# ComputeFirst Privacy Policy

Version 2026-09-29 · Effective 29 September 2026

**In short:** you can use ComputeFirst without an account, and we don't store the content of anonymous tool inputs and outputs. We record technical details of calls, and search text, to run the service and decide which tools to build. Anything more personal, such as your model name, an email sign-in or a newsletter address, is up to you. We don't sell personal data, and analytics run only if you allow them.

## 1. Who is responsible

ComputeFirst is run by **Idan Roth**, a private individual in Israel, who is responsible for your personal data (the "controller"). Contact: [idan.roth.ai@gmail.com](mailto:idan.roth.ai@gmail.com). For a postal address for legal notices, email us. "We" and "us" mean Idan Roth.

## 2. What we collect

You are never legally required to give us personal data. Usage records are created automatically when you call the service; everything else is voluntary, and without it you only miss the related feature.

### Every call to the MCP server, API or CLI

- **Usage record:** time, channel, operation (such as search or run), tool and version (or the list of tools in a batch), batch size, outcome or error code, response time, input and output sizes, calling software and version, country (from your IP address, via Cloudflare), referring host, the model name your agent reports on a call (if it does), whether the call's answer carried our one-line invitation, and a pseudonymous identifier: a keyed hash of your IP address (for IPv6, of its /64 network) that changes every month (so we can count repeat use within a month, but not across months) or, with a profile or key, a hashed account or key identifier. Successful tool runs and the things you choose to send (below) are always recorded; other calls, including failed or refused ones, stop being recorded for the day after a daily limit, and searches get a search record instead. Without a key, or with an email sign-in key, the record's identifier is also the call's reference for feedback and savings reports.
- **Request log:** only for calls made with a valid passkey profile agent key (for the MCP server, its tool calls, not protocol messages such as listing the tools), while validly signed in on the website, and for each successful passkey sign-in. A request with a missing, invalid or expired key or session gets no request log. It holds the address requested (without search text), operation, User-Agent, status, error code, a keyed hash of your IP address that does not change, your agent-key ID and profile ID (never the key itself), any model and task labels your agent sends, and whether content was recorded. Each tool run with such a key also gets an execution record (tool, version, outcome, timing and sizes, with your agent-key ID) so that feedback and savings reports can refer to it. Calls without a key and calls with an email sign-in key have no request log and no execution record.
- **Search record:** the search text (cut to 256 bytes), a language guess, the search method, the tools returned, the top match score, whether nothing matched, and the same pseudonymous identifier as the usage record, up to a daily limit (searching keeps working after it). Before saving, we automatically remove recognisable secrets, such as API keys and access tokens, and anything that looks like an email address. This filter is not perfect, so keep personal details out of searches. While optional search reranking is switched on, the same filtered text of some searches is also sent to TypeSafe (section 4).
- **Limit counters:** daily counts per agent key, account or monthly IP hash (of calls, and of tool requests, newsletter sign-ups, feedback and reports), counts of sign-ins per monthly IP hash, counts of sign-in, sign-up and key-registration attempts per keyed IP hash, service-wide daily totals, and, while search reranking is on, a record of each paid search rerank (the monthly IP hash or hashed account, whether you were signed in, and the estimated tokens and cost), used to enforce usage and spending limits.

**Not stored for anonymous use:** the content of tool inputs and outputs. It is processed in memory to produce your result and then discarded. We never store your IP address itself in our database.

### Website and hosting logs

Cloudflare, our host, processes each page request, including your IP address and browser details, and we may record the page, time, country, browser type and referring site. Cloudflare also logs each request for troubleshooting: time, address (which can include search text), status, our error messages and network details, which can include your IP address. Google Analytics runs only if you allow it (section 7).

