Scope
This Privacy Policy applies to the Bench Bazaar website, application, and related services (the “Service”). Bench Bazaar is operated by Ryan Stolliker (“Bench Bazaar,” “we,” “us,” or “our”).
This policy covers personal information we process as the operator of the Service. Third-party services you choose to use, including OpenRouter, its model providers, Google, GitHub, Stripe, and Link, also process information under their own terms and privacy policies.
Information we collect
Account and identity information
Clerk manages accounts and may provide us with your Clerk user ID, name, username, email address and verification status, profile image, and account and sign-in timestamps. If you sign in with Google or GitHub, those providers send identity information to Clerk according to the permissions you approve.
Benchmark and run information
We collect the content and configuration you submit, including benchmark names and descriptions, tasks, prompts, grading criteria, visibility settings, model targets, routing and generation settings, presets, private access grant labels, saved benchmarks, run status and scores, response and routing metadata, manual review details, and timestamps. For eligible retained runs, we also store model output bodies in private object storage.
Billing information
We store your plan, Stripe customer and subscription identifiers, product and price identifiers, subscription status and dates, and checkout state. Stripe and Link collect and process payment methods, billing details, transaction records, and fraud-prevention signals. Bench Bazaar does not receive or store full payment card numbers.
Technical information
Our hosting and authentication providers may process IP address, request time, browser and device information, referrer, cookie or session identifiers, and operational and security logs when you use the Service. We do not currently use advertising cookies, third-party product analytics, or session replay.
Information you send us
If you contact us, we collect your contact information and the contents of the communication so we can respond.
How we use information
We use information to:
- provide accounts, benchmark creation, client-side runs, grading, sharing, history, output retention, exports, and deletion;
- authenticate users, enforce visibility and access grants, protect the Service, prevent abuse, and troubleshoot errors;
- provide paid subscriptions, reconcile billing status, and manage customer support;
- maintain and improve the Service using operational information and user feedback; and
- comply with law, enforce our agreements, resolve disputes, and protect users, Bench Bazaar, and others.
Where applicable law requires a legal basis, we process information as needed to perform our contract with you, comply with legal obligations, pursue legitimate interests such as security and reliable operation, and with your consent where requested. We do not use benchmark prompts or model outputs to train AI models.
AI data flow
Step 1
Your browser
Holds your OpenRouter key and assembles the request.
Step 2
OpenRouter
Routes the prompt to your selected provider.
Step 3
Model provider
Generates and returns the response.
Your OpenRouter API key is stored in your browser's local storage if you choose to save it. The key is sent to OpenRouter from your browser and is not sent to or stored on Bench Bazaar servers.
Prompts, generation settings, and responses pass through OpenRouter and the selected model provider. Their logging, retention, training, and privacy practices depend on your OpenRouter settings, the selected route, and the provider. Review those settings and policies before submitting personal or confidential information.
During a run, output bodies initially exist in browser memory. We save scores, grading details, output metadata, and routing metadata to Bench Bazaar. Free-plan output bodies remain session-only. When output retention is available and enabled, your browser uploads the output directly to a private Vercel Blob store using a short-lived upload grant.
Retention and deletion
We keep account information and user content while your account is active and as needed to provide the Service. Production output bodies retained for eligible runs are not age-deleted automatically; they remain until the related run, benchmark, or account is deleted, or until product retention rules remove them. Downgrading may restrict access to retained output bodies, and free-history limits may remove older runs and their outputs.
Account deletion has no grace period. When you confirm deletion, we begin canceling your subscription, deleting your Clerk account and Stripe customer, and removing your authored benchmarks, runs, presets, saved items, access grants, and retained outputs. Cleanup retries if a provider is temporarily unavailable. Manual grades you submitted on another user's run may remain only as de-identified score data, without your user ID or review details.
After deletion completes, we retain a minimal deletion tombstone for 30 days to make cleanup reliable, then purge it. Providers may retain logs, backups, transaction records, or other information under their own schedules or where required by law. We may also retain limited information where necessary to meet legal obligations, resolve disputes, prevent fraud, or enforce agreements.
Security
We use technical and organizational safeguards designed to protect information. These include managed authentication, access checks, hashed private-access tokens, private object storage, short-lived upload and download grants, bounded output sizes, server-side output validation, and isolated previews for untrusted HTML and SVG model output.
No system is completely secure. Protect your account, browser profile, OpenRouter key, and private share links, and contact us if you believe your account or information has been compromised.
Your choices and rights
Depending on where you live, you may have rights to access, correct, delete, restrict, or object to processing of personal information; receive a portable copy; withdraw consent; or appeal a denied request. You may also have the right to complain to your local data protection authority. We do not discriminate against users for exercising privacy rights.
- Use Settings → Data & privacy to download an authored-data archive or delete your account.
- Update profile information through the Clerk user menu.
- Clear your OpenRouter key in Settings or your browser's site data.
- Choose benchmark visibility and revoke private access grants.
- Contact us for requests that are not available through self-service tools. We may need to verify your identity.
The account export excludes payment records held by Stripe, OpenRouter keys stored only in your browser, and content owned by other users. You can request those records from the relevant provider.
International transfers
Bench Bazaar and its providers operate in the United States and other countries. Your information may be transferred to, processed, and stored in countries with data protection laws different from those where you live. Where required, we and our providers rely on recognized safeguards for international transfers.
Children
The Service is not directed to children under 18, and we do not knowingly collect personal information from children. If you believe a child has provided personal information, contact us so we can review and delete it as appropriate.
Changes to this policy
We may update this policy as the Service or law changes. We will post the revised policy here and update the effective date. If changes are material, we will provide additional notice as required by law, such as through the Service or by email.
