Privacy Policy.
This policy explains what Anvil collects, why, and who it's shared with. We collect as little as we need to run the service.
What we collect
- Your GitHub profile when you sign in: your GitHub user id, username, display name and avatar. We don't get your email address or access to your repositories.
- What you create: scripts and all their versions, titles, descriptions, tags, stars, reports you send, and upload key labels. Upload keys themselves are stored only as a one-way hash.
- AI usage: for each AI request we record when it happened, which models ran, whether the answer passed our checks, how long it took and what it cost. We don't store your prompts or the AI's answers; they stay in your browser unless you save them into a script.
- Billing: your Stripe customer id, plan, subscription status, renewal date, credits and which purchases were applied. Card details go straight to Stripe and never reach us.
- Technical data: our hosting providers keep standard request logs (such as IP address and user agent) for security and debugging.
- In-game downloads: we count installs of each script, not who installed them.
Cookies and local storage
We use one sign-in cookie to keep you signed in. Your browser also keeps unsaved editor drafts in local storage on your own device. We don't use advertising or tracking cookies.
Who we share data with
- Vercel hosts the website; Neon hosts the database.
- DigitalOcean runs our AI service and provides the language models. The prompt, files and error text of an AI request are sent there to produce the answer, and to the model's provider as part of DigitalOcean's service.
- Stripe processes payments and keeps your billing details.
- GitHub handles sign-in.
We don't sell your data. We may disclose information if the law requires it.
Public information
Your username, avatar, public and unlisted scripts, and star counts are visible to others as described in the Terms. Private scripts are visible only to you.
How long we keep data
We keep your account and scripts until you delete them or ask us to close your account. Deleted scripts are removed from the database immediately; backups expire on our providers' schedules. We keep billing records as long as tax and accounting rules require.
Your choices and rights
- You can edit or delete your scripts and upload keys at any time.
- You can ask for a copy of your data, a correction, or for your account to be deleted by contacting us. Depending on where you live you may have further rights under laws such as the GDPR or CCPA.
Children
Anvil isn't directed at children under 13, and we don't knowingly collect their data.
Changes
If we change this policy we'll update the date above, and give notice on the site for significant changes.
Contact
Privacy questions and requests: support@thultz.dev.