### Optional passkey profile

- Username, display name, optional contact email (not verified), your passkey's public key, and the policy version you accepted and when. Your fingerprint, face or PIN stays on your device.
- Agent key names and dates, saved tools and notes, activity linked to your profile, and savings totals.
- Only hashes of your sessions, agent keys and recovery codes, and a keyed hash of the IP address used to create each agent key.
- **Content recording:** by creating a passkey profile you agree that we keep the request and result content of calls made with its agent keys, or on the website while you are signed in, after automatic removal of recognisable secrets, up to 256 KiB per side and within a daily storage budget. Sign-in, key management, admin, newsletter and tool-request calls are never recorded. There is no separate off switch yet: calls made without your keys and while signed out are not recorded.

### Optional email sign-in

- **Email sign-in:** your email address (not verified), when you signed in and the version of these terms you accepted, a generated account name, the agent key's label, dates and hash (never the key itself), and a keyed hash of the IP address used to sign in.
- Each sign-in creates a separate account with its own key. We never merge accounts that use the same email, and one account never sees another's data or keys.
- The key adds saved tools and notes, your call history, personal savings totals and its own daily limit, for the key's 90 days; a new sign-in starts a new, empty account. The history and totals come from the usage records and model reports of calls made with the key.
- Calls made with an email sign-in key are never content-recorded and have no request log.
- We use the email only to answer you about the account if you write to us; we send nothing to it while it is unverified. The newsletter is separate and only if you asked for it.

### Things you choose to send

- **Tool requests:** your description (up to 4 KB) and optional example input and output, after automatic removal of recognisable secrets and of anything that looks like an email address; where you sent it (MCP or API); the same pseudonymous identifier as the usage record; with a key from an account, the account ID, so the account can follow the request; and, only with your consent, an email address and the consent wording version, so we can tell you when the tool is ready.
- **Newsletter:** your email, your consent and its wording version, where you signed up (website, MCP or API), an unsubscribe token and the relevant dates. When you unsubscribe, we keep only a keyed hash of the address, so that nobody can sign it up again.
- **Feedback:** a category, an optional note (up to 1,000 characters), the tool and version, the reference of the call it concerns if given, the retry key your agent sends, and your agent-key ID or, without a key, the monthly hash of your IP address.
- **Savings reports:** token counts with and without ComputeFirst, the model name, task and baseline labels, and the call reference with the same agent-key ID or monthly hash as the call; never prompts. Don't put personal data in labels. Every report starts as reported, not verified; reports sent with a profile key also count towards your profile's totals.
- **Model reports:** the model name and provider your agent reports, optionally its own estimate of the tokens a call saved, the call reference if given, the estimated dollar value we compute from that model's dated public list price, where you sent it, and the same pseudonymous identifier as the usage record or, with a key from an account, the account ID so the account sees its totals. These are your agent's estimates, labelled as client-reported and never verified.
- **Emails to us:** your address and whatever you write.

### Emails we send

We email you only if you asked, and an address nobody has confirmed gets at most one email from us. We don't send newsletters yet. Before the first one, each address gets one confirmation email and nothing more unless it is confirmed; until then it stays unconfirmed, and an unconfirmed address is deleted 90 days after sign-up, or 30 days after its confirmation email if that is sooner, so an address someone else or an AI agent entered is not used. Each newsletter starts its subject line with "פרסומת" ("Advertisement"), as Israeli law requires, names Idan Roth as the sender with contact details and a postal address, and has an unsubscribe link that needs no sign-in. A "your tool is ready" email is sent by hand, once, only about that tool, and only to an address given with the request with consent. Unverified email sign-in addresses get no emails.

## 3. Why we use it

We use personal data only for these purposes (Israeli Privacy Protection Law, section 8(b)); this policy is the notice its section 11 requires. EU and UK GDPR legal bases are in brackets.

