← phewsh.com
Privacy Policy
Last updated: July 19, 2026
What we collect
- Account info: Email, display name, and avatar from Google/GitHub OAuth. We don't store passwords.
- Project data: Project names, intent artifacts, decisions, handoffs, tasks, membership, and the append-only event record you choose to sync.
- Connector provenance: For MCP writes, Phewsh records the calling provider/client signal, an optional session identifier, timestamps, and revision/idempotency data. These signals are labeled as claimed provenance, not proof of model identity.
- Generation usage: When you use Phewsh's generation features, we may record the model, token counts, and timestamps for billing, SAP tracking, and service improvement. The continuity MCP tools do not invoke a model.
- Payment info: Handled entirely by Stripe. We never see or store card numbers.
What we don't collect
- We do not store third-party BYO model keys sent through local-only browser features. Phewsh access credentials are handled separately: API keys are stored as one-way hashes server-side. Scoped connector keys also store a user-chosen label, declared MCP-only purpose, optional expiry, revocation state, and last-use timestamp. A connector's plaintext bearer credential is sent only to the MCP service; a model-gateway key is sent only to the gateway. Phewsh never stores either plaintext key.
- We don't sell, share, or monetize your data.
- We don't use your content to train AI models.
How we use your data
- To provide the service: sync project truth, return bounded continuity context, record user-requested decisions and handoffs, generate artifacts, and track credits.
- To track AI usage via SAP (Sustainable AI Protocol): model, tokens, estimated energy/carbon per generation.
- To improve the product based on aggregate usage patterns (never individual content).
Data storage
All data is stored in Supabase (hosted on AWS). Row-level security and service-side membership checks restrict access to projects you own or were invited to. Projects and artifacts are encrypted in transit (TLS) and at rest.
Retention
Project records, decisions, handoffs, and claimed provenance are retained while the cloud project or account is active. On a deletion request to hello@phewsh.com, project data is removed from primary storage within 30 days and purges from encrypted backups within 90 days.
Generation-usage records (model, token counts, timestamps) are retained 24 months for billing and SAP reporting, then deleted or aggregated beyond identification. One-way API-key hashes are deleted with the account; revoked connector keys retain their hash and revocation timestamp for 90 days so a compromised key can be audited. Raw Phewsh API keys are never stored server-side.
AI tools, plugins, and MCP connectors
When you connect Claude, ChatGPT, Codex, or another MCP client, the client sends only the tool arguments needed for the action you requested. Phewsh's continuity tools can return project metadata, bounded intent artifacts, decisions, handoffs, task counts, event revisions, timestamps, and claimed client provenance. Write tools can add a proposed or observed decision or handoff; they cannot mark an AI-authored write as human-approved or repository-verified.
The MCP service does not receive your source tree, terminal transcript, editor buffers, or private model conversation unless you deliberately include that material in a decision, handoff, or other tool argument. Phewsh does not use connector content to train AI models.
Third parties
- Supabase: Database, auth, edge functions.
- Stripe: Payment processing.
- OpenRouter: AI model routing (only when using PHEWSH credits, not BYO keys).
- Google/GitHub: OAuth sign-in only.
Your rights
- You can export your data at any time (download artifacts as markdown).
- You can request deletion of your account and associated cloud data by contacting hello@phewsh.com.
- You can use the service without an account (local-only mode).
Cookies
We use Supabase auth cookies for session management. No tracking cookies, no analytics scripts, no ad networks.
Changes
We'll update this page if anything changes. Material changes will be communicated via the app.
Contact
Questions or data requests? Email hello@phewsh.com