Privacy Policy
Last updated 2026-09-20
This policy explains what 1stAuthor collects when you use the website, the API and the dashboard, why, and what you can do about it. We collect as little as running a metered API requires.
1. What we collect
- Account. Your email address; with Google sign-in also your name, profile picture and Google account id. With email sign-in, only the address. Optional name and organisation if you enter them in Settings.
- API keys. We store only a hash of each key, its label, scopes, caps and when it was last used.
- Usage. For every billable request: a request id, the key used, the domain, operation and view, credits charged or refunded, HTTP status, latency, timestamp and the calling IP address. We do not store the text of your queries in the usage log.
- Caches. Search queries and document reads are cached briefly (minutes to an hour) so that repeated requests are fast; caches are keyed by request content and expire automatically.
- Sessions and audit. Dashboard sessions (a random id, when created, IP and browser); an audit log of sign-ins and key or plan changes.
- Payments. Handled by Stripe. We keep your Stripe customer id, subscription status and a ledger of credits; we never see your card number.
- Server logs. Standard request logs (path, status, latency, user agent, IP), kept for a short rotation period.
2. How we use it
To run the Service: authenticate you, meter and bill usage, enforce rate limits and key scopes, detect abuse, debug problems you report (quote the request_id), and understand aggregate usage per domain. We do not sell personal data and do not use it for advertising.
3. Where your queries go
Answering a request means sending your query to the systems that hold the corpus: our own indexes, and for some domains upstream providers — the Papers and Web domains run on the DeepXiv service; Web questions are also sent to a web search provider; agentic answers are generated with third-party language models. These providers receive the query text needed to answer and are bound by their own terms. We do not send them your account details.
4. Cookies and local storage
fa_session— the dashboard session cookie (HttpOnly, 30 days, refreshed while you use it). It is the only cookie we set.- Browser local storage holds your theme, language, and — only if you choose “use it in the playground” — an API key, so the playground can call the API from your browser. It never leaves your browser except in requests you make.
- No analytics or advertising trackers.
5. Retention
Account data is kept while your account exists. Usage events are kept for billing and dispute purposes and then aggregated or deleted; daily aggregates are kept longer. Caches expire within an hour. Server logs rotate within weeks. When you delete your account, your user record, keys, wallet and ledger are deleted; Stripe keeps what it must for tax and fraud purposes.
6. Your choices
- See and change your profile, keys and plan in the dashboard; see every billable request under Usage.
- Sign out of all devices from Settings.
- Delete your account from Settings (cancel any subscription first).
- Ask us for a copy or deletion of your data, or to correct it, at tommy@chien.io.
7. Security
Keys are stored hashed; sessions are server-side and revocable; write requests from the browser are origin-checked; production traffic is TLS-only. No system is perfectly secure — if you believe your key or account is compromised, revoke the key or sign out everywhere and tell us.
8. Children
The Service is for developers and professionals and is not directed at children under 16. We do not knowingly collect their data.
9. Changes
We update this page when our practices change, with a new date at the top; material changes are also announced by email to account holders.