- **Run tools and searches:** inputs (in memory only) and search text [legitimate interests; contract for profile holders].
- **Security, limits, abuse prevention and fixing errors:** usage records, request log, hashed IPs, hosting logs [legitimate interests].
- **Deciding what to build and improving search:** usage and search records, tool requests, feedback, savings and model reports [legitimate interests].
- **Profile and email sign-in features:** profile and account data [contract].
- **Debug and improve quality:** profile holders' recorded content [consent, given when creating the profile].
- **Newsletter and "your tool is ready" emails:** email address [consent].
- **Website analytics:** Google Analytics data [consent].
- **Answering you, legal duties and claims:** emails with us, any relevant data [legitimate interests; legal obligation].

We may publish aggregate statistics that don't identify anyone, such as calls per day.

We don't sell personal data or build advertising profiles, and we don't use, or let our AI development assistants use, your tool inputs, outputs, recorded content, searches or tool requests to train AI models. The search reranking service in section 4, while switched on, receives filtered search text under its own terms, and we have not confirmed that those terms rule out training, so keep personal details out of searches. We make no automated decisions with legal or similarly significant effects on you.

## 4. Who we share it with

- **Cloudflare, Inc.** hosts the service, its network, database and logs.
- **Google** provides Google Analytics (only with your consent) and Gmail, which handles emails you send us.
- **AI development assistants** (currently Anthropic's Claude and Google's Gemini, in the United States) help us build tools. We may give them tool-request text and examples and search text, filtered as in section 2, but never email addresses, hashed identifiers, profile data or recorded content, and we leave out anything we notice contains personal details.
- **TypeSafe** (the Jev search reranking service), only while we switch it on: for searches made with a key and for other searches whose plain match is uncertain, the search text, filtered as in section 2, and the public descriptions of the candidate tools are sent to TypeSafe's API to rank them. It gets no IP address, identifier or account data from us, and answers are cached so a repeated search is not resent.
- **An email delivery service**, if we use one for newsletters. We will name it here before first use.
- **Authorities or others**, where the law requires it or to protect people, rights or the service.
- **A successor** (a company Idan Roth sets up, or a new owner), announced in advance and bound by this policy.

Only Idan Roth, and helpers he engages under written confidentiality and data-security terms, can access stored personal data, each only as far as their task needs.

## 5. How long we keep it

- **Usage and search records:** 180 days.
- **Model reports:** 180 days.
- **Request log, execution records, limit counters and search rerank records, feedback, individual savings reports and recorded content:** 30 days.
- **Daily aggregate counts and service-wide savings totals, with no identifiers:** indefinitely.
- **Profile, passkeys, agent key records, saved tools, profile savings totals and the task labels counted in them:** until your profile is deleted.
- **Email sign-in accounts, their agent key records and saved tools:** until you ask us to delete them.
- **Agent keys issued without a profile before 19 September 2026** (the purpose given when the key was issued, its dates and a keyed hash of the IP address that requested it): until 30 days after the key expires or is revoked.
- **Tool requests, including any email:** until you ask us to delete them.
- **Newsletter subscription:** until you unsubscribe, after which the address is deleted within a day and only its keyed hash is kept, indefinitely, so it is never added again; an unconfirmed address is deleted as described in section 2.
- **Browser sessions:** 7 days. **Cloudflare hosting logs:** set by Cloudflare, currently no more than 7 days. **Google Analytics data:** no more than 14 months.
- **Emails with us:** until your request is handled, normally no more than 2 years.
- **Backup copies exported before a release or migration:** kept on Idan Roth's own access-controlled computer and deleted when no longer needed, normally within 90 days.

Apart from these backups, no copy of the database exists outside Cloudflare. Deleted data can remain in Cloudflare's recovery history for up to 30 days, and in a backup copy until that copy is deleted.

## 6. International transfers

Idan Roth is in Israel, which the European Commission and the UK recognise as adequate; that does not by itself cover onward transfers. Cloudflare (database and logs), Google (Analytics and Gmail), our AI development assistants and, while search reranking is on, TypeSafe process data in the United States and elsewhere.

