What is processed, and why
There is no username and password. Using the calculator stores nothing about you. Taking an API key creates a customer record; paying creates billing records at Stripe and here. Everything processed is listed below with its purpose, who else receives it and how long it is kept.
Who is responsible, and how to reach them
The controller for everything described here is Ander Pascal, Logroño, Spain. Data-protection requests go to corrections@llmbottleneck.com. The full legal identification — tax identifier and registered address — is published with the commercial terms at /terms, which is where a contract is entered into. No data protection officer is appointed; requests are handled by the controller.
Purpose, legal basis and how long
Every processing operation on this site, what it is for, the ground it rests on and when it ends. Where a period is a number, it is the number the code uses, not an aspiration.
| Purpose | Data | Legal basis | Kept until |
|---|---|---|---|
| Answering a calculation | The configuration in the request. Nothing is stored. | Legitimate interest in answering the request you made (GDPR art. 6.1.f). | Not kept: the answer is computed and returned. |
| Keeping the service available | A count per network address, in memory. | Legitimate interest in refusing a client that floods the service (art. 6.1.f). | The server instance restarts. Never written to disk. |
| Issuing and operating an API key | Customer id, email address, key digests, labels, dates. | Performance of the contract you enter into by taking a key, free or paid (art. 6.1.b). | You ask for the customer record to be deleted. |
| Enforcing the daily allowance | Calls per day, per customer and per key. | Performance of that same contract (art. 6.1.b). | 60 days, then deleted by a scheduled job. |
| Warning key holders before a breaking change | The email address on the customer record. | Performance of the contract (art. 6.1.b). The address given for a key is never added to the weekly email or to any marketing list. | With the customer record. |
| Detecting errors and answering support | One log line per request: route, status, duration, request id, outcome. No key, no configuration, no network address. | Legitimate interest in operating the service and diagnosing it (art. 6.1.f). | The hosting provider’s log retention. This site sets no separate period and does not copy these lines anywhere. |
| Taking payment and keeping accounts | Stripe customer and subscription ids, status, price, renewal date, checkout sessions, processed event ids, reconciliation records. | Performance of the contract (art. 6.1.b), and compliance with accounting and tax obligations (art. 6.1.c). | Finished checkout sessions: 30 days after they expire. Expired recovery tokens: 30 days. Billing records: the retention the controller’s accounting and tax obligations set, published in the commercial terms. |
| Counting page views without a cookie | Page path, referring site, country, browser and device type. No cookie, no browser storage, a daily-discarded hash. | Legitimate interest in knowing which pages are read, weighed against an analysis that stores nothing on your device and does not identify you (art. 6.1.f). | The provider’s retention; not joined to anything here. |
| Google Analytics | Page path and title, browser and device, referring site, its own cookies. | Your consent (art. 6.1.a), and consent for the cookies it sets. Withdrawable at any time from “Cookie preferences” at the foot of every page; withdrawing does not affect what was lawful before. | Google’s retention, under its own policy. |
Using the calculator and the widget
A diagnosis is computed from the configuration you send and a static catalogue; neither the request nor the answer is stored. Saved configurations stay in your browser’s localStorage and never reach a server. The embeddable widget sets no cookie and uses no storage; it sends one message out of its frame, its own pixel height.
Like every request to the site, a diagnosis passes through the hosting provider, and the calculator’s endpoint keeps a short-lived count per network address in memory to refuse a client that floods it. That count is never written to disk and disappears when the server instance restarts.
