Legal

Privacy policy

Last updated: 1 October 2026

This policy explains what typeai.dev collects, why, and the choices you have.

What we collect

  • Account details: your name, email address and a hashed version of your password.
  • API keys: a hash of each key and its first few characters so you can recognise it. We can't see your full key after it's created.
  • Usage metadata: for each API call, the endpoint, time, and token counts, linked to your account and key.
  • Messages: anything you send through the contact form.
  • Session cookie: a signed cookie that keeps you logged in. We don't use advertising or tracking cookies.

Content you send to the API

The text, code or logs you send are processed to produce a result. We don't store that content in our database. To produce results, the content is sent to our model provider, TypeSafe, and is subject to their terms and privacy policy.

Avoid sending personal data or secrets you don't need to — the guardrails endpoint can help you detect them.

How we use information

  • To run your account, authenticate requests and enforce rate limits.
  • To show you your usage, and to monitor the Service for abuse and errors.
  • To reply to your messages.

We don't sell your personal information.

Retention

We keep account information while your account is open. Usage metadata is kept for as long as needed to operate and secure the Service. Ask us to delete your account and associated data at any time.

Your rights

Depending on where you live, you may have the right to access, correct, export or delete your personal data, or to object to certain processing. Contact us to make a request.

Security

Passwords are hashed with scrypt and API keys with SHA-256. Access to the admin console is restricted to authorised staff.

Changes

We'll post any changes on this page and update the date above.