Privacy Policy
Last updated 2026-10-06
What this covers
Sluiceline hosts a credential for you and sits in front of the AI provider you already use. That shapes everything below: what we hold is mostly about your account and your keys, and the traffic that passes through the gateway is not held at all. This page says exactly which is which.
What we store
Your account: name, email address and profile picture, plus the access, refresh and ID tokens your sign-in provider issues. A session records the IP address and user agent of the browser that signed in.
Your keys: the name, provider, mode and quotas you set. A safe-key is stored encrypted so you can copy it again, and by its SHA-256 hash — that hash, never the key itself, is what the gateway looks up. A real provider key is stored with AES-256-GCM encryption, is never returned by any endpoint, and is decrypted in memory only to forward a request. If you set an alert email, or configure a mock fixture, those are stored too.
Billing: your plan, the Stripe customer, checkout and subscription identifiers, and — if you redeem one — the coupon code and the amount it took off. Card details go to Stripe and never reach us.
What we do not store
Your prompts, your completions, and the images or videos your provider returns. Requests stream through the gateway to your provider and back; their bodies are not copied, logged or persisted on our side. The same is true of the mock responses you generate.
There are no analytics, no advertising scripts and no tracking pixels on this site. One third-party embed is deliberately ours: the feedback widget, loaded from Feedlog, which keeps a session key in your browser's local storage and — while you are signed in — sends your name, email and picture along with whatever you write, so a reply can reach you. It is the only third-party embed we add to the page.
Three cookies are set: one remembers your language, one is your sign-in session, and one remembers whether the console sidebar is collapsed. Your theme choice lives in local storage, not in a cookie.
Usage data and blocked requests
To hold a key to its quotas the gateway counts its requests each day. Distinct visitors are counted by a SHA-256 hash of the caller's user agent and IP address. Treat that count as a pseudonym rather than as anonymisation: the hash is unsalted, and it is never joined back to an account.
When a key breaches a threshold, the gateway writes an entry to that key's alarm log: which key, which threshold, the status returned, and the IP address and user agent of the blocked request. That is the log the Alarm Events page shows you, and it is an audit trail — it outlives a key you later revoke.
Who else processes it
Cloudflare runs the service: the compute, the database and the object storage behind it, and its email service delivers threshold alerts to the address you configure.
Google is your sign-in provider and sees the name, email address and picture you authorise it to share. Stripe processes payments and holds your card details. Feedlog serves the feedback widget: it receives the name, email and picture of a signed-in user, along with whatever they submit to it, and keeps the widget's session in their browser. And the AI provider behind the gateway receives every request it forwards — that is what the gateway is for, and that provider's own policy applies to those requests.
How long it stays
Daily counters start again at 00:00 UTC, and the previous day's rows are kept as history rather than deleted, so those counts accumulate. Alarm events and key records stay until you ask us to remove them. Revoking a key stops it working at once and keeps its record, so the history of what it was used for survives the revocation.
Your requests
Write to privacy@sluiceline.com to get a copy of what we hold about you, to have it corrected, or to have your account and its keys deleted. We answer from that address and may ask you to confirm you control the account before we act.
Changes to this policy
If this policy changes in a way that matters, the date at the top changes with it.