Skip to main content
Legal · Privacy

Privacy Policy

This policy explains what Bench Bazaar processes, where it goes, and the controls available to you when you create and share AI model benchmarks.

Effective

Local API key

Your OpenRouter key stays in your browser.

Client-side runs

Inference travels directly from your browser.

Private outputs

Eligible output bodies use private object storage.

No ad tracking

No advertising trackers or sale of personal data.

01

Scope

This Privacy Policy applies to the Bench Bazaar website, application, and related services (the “Service”). Bench Bazaar is operated by Ryan Stolliker (“Bench Bazaar,” “we,” “us,” or “our”).

This policy covers personal information we process as the operator of the Service. Third-party services you choose to use, including OpenRouter, its model providers, Google, GitHub, Stripe, and Link, also process information under their own terms and privacy policies.

02

Information we collect

Account and identity information

Clerk manages accounts and may provide us with your Clerk user ID, name, username, email address and verification status, profile image, and account and sign-in timestamps. If you sign in with Google or GitHub, those providers send identity information to Clerk according to the permissions you approve.

Benchmark and run information

We collect the content and configuration you submit, including benchmark names and descriptions, tasks, prompts, grading criteria, visibility settings, model targets, routing and generation settings, presets, private access grant labels, saved benchmarks, run status and scores, response and routing metadata, manual review details, and timestamps. For eligible retained runs, we also store model output bodies in private object storage.

Billing information

We store your plan, Stripe customer and subscription identifiers, product and price identifiers, subscription status and dates, and checkout state. Stripe and Link collect and process payment methods, billing details, transaction records, and fraud-prevention signals. Bench Bazaar does not receive or store full payment card numbers.

Technical information

Our hosting and authentication providers may process IP address, request time, browser and device information, referrer, cookie or session identifiers, and operational and security logs when you use the Service. We do not currently use advertising cookies, third-party product analytics, or session replay.

Information you send us

If you contact us, we collect your contact information and the contents of the communication so we can respond.

03

How we use information

We use information to:

  • provide accounts, benchmark creation, client-side runs, grading, sharing, history, output retention, exports, and deletion;
  • authenticate users, enforce visibility and access grants, protect the Service, prevent abuse, and troubleshoot errors;
  • provide paid subscriptions, reconcile billing status, and manage customer support;
  • maintain and improve the Service using operational information and user feedback; and
  • comply with law, enforce our agreements, resolve disputes, and protect users, Bench Bazaar, and others.

Where applicable law requires a legal basis, we process information as needed to perform our contract with you, comply with legal obligations, pursue legitimate interests such as security and reliable operation, and with your consent where requested. We do not use benchmark prompts or model outputs to train AI models.

04

AI data flow

Step 1

Your browser

Holds your OpenRouter key and assembles the request.

Step 2

OpenRouter

Routes the prompt to your selected provider.

Step 3

Model provider

Generates and returns the response.

Your OpenRouter API key is stored in your browser's local storage if you choose to save it. The key is sent to OpenRouter from your browser and is not sent to or stored on Bench Bazaar servers.

Prompts, generation settings, and responses pass through OpenRouter and the selected model provider. Their logging, retention, training, and privacy practices depend on your OpenRouter settings, the selected route, and the provider. Review those settings and policies before submitting personal or confidential information.

During a run, output bodies initially exist in browser memory. We save scores, grading details, output metadata, and routing metadata to Bench Bazaar. Free-plan output bodies remain session-only. When output retention is available and enabled, your browser uploads the output directly to a private Vercel Blob store using a short-lived upload grant.

05

When information is shared

We disclose information only as needed to provide the Service, at your direction, for legal and safety reasons, or as part of a business transaction. We do not sell personal information, share it for cross-context behavioral advertising, or use it for targeted advertising.

Vercel

Application hosting, request delivery, operational logs, and private Blob storage for eligible retained model outputs.

Managed Postgres database hosting for account references, benchmarks, run metadata, scores, reviews, presets, and billing status.

Clerk

Authentication, account profiles, session management, identity verification, and account deletion.

Google and GitHub

Optional sign-in providers. If you choose one, it supplies identity information to Clerk under the provider settings and permissions you approve.

Stripe and Link

Hosted checkout, payment processing, fraud prevention, subscriptions, invoices, and the customer billing portal. Bench Bazaar does not receive full payment card numbers.

