This Privacy Policy explains how Polymeti (“Polymeti”, “we”, “us”) handles your information when you use the Polymeti web application at polymeti.com. Polymeti is built to keep as little of your data as possible: your conversations live in your own browser, not on our servers.
1. Who we are
Polymeti is the data controller for the personal data described below. For any privacy question, or to exercise your rights, contact us at [email protected].
2. What we store, and where
On our servers
- Account identity. When you log in with Google, we store your email address and display name to identify your account. We never receive your Google password.
- Usage counts. After each answer, your browser reports which model answered and how many tokens it used. We store these numbers with your account, but with no link to any chat or message, to see which models people prefer. We store counts only — never the content of your messages. Your own usage page is computed in your browser and does not read them.
- Operator-assigned API keys (invited users only). If we provide you with an API key, it is stored encrypted at rest and delivered to your logged-in browser, which uses it to call the AI provider directly. Keys you bring yourself are not stored on our servers (see below).
In your browser
- Your conversations. All chats, messages, attachments and app settings are stored locally in your browser (IndexedDB). They are not uploaded to or stored on our servers.
- Your own API keys (BYOK). Keys you add are kept in your browser. A key for a provider marked "Direct" is sent from your browser straight to that provider. A key for a provider marked "Via our proxy" passes through our proxy on its way there (section 3). No key is ever stored on our servers.
- Optional Drive backup. If you enable sync, a copy of your chats and the other data you choose to sync is uploaded to your own Google Drive. It is not routed through or copied to our servers. By default it is encrypted before it leaves your device, and the key that unlocks it stays with you: we never receive your recovery key or your passphrase, and cannot read or recover your backup. If you choose no encryption, the copy is stored as it is, readable by anyone who can open your Google Drive, and API keys are not synced.
3. How your prompts are processed
Polymeti is an interface to third-party AI providers. When you send a message, your prompt and any attachments go to the AI provider you select so it can generate a response. The app marks every provider in one of two ways, next to its key in Settings and next to the model when you write (see How your data flows):
- Direct. Your browser sends the request straight to the provider. It does not pass through our servers.
- Via our proxy. The provider does not accept requests from a browser, so your browser sends the request to our server, which forwards it to the provider unchanged and streams the answer back. Your key, your prompt and the response pass through our server on the way. We do not store them, write them to any log, or use them for anything else. Our login cookies are removed before a request is forwarded. Today this applies to Z.ai (GLM models) only.
Each provider processes your data under its own privacy policy and terms — we encourage you to review them:
- OpenAI Privacy Policy
- Anthropic Privacy Policy
- Google Privacy Policy
- xAI Privacy Policy
- DeepSeek Privacy Policy
- OpenRouter Privacy Policy
- Z.ai Privacy Policy
With a "Direct" provider the exchange happens between your browser and the provider, so we never receive your prompts or the responses. With a "Via our proxy" provider we pass them on without keeping them. Either way we cannot use them to train any model, or for anything else.
4. Cookies
We use only strictly-necessary cookies: a secure, HttpOnly session cookie that keeps you logged in, an anti-forgery (CSRF) cookie, and a short-lived cookie that completes the Google login handshake. We do not use advertising or third-party analytics cookies, so no cookie-consent banner is required.
To count visits we use Cloudflare Web Analytics, which sets no cookies and does not track you across sites. On each page view it records the page address (for a chat, that includes its ID, never its content), the referring site, your browser and device type, your country, and how fast the page loaded.
5. Legal bases (GDPR)
- Performance of a contract — to provide the service you log in to use.
- Legitimate interests — to keep the service secure and prevent abuse.
- Consent — where we ask for it specifically; you may withdraw it at any time.
6. Who we share data with
We do not sell your personal data. Your prompts reach a provider marked "Direct" straight from your browser (section 3), and that flow does not pass through our systems. A request to a provider marked "Via our proxy" passes through our proxy, and with it through our hosting and infrastructure providers, without being kept. Beyond that, we share data only with those providers (Microsoft Azure for hosting, Cloudflare for edge delivery, security and visit counts), and with authorities where required by law.
7. International transfers
Some providers and infrastructure may process data outside the European Economic Area (for example, in the United States). Where that happens, the transfer relies on the safeguards offered by those providers, such as Standard Contractual Clauses.
8. How long we keep data
- Account identity — for as long as your account exists.
- Usage counts — until you erase them or close your account.
- Browser data — under your control; it remains until you delete it or clear your browser storage.
9. Your rights
Under the GDPR and similar laws you have the right to access, correct, delete, export, and object to the processing of your personal data. You can act on the most common ones directly in the app:
- Delete your usage history — Settings → Account → Privacy.
- Delete your account — Settings → Account → Danger Zone. This removes your server-side identity and usage data.
- Delete your conversations — clear them in the app or clear your browser storage; they are local to your device.
For any other request, or to lodge a complaint, contact us at [email protected]. You also have the right to complain to your local data-protection authority.
10. Security
We protect your session with a secure, HttpOnly cookie, serve the site over HTTPS with HSTS, apply a Content-Security-Policy, and encrypt operator-assigned API keys at rest. No system is perfectly secure, but we take reasonable measures to protect your data.
11. Children
Polymeti is not intended for children under 16, and we do not knowingly collect their personal data.
12. Changes to this policy
We may update this policy from time to time. We will revise the “last updated” date above and, for material changes, provide a more prominent notice.
13. Contact
Questions about this policy or your data? Email [email protected].