Privacy policy
Last updated 2026-09-22
Who we are
AI Power Ups is operated by Small Tree ("we"). Contact: support@powerups-ai.store.
What we collect
Account data: your email address and password hash (held by our authentication provider, Supabase), display name if you set one, and the settings you choose. Connection data: the API keys we issue (stored as hashes), and for apps you connect through sign-in, the app's name and identifier. Usage data: for every request an assistant makes on your behalf, the capability used, the provider called, the outcome, the provider cost, the tokens charged, the time taken and the time it happened. Search data: the search parameters your assistant sent, the results we returned and their identifiers, so that follow-up requests work. Sharpen data: the task, context, approach and draft your assistant sent, and the review returned. Billing data: your plan, billing period and subscription identifiers; payment details are handled by Paddle, our merchant of record, and never reach us.
Signing in with Google or Apple
If you choose Google or Apple when that sign-in option is available, the provider learns that you are signing in to AI Power Ups. Supabase receives your provider account identifier, email address and any name the provider shares so we can create or find your account. We do not receive your Google or Apple password. A verified email may link to an existing account automatically. Apple's Hide My Email can create a separate account using a relay address; receipts may not arrive if that relay rejects the sender.
We use a short-lived functional cookie to remember which provider you chose and whether an app asked you to sign in again. Deleting your AI Power Ups account removes its stored identities but does not revoke Google or Apple's grant. You can revoke that grant separately in your Google or Apple account settings.
Account sign-in and security history
We keep a record of your account's sign-in and security outcomes: confirmed sign-ups, sign-ins and reauthentication, verified recovery and email-change links and invitations, confirmed password changes, and attempts to sign out other sessions with their confirmed or uncertain results. It holds your account id, non-secret session, operation and attempt identifiers, the event time and outcome, and the sign-in method and provider when known. It never holds passwords, tokens, email-link codes, email addresses or device details. We keep this history for 400 days and delete it with your account. It is separate from anonymous daily counts and optional Google Analytics.
How we use it
To run the service, meter usage against your plan, show you your history, prevent abuse, and answer support requests. We do not sell personal data and we do not use your content to train models.
Who else receives data
Search parameters go to the provider that answers them (for example OpenAlex, Open-Meteo, Serper, SearchApi, Firecrawl, GitHub, YouTube, twitterapi.io, HeiGIT/openrouteservice, SEC EDGAR, legal-source publishers, wger and TheMealDB). Sharpen tasks and drafts go to the reviewing model's provider through OpenRouter (OpenAI, Anthropic, Google, xAI, DeepSeek, depending on the tier). Paddle receives your email address and user identifier to process subscriptions. Supabase hosts our database in London. Railway and Vercel host the API and website. Our email provider delivers account and authentication messages.
When a connected app requests identity access, the consent screen explains what it receives. With your permission, we share your stable account identifier and, if requested, your verified email address. The account identifier is the same across connected apps. Apps use this information to identify your account and apply their workspace access rules. Disconnecting an app stops further access through that grant.
How we measure our website
We measure our website in two separate ways. The first is on for everyone and records nothing about you. The second is off unless you turn it on.
Anonymous page counts
When you open our home, pricing, sign-up or log-in page, your browser tells our own server which one of those four pages it was, and we add one to a daily total. We also keep a daily total of successful sign-ups and log-ins, counted on our server. That is the whole of it: we store a date, a page or event name, and a number.
Counting a page view sends us no identifier of any kind: no cookie is set for it, no device or visitor identifier is created or read, and we store no IP address, browser details, referring site or web address you came from. The only thing your browser is asked for is which of those four pages you opened. Because nothing distinguishes one visit from another, we can see that the home page was opened four hundred times on a given day, but never who opened it, whether two of those visits were the same person, or whether a particular visitor later signed up.
You can switch page counting off below. Doing so does store one small cookie, because remembering your objection is the only way we can honour it; it holds nothing but that preference. Switching page counting off does not change the sign-up and log-in totals, which are counted on our server at the moment you sign in and involve nothing stored in your browser at all. Those totals hold no identifier either.
Optional Google Analytics
Google Analytics is off unless you switch it on below, and nothing on this site switches it on for you. Agreeing to our terms does not turn it on. If you do switch it on, we use it to understand visits to our website, completed sign-ups and logins, and Google receives page categories, browser and device information, cookie identifiers and an opaque account identifier while you are logged in. We do not send your name, email, password, search content, payment details, or URL query strings to analytics. We do not enable advertising personalization or Google signals.
You can withdraw at any time below. We remember your choice for six months. Withdrawal stops future collection and removes our Google Analytics cookies in that browser; it does not erase data already collected by Google. Essential sign-in cookies work either way. Google processes analytics data under its own privacy policy, including processing outside your country. See Google’s privacy policy. Contact support@powerups-ai.store about access or deletion of data associated with your account.
Anonymous page counts
On. Opening our home, pricing, sign-up or log-in page adds one to a daily total. No identifier is sent and no record of you is created.
This control covers page views only. We also keep daily totals of successful sign-ups and log-ins, counted on our server when you sign in. Those hold no identifier either, and because they involve nothing stored in your browser, turning page counts off does not change them.
Optional Google Analytics
Off. You have not turned Google Analytics on in this browser. Turning it on sets Google cookies and sends Google an opaque account identifier while you are logged in. It is entirely optional, and the service works exactly the same without it.
Separately from either of the above, and as with any website, requests to our site pass through our hosting and network providers, whose own operational logs record the IP address that made the request under their retention policies rather than ours. We do not use those logs for audience measurement.
Retention
Search sessions and results: expire 24 hours after last use. Search request summaries: expire after 24 hours. Durable Sharpen jobs retain the submitted task, context, approach, draft and result for 24 hours so an interrupted connection can retrieve the same review. Sharpen review records and task summaries: expire after 30 days. Expired jobs are removed by the review worker; other expired records are removed by hourly cleanup. Tasks and drafts are sent to reviewers when a review runs. Usage records: for as long as your account exists, as your billing ledger. Account data: until you delete your account. Deletion removes your account, connections, search data, reviews and usage history after billing cancellation is confirmed and any payment in progress has been reconciled. We retain only the minimal billing identifiers needed to reconcile outstanding payments and prevent an old billing event from recreating a subscription. Paddle keeps its own payment records under its retention policy. Anonymous daily page and sign-up counts are kept indefinitely; they are totals with no personal data in them, so there is nothing in them to delete or return to you.
Your choices
Choose how we measure your visits under how we measure our website. Revoke any key or disconnect any app from the dashboard at any time. Delete your account from the dashboard or by emailing support. Export your usage history from the usage page.
Security
Keys and tokens are stored hashed; traffic is encrypted; access to production systems is limited to the operator.
Changes
We will post changes here and update the date above.