1. Data controller
The data controller for your personal data is Keimodel ("we", "us", "our"), based in California, United States, and reachable at hello@keimodel.com.
2. What data we collect
- Account data. When you register, we collect your name, email address, and profile information through Clerk, our authentication provider. You may also sign in with a third-party OAuth provider (Google, GitHub), in which case we receive the data that provider shares.
- Usage data. We log which models you run, the prompts and files you submit, and your in-app activity, and we store your run history so you can reopen it. We use this data to deliver the service and improve it.
- API keys. If you add your own OpenRouter key, we store it encrypted (AES-256-GCM) and use it only to send your model requests. You can remove it in Settings at any time.
- Payment data. If you purchase credits, your payment details are processed by Stripe. We store only the transaction outcome and credit balance, we never see your card number or bank details.
- Contact messages. If you contact us via the contact form, we store your name, email address, subject, and message.
- Technical data. We may collect your IP address, browser type, and device type for security and analytics purposes.
3. Legal basis for processing (GDPR)
We process your personal data on the following legal bases under GDPR Article 6:
- Contract performance (Art. 6(1)(b)). Processing necessary to provide the service you signed up for, including running tasks in the studios, storing your history, and managing your credits.
- Legitimate interests (Art. 6(1)(f)). Security monitoring, fraud prevention, product analytics, and improving the accuracy of benchmark data.
- Legal obligation (Art. 6(1)(c)). Retaining transaction records and responding to lawful requests from authorities.
- Consent (Art. 6(1)(a)). Where we ask for your consent (e.g. optional marketing emails), you may withdraw it at any time.
4. How we use your data
We use the data we collect to:
- Authenticate your account and keep it secure
- Process prompts and return model responses
- Manage your credit balance and billing history
- Respond to support and contact requests
- Improve the accuracy and reliability of the service
- Detect and prevent abuse or fraudulent activity
- Comply with applicable law
5. Cookies and tracking
We use strictly necessary cookies to keep you authenticated (session cookies set by Clerk) and store your preferences, such as the theme, in your browser. We do not use advertising cookies, we do not share your data with ad networks, and we do not run third-party analytics scripts.
6. Third-party sub-processors
We share data with the following sub-processors to operate the service:
- Clerk (clerk.com). Authentication and user management. Stores name, email, and OAuth tokens.
- Stripe (stripe.com). Payment processing. Stores transaction metadata; no raw card data passes through our systems.
- OpenRouter (openrouter.ai). Routes every model request to the provider that runs the model. Prompts, attachments and responses pass through OpenRouter on the way. When web search is on, OpenRouter runs the search for your prompt.
- AI model providers. When you submit a prompt, the text is transmitted to the relevant third-party model API (OpenAI, Anthropic, Google DeepMind, Meta, Mistral, xAI, DeepSeek, and others). Each provider's own privacy policy governs how they handle that data, including any training, logging, or retention practices they apply. We do not control third-party providers' data practices. Do not submit sensitive personal data, such as health, financial or government ID information, in prompts or files.
- TypeSafe (Jev). Jev, TypeSafe's decision model, receives data through OpenRouter in three cases: when a synthesis runs (your prompt, each model's response and the positions the synthesis found), when you run a meaning check in the Translation Studio (the source sentences and the translations), and when you ask Jev about the rows of a CSV in the Data Studio (the rows and your questions). OpenRouter lists TypeSafe as not training on prompts and not retaining prompt data.
- Railway (railway.app). Hosting and database. Our servers and database run on Railway. Data is stored in the United States.
7. Data retention
We retain account data and usage history for as long as your account is active. If you delete your account, we delete your personal data within 30 days, except where we are required by law to retain it (e.g. transaction records, which are retained for 7 years for tax and accounting purposes). Contact messages are retained for up to 2 years.
8. Your rights under GDPR
If you are based in the European Economic Area, UK, or Switzerland, you have the right to:
- Access (Art. 15). Request a copy of the personal data we hold about you.
- Rectification (Art. 16). Ask us to correct inaccurate or incomplete data.
- Erasure (Art. 17). Ask us to delete your personal data ("right to be forgotten").
- Restriction (Art. 18). Ask us to restrict how we process your data.
- Portability (Art. 20). Receive your data in a structured, machine-readable format.
- Objection (Art. 21). Object to processing based on legitimate interests.
- Withdraw consent. Where processing is based on consent, withdraw it at any time without affecting the lawfulness of prior processing.
- Automated decisions (Art. 22). The synthesis and Jev evaluate model answers, not people. We make no decisions about you by automated means that have legal or similarly significant effects.
To exercise any of these rights, email us at hello@keimodel.com. We will respond within 30 days.
9. International data transfers
We are based in California, and our infrastructure is in the United States. If you access the service from the EEA, UK, or Switzerland, your data is transferred to a country that may not offer the same level of data protection as your home jurisdiction. Where required, we rely on Standard Contractual Clauses (SCCs) or equivalent safeguards approved by the European Commission.
For privacy inquiries or to exercise your rights, contact us at hello@keimodel.com. We do not currently appoint a formal Data Protection Officer, but the above address reaches the person responsible for data protection at Keimodel.
11. US privacy rights
Depending on where you live in the United States, you may have additional privacy rights under state law. We do not sell your personal data and we do not share it for cross-context behavioral advertising.
- California (CCPA / CPRA). California residents have the right to know what personal information we collect and how we use it, the right to delete personal information we hold about them, the right to correct inaccurate information, the right to opt out of the sale or sharing of personal information (we do not sell or share it), and the right to non-discrimination for exercising these rights.
- Virginia (VCDPA), Colorado (CPA), Texas (TDPSA), and other US states. Residents of states with comprehensive privacy laws have similar rights: access, correction, deletion, portability, and the right to opt out of targeted advertising and profiling with legal or similarly significant effects. We do not engage in targeted advertising or automated decision-making that produces legal or significant effects.
To exercise any US state privacy right, submit a request to hello@keimodel.com. We will respond within the timeframe required by applicable law (45 days for most states, with one possible 45-day extension). We may need to verify your identity before processing your request. We treat a Global Privacy Control (GPC) signal from your browser as a request to opt out of the sale or sharing of personal data. We do not sell or share personal data, so the signal changes nothing about how we process yours. We do not track you across other websites, so a browser's Do Not Track signal also changes nothing.
12. Children's privacy
Keimodel is not directed to children under 13, and we do not knowingly collect personal data from them. If you believe a child under 13 has given us personal data, email hello@keimodel.com and we will delete it.
13. Right to complain
If you believe we have not handled your data lawfully, you have the right to lodge a complaint with your local supervisory authority. In the EU, this is typically the data protection authority in your member state. In the UK, it is the Information Commissioner's Office (ICO) at ico.org.uk.
14. Changes to this policy
We may update this policy from time to time. We will notify you of material changes by updating the effective date above and, where appropriate, by email. Continued use of the service after a change constitutes acceptance of the updated policy.