Privacy Policy
Last updated: July 2026
What we store
When you create a NinjaCode account we store your email address, optional display name and avatar, hashed API keys, hashed session tokens, credit balances and usage metadata (model, provider, token counts, price and timestamp for each request).
What we never store
Prompt contents and model responses transiting the gateway are not persisted and are never used to train models. With bring-your-own-keys, requests go directly from your editor to the model provider and never reach our servers at all.
Social login
When you sign in with GitHub, Google or Apple, we receive your provider user ID, verified email and (when available) name and avatar. We store only these fields to link your account. We never receive your provider password and request no repository or account write access.
Cookies
We use a single httpOnly session cookie for authentication on this site. No third-party analytics or advertising cookies are set.
Payments
Payments are processed by Stripe. We never see or store your card details; we store only your Stripe customer reference and payment outcomes.
Your rights
You can export your usage data from the dashboard, revoke sessions and API keys at any time, and delete your account entirely from Settings — deletion removes your account record, keys, sessions and usage history.
Contact
Questions? Email privacy@ninjacode.dev.