Legal
Privacy Policy
Last updated: August 27, 2026
Scope
This policy describes what Cross point collects when you use the web app: account auth, prompt routing, answers, feedback, usage metrics, and optional bring-your-own-key (BYOK) credentials. It is written to match the product as built—not a generic SaaS template.
What we collect
- Account data. Email and password authentication via Supabase Auth. We see your email as the account identifier; passwords are handled by the auth provider (we do not store plaintext passwords). Password-reset emails are sent by that provider to the address on the account.
- Routing and prompt data. For each routed request we may store the prompt text, classification/category, chosen model, confidence and reason text, answer text, compare answers when used, feedback (good/bad/skip), errors, token counts, and estimated platform cost. Rows can be tied to your user id when you are signed in. For signed-in accounts we keep the 50 most recent routing conversations (threads and their turns) and automatically delete older ones. The data model also allows unsigned rows; the live product currently requires sign-in for the workspace and routing APIs.
- BYOK keys. If you save an OpenAI, Anthropic, Google, or OpenRouter API key, we store it encrypted at rest with AES-256-GCM under a server master key. We also store non-secret metadata such as provider, status, fingerprint (last four characters plus length), and last error reason—not the full key in plaintext.
- Abuse limits. We store IP and signed-in user id with timestamps so per-IP and per-account request caps stay accurate across servers. Those rows are not prompts or answers.
- Operational logs. Hosting and infrastructure providers may process standard request logs (IP, user agent, timestamps) as part of running the app.
How we use data
- Authenticate you and keep you signed in
- Classify prompts, select models, generate answers, and show “why this model”
- Improve routing quality using stored interactions and feedback
- Show platform (OpenRouter) usage and estimated spend in the product
- Call a BYOK provider with your decrypted key only to fulfill your request—not to train our own models on your key
- Operate security, abuse prevention, and debugging
BYOK keys specifically
Keys are encrypted at rest (AES-256-GCM). They are decrypted in server memory when needed to call the matching provider on your behalf, then not written back as plaintext. We do not sell your keys. Provider error text is redacted before we persist diagnostics so full keys and provider-masked key fragments are not stored in error fields.
BYOK traffic is billed by that provider to whatever account owns the key. Cross point tracks that a BYOK call happened for product diagnostics; we do not receive that provider’s dollar invoice as our platform spend figure.
Platform model calls
When a request uses our platform path, prompt content is sent to OpenRouter and the underlying model provider to produce a classification and/or answer. Those parties process the content under their terms. We may store estimated OpenRouter token usage and cost for your account.
Sharing
We share data with:
- Infrastructure and auth vendors that host the app and database (e.g. Vercel, Supabase)
- OpenRouter and model providers for platform-routed calls
- OpenAI, Anthropic, or Google when you use BYOK for that provider
We do not sell your personal information. We may disclose data if required by law or to protect the service and its users.
Retention and deletion
Account and routing data are kept while your account is active and as needed to operate and improve the product. Signed-in prompt history is capped at the 50 most recent conversations; older threads and their turns for that account are deleted automatically. There is no fully self-serve account-delete button yet. To request deletion of your account and data we control, email anihatdurmus@gmail.com from your account email. We will delete or anonymize account-linked data we control within a reasonable time, except where we must retain records for security, dispute, or legal reasons. BYOK key rows are removed when you delete a key in Settings or when the account is deleted.
Security
We use transport encryption (HTTPS), authenticated sessions, encrypted BYOK storage, and access controls on application data. No method of transmission or storage is perfectly secure.
Children
Cross point is not directed at children under 13, and we do not knowingly collect their personal information.
Changes
If this policy changes in a material way, we will update the date above and post the new version at this URL.
Contact
Privacy questions: anihatdurmus@gmail.com. Related terms: Terms of Service.