PolymetiBack to home

Privacy Policy

Last updated: 6 July 2026

This Privacy Policy explains how Polymeti (“Polymeti”, “we”, “us”) handles your information when you use the Polymeti web application at polymeti.com. Polymeti is built to keep as little of your data as possible: your conversations live in your own browser, not on our servers.

1. Who we are

Polymeti is the data controller for the personal data described below. For any privacy question, or to exercise your rights, contact us at [email protected].

2. What we store, and where

On our servers

  • Account identity. When you sign in with Google, we store your email address and display name to identify your account. We never receive your Google password.
  • Usage counts. After each request, your browser reports how many tokens it used and we store those numbers so you can track your usage. We store counts only — never the content of your messages.
  • Operator-assigned API keys (invited users only). If we provide you with an API key, it is stored encrypted at rest and delivered to your signed-in browser, which uses it to call the AI provider directly. Keys you bring yourself are not stored on our servers (see below).

In your browser

  • Your conversations. All chats, messages, attachments and app settings are stored locally in your browser (IndexedDB). They are not uploaded to or stored on our servers.
  • Your own API keys (BYOK). Keys you add are kept in your browser and are sent directly from your browser to the AI provider they belong to. They are never sent to or stored on our servers.
  • Optional Drive backup. If you enable sync, your conversation transcripts are uploaded from your browser to your own Google Drive. They are not routed through or copied to our servers.

3. How your prompts are processed

Polymeti is an interface to third-party AI providers. When you send a message, your browser sends your prompt and any attachments directly to the AI provider you select so it can generate a response — the request does not pass through our servers (see How your data flows). Depending on your choice the provider may be OpenAI, Anthropic, Google, xAI, DeepSeek, or OpenRouter. Each provider processes your data under its own privacy policy and terms — we encourage you to review them:

Because the exchange happens between your browser and the provider, we never receive your prompts or the responses — and so cannot use them to train any model, or for anything else.

4. Cookies

We use only strictly-necessary cookies: a secure, HttpOnly session cookie that keeps you signed in, an anti-forgery (CSRF) cookie, and a short-lived cookie that completes the Google sign-in handshake. We do not use advertising or third-party analytics cookies, so no cookie-consent banner is required.

5. Legal bases (GDPR)

  • Performance of a contract — to provide the service you sign in to use.
  • Legitimate interests — to keep the service secure and prevent abuse.
  • Consent — where we ask for it specifically; you may withdraw it at any time.

6. Who we share data with

We do not sell your personal data. Your prompts reach the AI provider you choose directly from your browser (section 3) — that flow does not pass through our systems. Beyond that, we share data only with our hosting and infrastructure providers (Microsoft Azure for hosting, Cloudflare for edge delivery and security), and with authorities where required by law.

7. International transfers

Some providers and infrastructure may process data outside the European Economic Area (for example, in the United States). Where that happens, the transfer relies on the safeguards offered by those providers, such as Standard Contractual Clauses.

8. How long we keep data

  • Account identity — for as long as your account exists.
  • Usage counts — until you erase them or close your account.
  • Browser data — under your control; it remains until you delete it or clear your browser storage.

9. Your rights

Under the GDPR and similar laws you have the right to access, correct, delete, export, and object to the processing of your personal data. You can act on the most common ones directly in the app:

  • Delete your usage history — Settings → Account → Privacy.
  • Delete your account — Settings → Account → Danger Zone. This removes your server-side identity and usage data.
  • Delete your conversations — clear them in the app or clear your browser storage; they are local to your device.

For any other request, or to lodge a complaint, contact us at [email protected]. You also have the right to complain to your local data-protection authority.

10. Security

We protect your session with a secure, HttpOnly cookie, serve the site over HTTPS with HSTS, apply a Content-Security-Policy, and encrypt operator-assigned API keys at rest. No system is perfectly secure, but we take reasonable measures to protect your data.

11. Children

Polymeti is not intended for children under 16, and we do not knowingly collect their personal data.

12. Changes to this policy

We may update this policy from time to time. We will revise the “last updated” date above and, for material changes, provide a more prominent notice.

13. Contact

Questions about this policy or your data? Email [email protected].