Privacy policy
We never store the content of your requests or the model's replies. There are no analytics, no tracking cookies and no third-party scripts on this site. This page lists everything we do keep.
What we store
From Discord, when you sign in
- Your Discord user ID, username and avatar hash
- Your email address, as Discord reports it
- Your account's creation date, checked once to confirm eligibility
We ask Discord for the minimum scopes needed to do that. The access token Discord issues is used once, immediately, and never stored.
About your usage
- Which model each request used, and when
- Token counts: input, output, and how much was served from cache
- What the request cost, and how long it took
- The HTTP status we returned
- Every credit movement on your account, as an append-only ledger
For authentication
- A SHA-256 hash of each API key, plus its first few characters so we can find it. We cannot recover the key itself.
- A SHA-256 hash of your dashboard session token. A dump of our session table yields nothing anyone can sign in with.
What we never store
- The content of your requests. Not your prompts, not your character cards, not your lorebooks, not your chat history.
- The content of the model's replies.
- Your IP address, beyond the transient logs our infrastructure keeps
- Your Discord password — we never see it; that is the point of OAuth
- Payment card details — those go to our payment provider, never to us
We could not hand over your prompts if we were asked, because we do not have them.
Cookies
One cookie: your session, so the dashboard knows who you are. It is HTTP-only and holds a random token, not your identity. There are no analytics or advertising cookies, which is why there is no cookie banner — we have nothing to ask consent for.
Who else sees your data
- Model providers. Your request has to reach a model, so its content passes through the provider serving that model, subject to their own privacy terms. We forward the request; we do not keep it.
- Our payment provider, who acts as merchant of record and handles your payment details and tax.
- Our hosting and database providers, who hold the data described above on our behalf.
We do not sell data, and we do not share it for advertising.
How long we keep it
Usage and ledger records are kept while your account exists, because they are the record of what you were charged. Expired dashboard sessions are deleted automatically. If you close your account we delete your profile and keys; we may retain billing records for as long as tax law requires.
Your rights
You can ask for a copy of what we hold about you, ask us to correct it, or ask us to delete your account and its data. Email umbradevelopers1@gmail.com from the address on your account and we will action it.
Umbra is operated from Manitoba, Canada, so Canadian federal privacy law — PIPEDA — applies, and you can complain to the Office of the Privacy Commissioner of Canada if you think we have mishandled your data. If you are in the UK or the EU, the GDPR gives you further rights including data portability and the right to object, and you may complain to your own supervisory authority. We will honour whichever gives you more.
Children
Umbra is not for anyone under 18. Accounts must be linked to a Discord account at least 30 days old with a verified email, and we close any account we learn belongs to a minor.
Changes
If we start storing something new, this page changes before that happens and the date at the top changes with it.
Contact
Youssef Abdrabbo — umbradevelopers1@gmail.com