Updated August 2026

Security

An overview of how the app is built with respect to your credentials and data.

Key handling

Provider API keys are kept in your browser's local storage and sent only with the generation request that needs them. They are not stored in our database and are not written to logs.

Authentication

Sign-in uses email and password or Google sign-in. Sessions are managed by our authentication provider and protected routes redirect signed-out visitors.

Shared devices

Because keys live in the browser, disconnect your providers in Settings before leaving a shared or public computer.

Reporting a vulnerability

If you believe you have found a security issue, please reach out through the Contact page with steps to reproduce. Please do not publicly disclose before we have had a chance to respond.