Privacy Policy
Privacy Policy
Last updated 2026-09-28. The short version: we collect only what running the service requires, plus site visit statistics that store no IP address (the returning-visitor cookie only with your consent), sell nothing, run no ads, and your code is used solely for the optimization you asked for.
1. What we collect
Account: signing in with Google or GitHub gives us your email, display name and avatar, and nothing else. We never act on those accounts. Submitted code: the repository URL or archive you submit, plus the logs, reports and patches the optimization produces. Private dataset (optional): a data archive of up to 1 GB uploaded with a job, unpacked only inside the sandbox that runs your program — never on the dispatcher, in the report or in the patch — and deleted seven days after upload. Usage & billing: GPU time, model token usage, the credit ledger. Technical logs: API access and audit logs (action, time, job id). Site visit statistics: when you open a page on this site, your browser sends us one visit record. We keep the page path, the referring site’s domain, any utm campaign parameters in the link, the page language, a screen-width range, the device and browser type (parsed from the user agent, which itself is not kept), the country, region and city Cloudflare resolved for the request, and the operator of the network the request came from (an ISP, company, university or cloud provider — the ASN and its organisation name, never more specific than the organisation). We also keep a visitor id that changes every day: a hash of your IP address and user agent with a random value that is created for one UTC day and discarded after it, so ids cannot be linked across days and we never store your IP address. Visit records carry no account details (only whether you were signed in) and are deleted after 180 days. If your browser sends Global Privacy Control (GPC) or Do Not Track (DNT), nothing is recorded. No third-party tracking or advertising cookies. Analytics cookie (only with your consent): only after you press Accept on the bar at the bottom of the page do we set one first-party cookie, ao_vid (a random id, kept for 13 months), to count returning visitors. If you decline or do not answer, nothing is set; your browser only remembers your answer (ao.consent, in local storage) so we do not ask again. We receive the id and store only a keyed hash of it (the key lives on our server), never the id itself. If you have accepted and are signed in, we note on your account the first such hash we saw, to measure where sign-ups come from (for example, which site you first arrived from and how many days later you signed up). You can switch to Decline at any time with the “Cookie settings” link in the footer; the cookie is deleted immediately. Apart from this, the only cookie is your session.
2. What it is used for
To run the optimization you requested, for billing and reconciliation, abuse prevention and security auditing, and to notify you when a run finishes. Your code is used only inside the isolated sandbox and pipeline executing your job, and is never used to train models or for other customers.
3. Who we share with
Only processors required to run the service: Cloudflare (hosting & storage), CompShare / UCloud (the GPU hosts we rent by the hour, located in mainland China, on which your code runs only inside an isolated sandbox), Anthropic (model calls by the optimization agent), Dodo Payments (payments, as merchant of record for cards and WeChat Pay alike; we never see or store your card or wallet details), Google / GitHub (sign-in only). We sell nothing and share nothing with advertisers.
4. Security and cross-border transfers
All traffic is encrypted with TLS; uploaded code and datasets live in private buckets isolated per account (a dataset is unpacked only inside the sandbox that runs your program and is deleted seven days after upload); payment credentials never touch our systems (the merchants of record handle them directly); internal access to customer data leaves an audit trail. The processors above (Cloudflare, CompShare / UCloud, Anthropic, Dodo Payments) may process data outside your jurisdiction; we work only with processors necessary to provide the service.
5. Email
We send you two kinds of mail. Job notifications (the free estimate is ready, the mid-run range, the run finished) are a subscription: every one carries an unsubscribe link, your mail client’s own unsubscribe button works, and you can turn them off any time under Email notifications on your account page. Sign-in codes and replies to your own support requests are not a subscription — each answers something you just did — and are always sent. We send no marketing mail and give your address to nobody for marketing.
6. Your rights
You may request a copy of the data we hold about you, corrections, or deletion at any time. Mandatory data-protection rights in your jurisdiction (e.g. under GDPR / CCPA) are unaffected by this policy.
7. Contact
Privacy questions: hi@autooptm.com.