Privacy Policy
Version 1.1 · September 22, 2026
We route your jobs to your own devices. The work happens on hardware you control, and the contents of that work never reach us — not by policy, but because we hold no key that opens it.
The one-sentence version
byollm.cloud sees only what routing and metering need: which devices and sites are connected, each job's kind, size, and outcome, and timestamps. Never prompts, never answers, never credentials.
What we cannot see
Prompts, answers, and your AI provider credentials. Work is encrypted end to end between the site and your device; byollm.cloud routes ciphertext and holds no key that opens either direction. Your provider credentials never leave your device.
The one thing we can see is what you type into a hosted device’s console (for example, during a CLI sign-in), because that passes through the operational logs of the machine we run for you. It is not the encrypted job channel. Treat a hosted-device console as operated by us; everything your CLIs then store, and every prompt and answer, stays encrypted and unreadable to us.
That claim is testable and tested. The protocol is open source, and the rule has a name in it (RELAY_BLIND) with a test that fails if it stops being true.
What we collect
- Account: your email and name from Google sign-in.
- Devices: names you give them, platform, public key identities, online status, and the services and model names each device offers.
- Connections: which sites you have connected, which purposes you mapped, and your consent and revocation history.
- Usage metering: per job, that it happened, who requested it, which site, what kind, approximate size, and whether it succeeded. Never its contents.
- Billing: handled by Stripe; we store your plan, entitlements, and invoice status, not your card number.
- Early access: if you add your email to the early access list, we will email you as there is space. We keep the address and the date you joined, and nothing else. The email address you give us won’t be used for anything else — no newsletter you did not ask for, and we do not pass it on. Ask us and we will delete it.
What your own device stores, which we never receive
The daemon keeps a log of every job that has run on your device, in full, at ~/.byollm/ingress.log. It is on your disk, it is yours, and we never receive it; deleting your account here does nothing to it.
This matters most when the device is not yours alone. If you run jobs on somebody else’s device — a teammate’s, or one shared with a group — the owner of that device can read what ran on it. That is not a leak; it is how a computer works, and we say it out loud on the screen where you consent, because a promise we could not keep would be worse than the plain fact.
Teams
A team admin can see members’ device names, connected sites, and usage metering for team activity, as shown in the product before you join. Personal subscriptions are never shared and their private usage is not attributed to team sharing.
Who touches this data
Hosting and database: Vercel and Supabase. Payments: Stripe. Sign-in: Google. We do not sell your data, we do not run ads, and we share data only with these processors, or if the law requires it.
Cookies
One session cookie, so you stay signed in. Nothing else — no analytics or advertising cookies.
Retention and deletion
Account and metering data are kept while your account exists. Delete your account (or ask support@byollm.cloud) and we delete your account data within 30 days, except invoices we must keep for accounting. Your own devices keep local logs on your machines; those are yours.
Security
End-to-end encryption for job content, per-device keys with a fingerprint ceremony you verify yourself, and row-level access controls in our database. Report security issues to security@byollm.cloud; see SECURITY.md in the repo.
Where you are
We operate from the United States and process data there; by using the service you consent to that processing.
Changes
Material changes are announced on the site and take effect when posted. Questions: support@byollm.cloud.
Questions about this document: support@byollm.cloud. The protocol and every claim above are open source at github.com/oftomorrowinc/byollm.