Privacy Policy

What we collect, why, and what we deliberately do not keep. Last updated: 17 August 2026. The current version always lives at compreslm.com/app/privacy.

1. Who processes your data

Individual Entrepreneur Mikita Valkunovich (identification number 300412284, registered in Georgia; see the Terms of Service for full registration detail) operates CompresLM and acts as the data controller for the account data described below. We process personal data under the Law of Georgia on Personal Data Protection and, where it applies to you, the EU or UK General Data Protection Regulation.

2. What we collect

  • Account data: your email address, an argon2 password hash (never the plain password), and account creation/verification timestamps.
  • API token data: a hash and short prefix of each CompresLM token you generate — never the full token after the one time it's shown to you.
  • Usage metering: per-request token counts, estimated cost before/after compression, model name, and timestamp — used to run the free tier and billing. This is numeric metering only.
  • Billing settings and records: the identifiers your payment method has at Paddle (customer, subscription), whether billing is active or suspended, your monthly spending limit if you set one, any bonus free tokens granted, and one row per invoice with its amount, status and dates. No card number, expiry or CVC ever reaches us — see section 5.
  • Referral program (only if you join it): the email of the Payoneer account you name for payouts, your referral code, which accounts signed up through your link, the commission ledger, and payout requests with their outcomes. If you signed up through someone's referral link, we record which partner referred you; that partner sees your email in masked form only (e.g. a***@example.com), never in full.
  • Session cookie: a signed, httponly, secure cookie that identifies your logged-in session. No analytics or advertising cookies are set.
  • Playground rate limiting: the public playground works without an account, so to keep two free runs per visitor we store a salted SHA-256 hash of your IP address alongside the token counts and cost of each run. The address itself is never written down and cannot be recovered from the hash; the row exists only to count runs and to cap what the demo spends. The document, the question and the answers are not stored — the playground is subject to section 3 exactly like the API.

3. What we deliberately do not store

  • Your upstream provider API key (OpenAI/Anthropic/local): read from the X-LLM-API-Key header, held in memory only for the duration of that single request, then discarded. It is never written to a database, file, or log.
  • Prompt and completion content: the text you send and receive is processed transiently to apply compression and is forwarded to your chosen upstream provider; we do not retain it as a product dataset, and it is not used to train any model.
  • Model replies: there is no response cache. The answer your provider returns is passed straight back to you and is not written to any store, not even briefly — so no reply of yours can be read back, or served to anyone else, after your call finishes.
  • Questions typed into the site assistant (the chat widget on our public pages): each turn, the recent conversation is sent from your browser to our model provider (OpenRouter, Inc.) to generate the answer, and is processed transiently on our side — we do not store the conversation. Your copy of it lives in your own browser (localStorage) for up to 12 hours. Don't paste secrets or personal data into the widget.
  • File, log, and tool-output content sent via the local MCP tool (compreslm-mcp): processed transiently in memory to compute the compressed result, then discarded the same way as proxy request content above. Only aggregate token counts are kept, for billing and your dashboard.

Short-lived operational logs (e.g. error traces from our hosting provider) may exist for a limited period for debugging and abuse prevention. They are not mined for content, not sold, and not shared with third parties beyond what section 5 describes.

4. Legal basis and use

We process account and metering data to provide the service you signed up for (performance of a contract), to enforce the free tier and calculate fees (performance of a contract), to keep accounting and tax records (legal obligation), and to protect the service against abuse (legitimate interests). We do not sell personal data, and we do not use it for advertising or automated decision-making that produces legal effects for you.

5. Who else sees data

  • MailerSend (mailersend.com) — sends your email-verification code. Receives your email address for that purpose only.
  • Your chosen upstream LLM provider (OpenAI, Anthropic, or your own self-hosted endpoint) — receives the (compressed) request content directly, using the key you supplied, exactly as if you had called them yourself. Their own privacy policy governs what happens on their side.
  • Our hosting/database provider (Railway) — stores account and metering data on our behalf, under its own infrastructure-level security controls.
  • Paddle — our payment processor and merchant of record. Card numbers are collected and stored by Paddle; CompresLM never sees or stores them. Because Paddle is the merchant of record it is an independent controller of the purchase data it collects, under its own privacy policy.
  • Formspree — relays messages sent through the contact form, and receives only what you put in that form.

These providers operate outside Georgia, so using the service involves transferring data internationally, including to the EU, the UK and the United States. Where the GDPR applies, we rely on the transfer safeguards offered by each provider — standard contractual clauses or an adequacy decision. We do not sell or share data with anyone else, and we disclose it to authorities only where we are legally required to.

5a. Your content, and other people's data inside it

The documents, prompts and files you send are your content. If they contain personal data about other people — your customers, employees or users — then for that data you are the controller and we act as your processor: we process it only to carry out the request you made, only for as long as that request takes, and we never retain it afterwards (see section 3).

You are responsible for having a lawful basis to send that content through the service, and for telling the people concerned if the law requires it. Please do not send special categories of data (health, biometrics, political or religious beliefs and similar) unless you have satisfied yourself that doing so is lawful. If you need a separate data processing agreement, contact us.

6. Retention

Account data is kept while your account is active. Usage-metering records are kept as long as needed for billing, accounting, and tax records (which may exceed account lifetime under applicable law). You can request deletion of your account and associated personal data at any time (see section 8); metering rows required for completed billing periods may be retained in anonymized/aggregated form.

7. Security

  • Passwords hashed with argon2, never stored or logged in plain text.
  • Session cookies are signed, httponly, and secure.
  • All traffic to the service runs over TLS.
  • Provider API keys travel per-request and are never persisted (section 3).

8. Your rights

Depending on where you live, you may have the right to access, correct, export, or delete your personal data, or to object to or restrict certain processing. To exercise any of these, contact us (below); we will respond within a reasonable time and may need to verify your identity first. Exercising these rights is free.

If you think we have handled your data wrongly, you may complain to the Personal Data Protection Service of Georgia (personaldata.ge) or, where the GDPR applies to you, to the supervisory authority where you live or work. We would appreciate the chance to fix it first.

9. Children

CompresLM is not directed at, and should not be used by, anyone under 18.

10. Changes

We may update this Policy unilaterally. The current version is always published at /app/privacy and carries the date it last changed; that published version is the operative one. For a change that materially reduces your rights we will give at least 14 days' notice to your account email, and continued use after it takes effect constitutes acceptance. Changes required by law may take effect immediately.

11. Contact

Privacy questions or data requests: use the contact form.