m3ekLocal-first
Privacy

What we hold, and what never reaches us

Last updated 25 August 2026

The short version

This summary is here to be read. The sections below are the binding text.

1. Who is responsible

The controller of the personal data described here is m3ek, contactable at [email protected]. Where this policy says "we", it means that entity.

2. What we collect, and why

Account

Your email address, the time the account was created, the time it was last used, and which plan it is on. The lawful basis is performance of a contract: without an email address there is no way to sign you in and no way to attach a licence to you.

Beta testers list

If you leave your details on the home page to be told when the trial opens, we keep the name and email address you typed, the time you left them, and which page they came from. The lawful basis is consent, given by submitting the form. Leaving your details there does not create an account, does not sign you in, and does not put you on any other mailing list. We use the address for one thing: to write to you when a place opens up. Ask us and we will remove the entry; you do not need an account to ask.

Sign-in codes and sessions

When you ask to sign in we generate a six-digit code and send it to you. We do not keep the code itself — only a scrambled fingerprint of it, for ten minutes, which is enough to check the code you type but cannot be turned back into the code. The pass that keeps you signed in afterwards is kept the same way. Someone who obtained a copy of our database could not use it to sign in as you.

Server logs

Our web server records, for each request to the website, the IP address it came from, the time, the page asked for, and the browser and operating system your device reports. The lawful basis is legitimate interest in keeping the service available and detecting abuse. Logs are deleted after 30 days.

Page counts

We count how many times each page on this site was opened, per day. That is the whole of it: a date, a path and a number. No IP address, no user agent, no cookie, nothing that could be traced back to you or joined to anything else.

In the EU, the EEA and the UK we ask first, and no is a real answer. A notice appears at the foot of the home page the first time you open it, and nothing is counted until you allow it. If you decline, the page never sends the request, so there is nothing to record and nothing to delete — the counter is fed by the page, not by our server watching you arrive, precisely so that declining changes what happens rather than only what we promise. The lawful basis is your consent.

Elsewhere the count runs without asking, because what it holds — a date, a path and a number — is not personal data and identifies nobody. You can still switch it off at any time, wherever you are, using Privacy choices at the foot of the home page or the button below.

We work out which of the two applies from the country your network connection appears to be in, as reported by our content delivery network. We are not told your location beyond that country, we do not store it, and when it cannot be determined we treat the visit as one that has to be asked.

Alongside it we record where the visit came from: the name of the website that linked to us, or the campaign name written into the link you followed. We keep only that name, never the full web address you arrived on — a link someone sends you can carry all sorts of things in it, and storing those would mean keeping them on their behalf. If you go on to join the beta list, that name is saved with your entry, so we can tell which advertising is worth paying for. It records where you came from, not who you are, and it stores nothing on your device.

Payment

We do not take payments yet. Nothing on this site charges anyone, and we hold no billing details of any kind. When paid plans open we will name the payment processor here before the first charge, and we will not receive or store card numbers at any point — the processor handles those.

What we do not collect

We do not collect the content of the Reddit threads you read, the drafts you write, the communities you target, your product profile, or your Reddit username. Those are produced and stored by the workbench on your own computer, in a file that never leaves it.

3. Model calls

The workbench uses large language models to draft replies and to probe answer engines. Today there is one arrangement, and it does not involve us. You supply your own key, or you point the workbench at a model tool already installed on your computer. Either way the request goes from your machine straight to the provider. The thread text and the draft never reach our server, because there is nothing on our side built to receive them.

Which provider a request reaches depends on what you set up: Anthropic or OpenAI if you entered a key, or whichever service the tool you chose connects to. We do not pick it for you and we do not see it.

The paid plan describes model access run on our infrastructure. That is not built yet. When it is, the text of the thread you selected and the draft being produced will pass through our server so the call can be made and metered — and we will say so here before it goes live, not after. Until then, treat every model call as leaving your machine directly.

Model providers commit in their contracts not to train on what is sent to them through the paid plans a key like yours is on. That is their commitment rather than ours; if it matters to you, use your own key, where the question does not arise.

4. Who else processes your data

ProcessorPurposeWhat it sees
Amazon Web ServicesHosting the websiteEverything stored on the server: your email, your plan, the scrambled fingerprints of your sign-in, and the logs
CloudflareRouting the domain and delivering the site over an encrypted connectionDetails of each request, including your IP address
BrevoSign-in emailsYour email address and the sign-in code, at the moment it is sent
Model providers (Anthropic, OpenAI, or whichever service your own tool connects to) Drafting and probing The thread text and draft — sent from your machine, not ours, under whatever terms you have with that provider

We do not sell personal data and we do not share it for advertising.

5. How long we keep it

DataKept for
Account (email, plan)Until you delete the account
Beta testers list (name, email)Until the trial opens and we have written to you, or until you ask us to remove it
Sign-in code, as a scrambled fingerprint10 minutes, then deleted
The pass that keeps you signed in, as a scrambled fingerprint30 days, or until you sign out
Server logs30 days
Visit counts (a date, a page, where it came from, and a number) Kept as a running total; they contain no personal data
Payment records7 years, where tax law requires it

6. Your rights

If you are in the UK or the EEA, the GDPR gives you the right to access your data, to correct it, to have it erased, to receive it in a portable form, to restrict or object to processing, and to withdraw consent. Exercise any of them by writing to [email protected]; we will answer within 30 days.

Erasure has one exception: payment records we are required to retain for tax purposes are kept for the period in section 5, under Article 17(3)(b), with identifying details removed where possible.

You also have the right to complain to your national data protection authority.

7. Cookies and local storage

We set no cookies. The website keeps the pass that signs you in inside your browser's own storage, so that you are not asked to sign in again on every page; it is removed when you sign out. The workbench, running on your own machine, keeps two more items there: whether you have already seen the introduction, and the list of buyer questions you typed. Those never leave your computer, and none of it is sent to any third party.

Your answer to the question about counting visits, described in section 2, is kept on your device so we do not ask again on every visit. It holds one word, yes or no, and it is never sent to us as anything other than the presence or absence of a count.

The home page also remembers two things for the length of one browsing session — whether you closed the sign-up box, and whether you already joined the list. They exist so we do not put the same box in front of you on every page. They are cleared when you close the tab, they are never sent to us, and they hold nothing but a yes.

We run no analytics scripts and embed no third-party trackers. Fonts are served from our own server rather than a font CDN.

Change your choice

This clears the answer stored on this device. The next time you open the home page you will be asked again, and nothing is counted in the meantime.

8. Security

The site is served over an encrypted connection, so what passes between your device and us cannot be read on the way. Sign-in codes and the pass that keeps you signed in exist in our database only as scrambled fingerprints. Wrong codes are counted and a code stops working after five attempts. There is a limit on how often sign-in can be attempted from the same internet connection.

If a breach affects your personal data we will notify the relevant supervisory authority within 72 hours of becoming aware of it, and notify you without undue delay where the risk to you is high.

9. International transfers

Our servers and processors are located in Amazon Web Services in us-east-1 (N. Virginia, United States), with Cloudflare as the network edge. Where personal data is transferred outside the UK or EEA, that transfer relies on the European Commission's Standard Contractual Clauses, which both Amazon Web Services and Cloudflare incorporate into their data processing agreements.

10. Children

The service is not intended for anyone under 16 and we do not knowingly create accounts for them. If you believe a child has an account, write to [email protected] and we will delete it.

11. Changes

If we change this policy we will update the date at the top and, where the change is material, email account holders before it takes effect.