For these transfers, including under Israel's Privacy Protection (Transfer of Data to Databases Abroad) Regulations, 5761-2001, we rely on each provider's written data processing or API terms (committing it to protect the data, use it only to serve us and pass it only to listed sub-processors, with the EU Standard Contractual Clauses where they apply) and on certified providers' EU-U.S. Data Privacy Framework certification, with its UK and Swiss extensions. For data from the European Economic Area we also follow Israel's 2023 regulations on such data, including deletion on request.

## 7. Cookies and similar technology

- `__Host-cf_session`: keeps you signed in to your profile; 7 days; strictly necessary, set only if you sign in.
- `__Host-cf_challenge`: completes a passkey sign-in step; 5 minutes; strictly necessary.
- `cf_analytics`: remembers your analytics choice; 180 days; strictly necessary.
- `_ga`, `_ga_*`: Google Analytics measurement; up to 180 days; only after you choose "Allow analytics".
- `__cf_bm`, `cf_clearance`: may be set briefly by Cloudflare if bot protection or a security check is active; strictly necessary, with no profile information.

With your permission, Google Analytics measures page views and clicks on the profile link; no Google script loads before you choose. It gets page addresses without query strings and referrers reduced to their domain; Google signals and ad personalisation are off. We never send your email, username, keys, prompts or tool data, but Google receives your IP address, possibly on US servers. The "Analytics preferences" button changes your choice; declining deletes the Analytics cookies our site can reach.

Our pages don't use browser local storage. Agents using the MCP server, API or CLI need no cookies; only the website's profile pages use the session cookie.

## 8. Your rights

Under Israel's Privacy Protection Law, 5741-1981 (as amended by Amendment 13, in force since August 2025), you can inspect the personal data we hold about you, yourself or through a representative you authorise in writing; ask us to correct or delete data that is wrong, incomplete, unclear or out of date; refuse direct mailing and be removed from any mailing list; and complain to the Privacy Protection Authority (הרשות להגנת הפרטיות).

If the EU or UK GDPR applies to you, you can also get a portable copy of your data, have it erased, restrict processing, object to processing based on legitimate interests (including search logging), withdraw consent at any time, and complain to your data protection authority.

**How to make a request:** email [idan.roth.ai@gmail.com](mailto:idan.roth.ai@gmail.com) with the subject "Privacy request" and help us find your data (profile username, the email you signed in or subscribed with, or request IDs from the `x-request-id` response header). **Never send us an agent key, recovery code or password.** We may confirm it's you through your profile or the subscribed address. We reply within 21 days, free of charge; a complex request may take up to 15 more days, as Israeli regulations allow, and we will tell you why within the first 21 days. Without a profile we keep only hashed identifiers, so we usually cannot find your records without request IDs.

You can unsubscribe with the link in any newsletter. To stop content recording, revoke your agent keys in your profile and sign out; calls made without them are not recorded. To withdraw consent for a tool-request email, or to delete your profile or an email sign-in account, email us.

## 9. Children

ComputeFirst is not for children under 16. If we learn we hold personal data from a child under 16, we will delete it.

## 10. Security

All traffic uses HTTPS. Profiles use passkeys, not passwords, and an email sign-in account has no password: its agent key is its only credential. Sessions, agent keys and recovery codes are stored only as hashes, and IP addresses only as keyed hashes. Backup copies are kept only on the operator's own access-controlled computer. No system is perfectly secure; if a breach affects your personal data, we will notify you and the authorities as the law requires.

## 11. Changes to this policy

We will post updates here with a new version date. For material changes we give at least 14 days' notice on the website, in the MCP server description and API documentation, and by email to profile holders and subscribers who gave an address, and we ask for consent where a change needs it.
## 12. Contact

Idan Roth, Israel · [idan.roth.ai@gmail.com](mailto:idan.roth.ai@gmail.com) · security issues: [security.txt](https://computefirst.net/.well-known/security.txt)
