Privacy policy

Built by Tradi3. Operated by Vaytric, which is responsible for the data described here. This page covers the hosted site at bountyoperator.com. The open-source command-line kit runs on your own machine.

Last updated

  • No ad cookies. No tracking pixels.

    No third-party analytics scripts either.

  • Your files are not stored

    Files, instructions, API keys and review results are never written to our database or logs.

  • Two cookies

    Both exist to sign you in. Nothing else is set.

  • Export or delete

    Download your account data or delete the account from the account panel.

Your files and your API key

File selection, the privacy check and prompt export run in your browser.

A hosted review sends the files you selected, your instructions, the model name and your API key through our Cloudflare Worker to the provider you select. The Worker adds the review method of the profile and holds everything in memory for that one request. Your files, your instructions and your key are never written to our database or our logs, and neither is the review that comes back.

The Worker reads the answer to a hosted profile as it passes through, to stop an answer that repeats the method in place of a review. It keeps nothing of what it reads.

The provider you select receives your files under its own terms and keeps them under its own retention policy.

Exporting the prompt of a core profile contacts no provider and sends nothing of yours to our server. You paste it into a model yourself.

Account records

An account is a random identifier. Sign-up asks for no password and no email address.

We store:

  • your passkey public keys, with their identifiers, counters, transport hints, labels and creation times
  • a hash of your recovery code
  • hashes of your session tokens, each with a CSRF token, its expiry and the time you last signed in
  • hashes of your connection tokens, with the label you gave each one and its creation, expiry and last-use times
  • the billing references listed under Payments

Passkey private keys and device biometrics stay on your device.

Cookies and browser storage

Two necessary cookies: a session cookie (up to 30 days) and a five-minute sign-in cookie.

  • __Host-bounty-session keeps you signed in. It lasts up to 30 days.
  • __Host-bounty-challenge ties a passkey prompt to the request that started it. It lasts five minutes.

Both are HttpOnly, Secure and SameSite=Lax.

Your browser also keeps two things on your device:

  • your colour theme
  • review history, when you turn it on

History is optional and is saved only in this browser. It never includes API keys or GitHub tokens, it is never sent to our server, and one button clears it.

When a free tool, a template page or the guide hands a draft to the workbench, the draft passes through the tab’s session storage and is gone when the tab closes.

Usage records and abuse limits

For each hosted review we store the account identifier, the status (running, completed or failed), the review profile, the channel (web or MCP) and the timestamps. These rows enforce the daily allowance and the concurrency limit. They are deleted after seven days.

Abuse limits use a keyed hash of your IP address that expires within a day. Expired sessions, sign-in challenges and rate-limit rows are deleted daily.

Our logs record the request path and an error name, and for a failed billing call Stripe’s error type and code. They never record request bodies, file contents, API keys or Stripe payloads.

Page and funnel counters

Page views and named actions are counted in aggregate. We do the counting ourselves and keep one number per day for each of these:

  • page views per path
  • the referring site, from a fixed list
  • sign-ups and sign-ins
  • completed reviews per profile, and failed reviews
  • daily-limit hits, checkouts started and subscriptions activated
  • named actions a page reports from a fixed list: an example loaded, a prompt exported, a packet saved, a free tool run, a template copied, an MCP command copied

A page reports an action by its name and sends nothing with it. On a free tool, a template page and the MCP page that counter is the only request your action causes: what you paste or drop there never leaves the browser.

A counter holds a date, a name and a total. It holds no account identifier, no IP address and no cookie value. Counters older than 400 days are deleted.

Cloudflare, GitHub, OpenRouter and MCP

Cloudflare hosts the site and processes request metadata, including IP addresses, under its own policies.

A GitHub import goes from your browser straight to api.github.com, with the link you chose and your read-only token if you supply one. The token is held in tab memory. The imported files reach our server only when you run a hosted review.

Connecting OpenRouter happens between your browser and openrouter.ai.

The MCP server handles the file contents your agent passes to a tool. list_profiles, prepare_review and build_packet keep none of it. run_review is a hosted review and is recorded like one. Your agent’s own model provider receives tool results under its own terms.

Connection tokens are shown once and stored as hashes. They expire after 90 days and you can revoke one in the account panel. Recovering an account, or signing out everywhere, revokes all of them.

Payments

Stripe collects your email, card and billing details at checkout. Card details never reach our application. We send Stripe your account identifier.

Our database keeps the Stripe customer and subscription IDs, the subscription status, the paid-until time, your receipt email, and webhook event IDs for 30 days. Stripe keeps its own financial records.

Export and deletion

Download your account data or delete your account from the account panel. Cancel an active subscription first.

Deleting removes the account, its passkeys, sessions, connection tokens, usage rows and billing references from our database. It cannot be undone.

Questions: support@bountyoperator.com.

Changes

We update this page when what we process changes. The date at the top is the current version. The security page shows how the stored data is protected.