terms

What we collect, what we do with it, and — just as importantly — what you should not expect from a service run by six students.

Everything here is a research preview

The Developer Platform, the API and Sigma are all research previews. They exist so we can learn, publish what we build, and let people try the models — not to run anyone's business.

We are a high-school team. This is maintained around schoolwork, exams and holidays, by people who also have homework. There is no on-call rota, no support contract, and nobody watching a dashboard at 3am.

What that means in practice:

  • Long outages are possible. Days, not minutes. It can go down because a laptop is shut, an exam week starts, a tunnel expires, or a power cut happens.
  • Response to problems is not real-time. Issues reported today may be looked at next weekend.
  • Breaking changes can happen without much notice. Model names, limits and request formats may change as we improve things.
  • Do not build a production service on this. If you have, or expect to have, a large number of users, please use a provider with a real SLA. We are not one, and we would rather say so now than have you find out during your own outage.

We are continuing to improve the backend and the hardware behind it — better inference machines, redundancy, monitoring and backups. Those improvements are the plan, but they are not promises with dates attached.

What we collect

DataWhy
Email and display name To identify your account. Your email is the login identifier.
Password Stored only as a salted hash (scrypt). We cannot read it and cannot recover it — a forgotten password needs an admin reset.
API keys Stored as a SHA-256 fingerprint plus a short display prefix. The full key is shown once at creation and never again.
Usage records Per request: model, input and output token counts, cost and a timestamp. This is what your usage page and any billing are built on.
Conversation content Messages you send through Sigma or through threads are stored so the conversation can continue. Stateless /api/v1/chat calls are not stored as conversations.
Login attempts Email and IP address, kept briefly, to slow down password guessing.

What we do with it

We do not sell your data, and we do not use your conversations to train models. If we ever want to use published conversations as training data, we will ask first and make it opt-in.

Where it runs

The API runs on a machine in a home, reached through a tunnel. The documentation and the dashboard are static files on GitHub Pages. In practice that means two third parties see something:

If you are not comfortable with a home-hosted service and a tunnel, you should not use this one. That is a reasonable position and we would not argue with it.

Keeping and deleting

One caveat we would rather state: backups and logs are not yet as thorough as they should be, so a deletion request is handled by hand rather than by a guaranteed pipeline.

Not a legal document

We are a student team, not a company, and this page is plain-language rather than a contract. There is no warranty of availability, fitness or data retention. Use the service for what it is — a preview of models we are proud of — and keep anything you cannot afford to lose somewhere else.

Questions

If something here is unclear, or you want your data removed, ask us.