Privacy

Policy version: 2026-09-19

Operator and contact

An independent open-source project operated by Richard Tang (@richardt830). For privacy or deletion requests, email richard@learnest.org. Do not send API keys. Use GitHub for public bugs and discussions, never private tasks or deletion receipts.

We do not save your model API key

Your key stays in the current tab’s memory and clears on refresh. It is not included in research submissions, downloads or share links. This does not mean that no other data is saved: voluntary research contributions and provider or infrastructure records are separate, as explained below.

Playing as a guest

Your question, possible answers and any necessary context are sent to the selected AI providers when you explicitly run an experiment. OpenRouter calls go directly from your browser to OpenRouter. When enabled, Vercel AI Gateway calls pass through our fixed server relay: it handles your key and task in request memory without saving them. Providers process your content under their own policies. Do not submit passwords, confidential documents or sensitive personal information.

The page can access a key while you use it. Memory-only storage and HTTPS do not eliminate the need to trust the website and its code. Use a dedicated key with a small provider-side budget, never a production key or Vercel account token. You can browse cases without a key or inspect the open-source code and run it locally.

Connecting OpenRouter opens its own authorization page. If you authorize, JevArena exchanges a short-lived code directly with OpenRouter for a user-controlled API key and holds that key in the original tab’s memory. No model runs automatically. The callback code arrives in a URL and may appear in infrastructure access logs; it is removed from the visible URL immediately. The API key is not placed in URLs or browser storage. Disconnecting clears the tab’s key but does not revoke it at OpenRouter; revoke it in your OpenRouter key settings.

Guest drafts, model API keys, judgments and votes stay in the current tab unless you explicitly save, contribute, download or share them. Refreshing clears the in-memory state. API keys are not saved to an account, research submission or share link. This is not a promise that provider or hosting infrastructure keeps no operational logs.

Optional account and private history

When enabled, email sign-in uses Supabase Auth and a configured email-delivery service to send a one-time login link. The account contains your email and identity identifier. Your email is used for authentication and service messages, not a marketing subscription. Essential session cookies keep you signed in; they are separate from your model API key.

Only clicking Save privately after its separate checkbox uploads the selected question, answers, model results and vote to your account history. Logging in does not upload the current conversation automatically. History is private to your account in the application, not public or end-to-end encrypted; authorized infrastructure administrators may access stored data for operations and support. The service limits history to 100 experiments per account and retains each for up to 30 days.

Download or delete saved experiments from Your history. Expired items are excluded from reads immediately and removed by scheduled cleanup. Deletion removes active records; restricted infrastructure backups may retain copies until their normal expiry. Account deletion requests require identity verification through the private contact channel above.

Research contributions are a separate choice

Saving private history is not research consent. Research submission separately asks you to review the content, confirm rights and agree to the displayed contribution license. The intake stores the submitted task, runs, vote when supplied, consent version and timestamp. It also uses a salted IP hash for abuse limits; hosting providers may process IP addresses. Private research submissions remain untrusted, are retained for up to 30 days, and are not automatically published or used to run later paid evaluations.

Use your downloaded deletion receipt at Withdraw a contribution. Keep the receipt secret. Minimal receipt and abuse-prevention metadata may remain to prevent accidental resubmission. Public GitHub contributions and reviewed case pages require a separate deliberate publication workflow.

Sharing and public data

Instant share links contain approved experiment data in their URL fragment. Anyone with the link can read or copy it. Downloaded JSON and images are controlled by whoever receives them. Public GitHub content and published case studies can be copied or archived by others; removing our copy cannot recall those copies.

Infrastructure, cookies and security

Vercel hosts the site and functions; Supabase provides account and database infrastructure when configured; the authentication email-delivery service processes recipient addresses and login emails; selected AI providers process model requests. These services may process data outside your country. We use HTTPS, access controls, server-only credentials and owner-scoped database access. No system is risk-free. We do not intentionally log request bodies or API keys.

There is no marketing subscription, advertising tracker or reCAPTCHA in this release. Essential login cookies may remain until sign-out or expiry. Provider sites reached through external links have their own practices. Changes to processing will be reflected in a revised policy and appropriate new choices before new uses.