OpenRouter and model providers

User-directed AI inference. Prompts, generation settings, and model outputs pass from your browser through OpenRouter to the model provider you select.

Other users and the public

Public benchmarks and their shareable run pages can be viewed by anyone and may be indexed by search engines. Unlisted benchmarks and runs can be viewed by anyone who has the link. Private benchmarks are limited to the owner or to people using a valid access grant, as applicable. Do not put personal or confidential information in content you make public or share with others.

Legal, safety, and business transfers

We may disclose information when reasonably necessary to comply with law or valid legal process; investigate fraud, abuse, or security issues; enforce agreements; or protect rights, property, and safety. If Bench Bazaar is involved in a merger, financing, acquisition, reorganization, bankruptcy, or sale of assets, information may transfer as part of that transaction, subject to applicable law.

06

Cookies and browser storage

Bench Bazaar uses storage that is necessary for requested features:

  • Clerk cookies and browser storage keep you signed in, protect sessions, and support account security.
  • A theme preference remembers whether you selected the light or dark interface.
  • Private benchmark access grants may be stored in a cookie so access continues during later navigation until the grant expires or is revoked.
  • Your OpenRouter API key is stored in local storage only when you choose to save it. Anyone with access to your browser profile may be able to read it.

Blocking necessary cookies or browser storage may prevent sign-in, private sharing, saved preferences, or client-side runs from working. We do not currently place advertising or third-party analytics cookies.

07

Retention and deletion

We keep account information and user content while your account is active and as needed to provide the Service. Production output bodies retained for eligible runs are not age-deleted automatically; they remain until the related run, benchmark, or account is deleted, or until product retention rules remove them. Downgrading may restrict access to retained output bodies, and free-history limits may remove older runs and their outputs.

Account deletion has no grace period. When you confirm deletion, we begin canceling your subscription, deleting your Clerk account and Stripe customer, and removing your authored benchmarks, runs, presets, saved items, access grants, and retained outputs. Cleanup retries if a provider is temporarily unavailable. Manual grades you submitted on another user's run may remain only as de-identified score data, without your user ID or review details.

After deletion completes, we retain a minimal deletion tombstone for 30 days to make cleanup reliable, then purge it. Providers may retain logs, backups, transaction records, or other information under their own schedules or where required by law. We may also retain limited information where necessary to meet legal obligations, resolve disputes, prevent fraud, or enforce agreements.

08

Security

We use technical and organizational safeguards designed to protect information. These include managed authentication, access checks, hashed private-access tokens, private object storage, short-lived upload and download grants, bounded output sizes, server-side output validation, and isolated previews for untrusted HTML and SVG model output.

No system is completely secure. Protect your account, browser profile, OpenRouter key, and private share links, and contact us if you believe your account or information has been compromised.

09

Your choices and rights

Depending on where you live, you may have rights to access, correct, delete, restrict, or object to processing of personal information; receive a portable copy; withdraw consent; or appeal a denied request. You may also have the right to complain to your local data protection authority. We do not discriminate against users for exercising privacy rights.

  • Use Settings → Data & privacy to download an authored-data archive or delete your account.
  • Update profile information through the Clerk user menu.
  • Clear your OpenRouter key in Settings or your browser's site data.
  • Choose benchmark visibility and revoke private access grants.
  • Contact us for requests that are not available through self-service tools. We may need to verify your identity.

The account export excludes payment records held by Stripe, OpenRouter keys stored only in your browser, and content owned by other users. You can request those records from the relevant provider.

10

International transfers

Bench Bazaar and its providers operate in the United States and other countries. Your information may be transferred to, processed, and stored in countries with data protection laws different from those where you live. Where required, we and our providers rely on recognized safeguards for international transfers.

11

Children

The Service is not directed to children under 18, and we do not knowingly collect personal information from children. If you believe a child has provided personal information, contact us so we can review and delete it as appropriate.

12

Changes to this policy

We may update this policy as the Service or law changes. We will post the revised policy here and update the effective date. If changes are material, we will provide additional notice as required by law, such as through the Service or by email.

13

Contact

Privacy questions and requests

Ryan Stolliker, operator of Bench Bazaar

support+bazaar@ryanws.tech