Account data — name, email address, hashed password or federated identifier, tenant membership, role, and authentication events. Collected from you when you register or are invited.
Billing data — plan, subscription state, invoices, and payment identifiers held by our payment processor. We do not store full card numbers.
Customer content (processor role) — documents a seller uploads, their derived text chunks and vector embeddings, and the messages exchanged in conversations. Buyers may include personal data in messages; sellers decide what to upload.
Usage and metering data — per-call token counts, model name, and computed cost. These records contain no message bodies.
Abuse-prevention data — truncated one-way SHA-256 hashes of identifiers and IP addresses, held transiently in our cache with a time-to-live tied to the rate-limit window. We do not store plaintext IP addresses for this purpose.
Placement measurement — impressions and clicks on sponsored cards, recorded against a one-way hash of the viewer, never against a name or email.