legal
Privacy.
What is stored, where it sits, who else is involved, and how to get rid of it.
Who is responsible
Until this is filled in, the responsible party for the purposes of the GDPR is not stated on this page. See the imprint.
What we store
Your account. Email address, an optional display name, a password hash (PBKDF2- SHA256, salted and peppered — never the password itself), the time the account was created and last signed in, and your credit balance.
Your work. Conversations, the requests you send and the answers you receive, kept with your account so you can find them again.
Usage. Per request: which model answered, the token counts reported by the provider, the cost, the latency and the outcome. This is what the price next to each answer is calculated from.
Security log. Sign-ins, failed sign-in attempts, password and email changes, and account deletion — with IP address and user agent. Without this, a break-in would go unnoticed.
Email log. Recipient, template and delivery outcome of the messages we send you. Not their contents.
Who else is involved
CALEST is not able to run without these. Each one receives only what it needs to do its part.
- Hosting, database and rate limiting. All application data sits here.
- Routes requests to the model providers. Receives the compiled request.
- Payments. Receives what a payment needs; we never see your card details.
- Transactional email — confirmation and password reset.
Training
What you type is used to carry out your request and nothing else. It is not sold, and it is not handed to anyone to train a model on.
Deleting it
You can delete a single conversation at any time, or the whole account from settings.
Deleting the account removes every session, token and API key outright, and replaces your address, name and password hash. The account row itself is retained in anonymised form so that billing and usage records do not point at nothing — after that step it carries no personal data, and the address is free to register again.
Your rights
Under the GDPR you can request access, correction, deletion, restriction and portability, and you can object to processing. You may also complain to a supervisory authority.