1. Data controller
The data controller for your personal data is Keimodel ("we", "us", "our"), reachable at hello@keimodel.com.
2. What data we collect
- Account data. When you register, we collect your name, email address, and profile information through Clerk, our authentication provider. You may also sign in with a third-party OAuth provider (Google, GitHub), in which case we receive the data that provider shares.
- Usage data. We log which models you compare, the prompts you submit, and your in-app activity. This data is used to deliver the service and improve it.
- Payment data. If you purchase credits, your payment details are processed by Stripe. We store only the transaction outcome and credit balance — we never see your card number or bank details.
- Contact messages. If you contact us via the contact form, we store your name, email address, subject, and message.
- Technical data. We may collect your IP address, browser type, and device type for security and analytics purposes.
3. Legal basis for processing (GDPR)
We process your personal data on the following legal bases under GDPR Article 6:
- Contract performance (Art. 6(1)(b)). Processing necessary to provide the service you signed up for, including running model comparisons, storing your history, and managing your credits.
- Legitimate interests (Art. 6(1)(f)). Security monitoring, fraud prevention, product analytics, and improving the accuracy of benchmark data.
- Legal obligation (Art. 6(1)(c)). Retaining transaction records and responding to lawful requests from authorities.
- Consent (Art. 6(1)(a)). Where we ask for your consent (e.g. optional marketing emails), you may withdraw it at any time.
4. How we use your data
We use the data we collect to:
- Authenticate your account and keep it secure
- Process prompts and return model responses
- Manage your credit balance and billing history
- Respond to support and contact requests
- Improve the accuracy and reliability of the service
- Detect and prevent abuse or fraudulent activity
- Comply with applicable law
5. Cookies and tracking
We use strictly necessary cookies to keep you authenticated (session cookies set by Clerk) and to remember your preferences (e.g. saved filter state). We do not use third-party advertising cookies or share your data with ad networks. Analytics, if any, are limited to aggregate, anonymised usage metrics.
6. Third-party sub-processors
We share data with the following sub-processors to operate the service:
- Clerk (clerk.com). Authentication and user management. Stores name, email, and OAuth tokens.
- Stripe (stripe.com). Payment processing. Stores transaction metadata; no raw card data passes through our systems.
- AI model providers. When you submit a prompt, the text is transmitted to the relevant third-party model API (OpenAI, Anthropic, Google DeepMind, Meta, Mistral, xAI, DeepSeek, and others). Each provider's own privacy policy governs how they handle that data — including any training, logging, or retention practices they apply. We recommend reviewing the privacy policy of each provider before submitting sensitive or confidential information. We do not control third-party providers' data practices.
- Hosting infrastructure. Our servers run on Replit's cloud infrastructure. Data is stored in the United States.
7. Data retention
We retain account data and usage history for as long as your account is active. If you delete your account, we delete your personal data within 30 days, except where we are required by law to retain it (e.g. transaction records, which are retained for 7 years for tax and accounting purposes). Contact messages are retained for up to 2 years.
8. Your rights under GDPR
If you are based in the European Economic Area, UK, or Switzerland, you have the right to:
- Access (Art. 15). Request a copy of the personal data we hold about you.
- Rectification (Art. 16). Ask us to correct inaccurate or incomplete data.
- Erasure (Art. 17). Ask us to delete your personal data ("right to be forgotten").
- Restriction (Art. 18). Ask us to restrict how we process your data.
- Portability (Art. 20). Receive your data in a structured, machine-readable format.
- Objection (Art. 21). Object to processing based on legitimate interests.
- Withdraw consent. Where processing is based on consent, withdraw it at any time without affecting the lawfulness of prior processing.
To exercise any of these rights, email us at hello@keimodel.com. We will respond within 30 days.
9. International data transfers
Our infrastructure is based in the United States. If you access the service from the EEA, UK, or Switzerland, your data is transferred to a country that may not offer the same level of data protection as your home jurisdiction. Where required, we rely on Standard Contractual Clauses (SCCs) or equivalent safeguards approved by the European Commission.
10. Contact and DPO
For privacy enquiries or to exercise your rights, contact us at hello@keimodel.com. We do not currently appoint a formal Data Protection Officer, but the above address reaches the person responsible for data protection at Keimodel.
11. US privacy rights
Depending on where you live in the United States, you may have additional privacy rights under state law. We do not sell your personal data and we do not share it for cross-context behavioural advertising.
- California (CCPA / CPRA). California residents have the right to know what personal information we collect and how we use it, the right to delete personal information we hold about them, the right to correct inaccurate information, the right to opt out of the sale or sharing of personal information (we do not sell or share it), and the right to non-discrimination for exercising these rights.
- Virginia (VCDPA), Colorado (CPA), Texas (TDPSA), and other US states. Residents of states with comprehensive privacy laws have similar rights: access, correction, deletion, portability, and the right to opt out of targeted advertising and profiling with legal or similarly significant effects. We do not engage in targeted advertising or automated decision-making that produces legal or significant effects.
To exercise any US state privacy right, submit a request to hello@keimodel.com. We will respond within the timeframe required by applicable law (45 days for most states, with one possible 45-day extension). We may need to verify your identity before processing your request.
12. Right to complain
If you believe we have not handled your data lawfully, you have the right to lodge a complaint with your local supervisory authority. In the EU, this is typically the data protection authority in your member state. In the UK, it is the Information Commissioner's Office (ICO) at ico.org.uk.
13. Changes to this policy
We may update this policy from time to time. We will notify you of material changes by updating the effective date above and, where appropriate, by email. Continued use of the service after a change constitutes acceptance of the updated policy.