API keys and the customer record
| What | Why | Kept |
|---|---|---|
| Customer record | Every key belongs to a customer: an opaque id, the email address given when the first key was taken — or, for a plan bought without a key, the address entered at Stripe’s checkout — and the plan. The plan and any subscription belong to the customer, so every key of the customer shares them. The address is not verified and never merges two customers. | Until the customer is deleted on request. |
| Email address | To warn key holders before a breaking change to the API, and, if you buy a plan, to identify you to Stripe, which uses it for receipts and invoices. It is not sold, and it is never added to the weekly email. | With the customer record; at Stripe, under Stripe’s policy. |
| Keys | The key itself is not stored. Only its SHA-256 digest, its label, its creation date, the last day it was used (to the day) and, once revoked, the revocation date. A lost key is replaced, never recovered. | Revoked keys are kept so their usage history stays attributable; deleted with the customer. |
| Usage counts | Calls per day, counted against the customer’s shared daily allowance, with a per-key breakdown so you can see which key spent what. Refunds of calls that failed on the server are recorded until applied. | 60 days, then deleted by a scheduled job. |
| Network address when taking a key | Held in memory to throttle key issuance. | Never written to disk; gone when the instance restarts. |
API request logs
Every API request writes one structured log line: the route, the response status, the duration, a request id and, for analyses, whether the engine answered or refused. It does not contain the key, the configuration you asked about, the answer, or your network address. These lines exist to detect errors and outages and to answer a support request that quotes a request id. They are kept by the hosting provider’s log retention, not joined to anything, and not used to profile anybody. The hosting provider also keeps ordinary web server logs, which include network addresses, for operational reasons.
Paying for a plan
Payments are handled by Stripe. Card details go to Stripe and never reach this site. To create the Stripe customer, this site sends Stripe the customer’s email address, when it has one, and its opaque customer id. A plan bought without a key opens a customer record with no address; the address, name and any VAT number are entered at Stripe’s checkout, and the address is copied back to the customer record when the payment is confirmed. A record whose checkout is never paid holds nothing else and is deleted after a week. What is stored here: the Stripe customer and subscription ids, the subscription’s status, price, item, renewal date and any pending plan change; the checkout sessions started (to prevent a second purchase); the ids of Stripe events already processed; and records a person must review when a payment cannot be matched to a customer. Stripe’s privacy policy covers what it keeps.
Finished checkout sessions are deleted 30 days after they expire. Subscription, event and reconciliation records are kept for as long as the operator’s accounting and tax obligations require; that period is set by the operator in the commercial terms, not by this code.
Page views and analytics
Pages are counted with Vercel Web Analytics, which sets no cookie, stores nothing in your browser and groups visits by a hash discarded daily. It records the page path, the referring site, the country and the browser and device type. The query string is removed before anything is sent, because a calculator link carries your whole configuration.
The same counter records three actions, as events with no cookie and no identifier: a click on a store link, a click on a cloud provider link, and the opening of a checkout. A click carries the store or provider and the kind of page it was on; a checkout carries the plan and the billing period. None carries the device, the model, your configuration or anything about you. Browsers that announce they are automated are left out of all of it.
Page speed is measured with Vercel Speed Insights, under the same terms: no cookie, nothing stored in your browser, the query string removed. It records how long the page took to load and respond (the Core Web Vitals), with the page path, the country and the device type.
Google Analytics 4 loads only after you allow it, with one exception: in the United States and its territories it is on by default, because the law there does not require prior consent for analytics storage, and the notice shown on the first visit turns it off in one click. Anywhere else it waits for Allow analytics. A Global Privacy Control or Do Not Track signal is treated as a refusal everywhere.
When it runs, Google Analytics may set analytics cookies and receives the page path, the page title, browser and device information and the referring site, with the query string removed. Choosing No, thanks — or withdrawing later from “Cookie preferences” at the foot of every page — stops it immediately and removes its cookies on this site; allowing it again resumes it. The choice itself is kept in localStorage in your browser. The embedded widget is never counted by either service.
Links to cloud providers
The buttons that open Vast.ai, RunPod, Novita AI or OpenRouter go through a redirect on this site (/go/…) that adds a referral code where one applies and counts the click. The count is one number per provider and one per kind of page, per day — nothing about who clicked, no cookie, no identifier and no IP address is kept. The redirect sends no referring page to the provider; the link itself tells the provider it came from this site, which is how the referral is credited.
Once you are on the provider’s site, its own privacy policy applies, and it may set its own cookies to remember the referral. Nothing you do there is reported back to this site except, for a referral, the provider’s own statement of the commission it owes, which carries no information about you that this site can see. The prices on the cloud pages are read by this site’s server from each provider’s public API; loading them sends nothing about you to the provider.
