What the NoLLMWM privacy policy covers

We process the email address and password hash needed for your account; signed session records; plan, balance, and safe rewrite usage data; order and verified payment-event records; API-key hashes and labels; rate-limit buckets; and allowed conversion events. We do not store your account password in readable form, payment card data, raw API keys after display, or raw source and rewritten text in the application database.

Browser-local Unicode inspection and cleanup do not send the pasted text to our server. If you request a rewrite, the text is transmitted to our server and the configured OpenRouter/model provider to perform that request. Provider processing is governed by its terms and policies.

Why we use data

We use account and session data to authenticate you, usage records to enforce balances and prevent double spending, order events to grant purchased entitlements, rate-limit data to reduce abuse, and aggregate events to understand signup, rewrite, and checkout reliability. Safe operational notifications help diagnose failures without containing tool content.

We do not sell raw tool text or build an application database of prompts. Cloudflare Web Analytics receives page and performance metadata through the edge-injected beacon, not pasted or rewritten tool text. Optional GA4 is enabled only with a validated public measurement ID and also receives no text payload from the tool.

Retention and sharing

Raw text is not intentionally persisted by NoLLMWM. Account, order, entitlement, event, and security records are retained as reasonably needed to operate the service, meet legal obligations, resolve disputes, and prevent abuse. Specific schedules may evolve with operational and legal requirements and will be reflected in this policy.

We share request data with OpenRouter and the selected model provider only when you request a rewrite. pay.yito.ai and its payment provider process checkout. Cloudflare provides DNS, proxying, security, and page-performance measurement. Feishu can receive bounded operational fields, and ZeptoMail can receive one aggregate daily report when explicitly enabled. Service providers receive only the data needed for their role.

Your choices and requests

You can use local scanning without an account. You can avoid provider processing by not selecting Rewrite. You may request access, correction, or deletion of applicable account data by contacting [email protected] from the account email. Some order, fraud-prevention, or legal records may need to be retained.

Do not submit another person’s personal or confidential text without authorization. The service is not intended for children or for regulated secrets. Contact us with jurisdiction-specific questions before relying on the product for a sensitive workflow.

Security, changes, and contact

We use encryption in transit, server-only secrets, scrypt password hashing, signed HttpOnly sessions, transactional quotas, raw-body webhook verification, and data-minimized logging. No system is risk-free; the security page explains controls and remaining responsibilities.

We may update this policy as the product or legal requirements change. Material changes will update the effective date. Contact [email protected] for privacy questions.

Continue with a related resource