Account information — your email address and name, provided via Google OAuth
Usage data — timestamps of API requests, associated with your API key (for rate limiting and quota accounting)
Waitlist data — email address and optional use-case, if you signed up for the waitlist
Rendered content — we do not retain the screenshots or PDFs you generate beyond temporary caching (see below)
2. How We Use Your Data
To authenticate you and provide the Service
To enforce rate limits and monthly quotas
To process billing (via Waffo Pancake)
To send transactional emails (waitlist confirmation, if configured)
We do not sell your personal data.
3. Data Storage
Your data is stored in Cloudflare's infrastructure (D1 database and R2 storage). Rendered content may be cached temporarily to improve performance and is automatically evicted. We retain usage records for billing and abuse-prevention purposes.
4. Third-Party Services
Google — for authentication (OAuth). Google's privacy policy applies to the login flow.
Waffo Pancake — our Merchant of Record, which processes payments and handles payment-related data.
We use a single session cookie to keep you signed in. It is HTTP-only, does not track you across sites, and is cleared when you sign out.
6. Your Rights
You may request access to, correction of, or deletion of your personal data by emailing us. We will respond within 30 days. You can also delete your API keys at any time from the dashboard.
7. Security
API keys are stored as SHA-256 hashes, never in plaintext. All traffic is encrypted via HTTPS. We take reasonable measures to protect your data, though no method of transmission is 100% secure.