Updated August 2026
Security
An overview of how the app is built with respect to your credentials and data.
Key handling
Provider API keys are kept in your browser's local storage and sent only with the generation request that needs them. They are not stored in our database and are not written to logs.
Authentication
Sign-in uses email and password or Google sign-in. Sessions are managed by our authentication provider and protected routes redirect signed-out visitors.
Shared devices
Because keys live in the browser, disconnect your providers in Settings before leaving a shared or public computer.
Reporting a vulnerability
If you believe you have found a security issue, please reach out through the Contact page with steps to reproduce. Please do not publicly disclose before we have had a chance to respond.