The weekly email
No weekly email is sent at present and no form on this site collects an address for one. What follows describes how it works where it is offered.
It is separate from everything above: the address you give for an API key is never added to it. If you subscribe on /new, your address goes straight to Buttondown, the service that sends the email; this site keeps no copy. Buttondown asks you to confirm before sending anything, every email has an unsubscribe link, and its own privacy policy covers what it holds. The only thing counted here is that a subscription happened, as one number per day.
Benchmarks you choose to send
The command-line tool can run llama.cpp’s benchmark on your machine, and sends the result here only when you add --submit. What is stored is the GPU name, the model file’s name and size, the runtime and its version, the benchmark’s own figures, and a keyed digest of the network address or API key it came from. The digest is keyed with a secret held only by this deployment, so it cannot be turned back into an address; it exists to limit submissions per day and to discard a bad batch together. The legal basis is the legitimate interest in checking the published speed estimates against real runs (art. 6.1.f). A submission is held for review and is published, if at all, only as a figure in a scorecard, never with its digest. No deletion schedule is set for these rows, which hold no address, no key and no name.
Links to stores
The links that search Amazon or eBay for a device go through a redirect on this site (/shop/…) that adds an affiliate code where one is configured and counts the click, in the same way as the cloud links: one number per store and one per kind of page, per day, with nothing about who clicked. The country your connection comes from, as our hosting provider reports it, chooses which of the store’s national sites to open; it is read for that redirect only and not stored or passed on. The store’s own privacy policy and cookies apply once you are there.
Who else receives it, and where
Each of these acts on this site’s instructions except Stripe and Google, which also decide things for themselves and publish their own policies. Typefaces, scripts and figures are served from this origin. There is no advertising network, session recorder or error-reporting service.
| Recipient | What for | Outside the EEA |
|---|---|---|
| Vercel | Serves the site, holds its server logs, counts page views. | Yes, United States. Its privacy policy and data processing addendum state the transfer mechanism it relies on. |
| The database provider | Stores the customer records, key digests, usage counts and billing records. | Depends on the region the database is provisioned in, which the controller chooses. The connection is TLS-verified. |
| Stripe | Takes the payment and issues receipts. Card details go to Stripe and never reach this site; this site sends Stripe an email address and an opaque customer id. | Yes, United States. Stripe’s privacy policy and its data processing agreement state the transfer mechanism. |
| Google Analytics 4, and only after you allow it. | Yes, United States. Google’s business privacy page states the transfer mechanism. |
A transfer to a country outside the European Economic Area needs a safeguard — an adequacy decision, or standard contractual clauses. Each provider above publishes which it relies on at the link beside it, and those pages are the statement: this one does not restate a legal position on their behalf, because a restatement is the thing that goes stale.
Your rights, and how to use them
You can ask for access to the data held about you, its rectification if it is wrong, its erasure, the restriction of its processing, and its portability in a machine-readable form. You can object to any processing that rests on legitimate interest — the availability throttling, the request logs and the cookieless page counts — and you can withdraw consent to Google Analytics at any time from “Cookie preferences” at the foot of every page, which takes effect immediately. No decision here is automated and nobody is profiled.
Requests go to corrections@llmbottleneck.com, and are answered within one month. Because an email address is never verified here, an email alone does not show that a customer record is yours: see the next section for what does.
If you think a request was handled badly, you can complain to the Agencia Española de Protección de Datos (AEPD), the supervisory authority for Spain, or to the authority where you live or work. You do not have to ask here first.
Deleting your data
To have a customer record, its keys and its usage deleted, write to corrections@llmbottleneck.com and include a request id from a call made with one of the customer’s keys, or rotate a key from /usage and quote its public id. Because addresses are not verified, an email alone does not prove you own a customer record, so it is not enough on its own. The keys stop working when the record is removed. Billing records that must be kept for accounting are kept, without the keys.
If this page and the site’s behaviour ever disagree, the page is the defect. Report it to corrections@llmbottleneck.com.