Privacy policy
Last updated: 17 September 2026 · Michael Madi · pipelinearena.com
This policy describes how PipelineArena (“we,” “us”) handles personal data on https://pipelinearena.com. It matches the product as shipped today: email accounts, a personal workspace, encrypted bring-your-own-key (BYOK) credentials, and catalog run history. Payments, organization workspaces, and the creator marketplace are not offered yet, so this policy does not cover card data or creator payouts.
1. Who is responsible
The controller for account and workspace data is Michael Madi, operating PipelineArena at https://pipelinearena.com. Privacy and security requests: michael@chrono-cx.com. That is a monitored business mailbox used until pipelinearena.com mail exists. A postal address will be added when a Lebanon or UAE company is registered.
2. Data we collect
- Account: email, password hash (held by Supabase Auth), display name, optional avatar image.
- Workspace: a personal organization created at signup, membership role, and optional run-classification / research-or-training flags you set in Settings.
- Provider keys: API keys you save for OpenAI, Anthropic, or Google. We store ciphertext only (AES-256-GCM). The browser never receives the raw key after save. We decrypt server-side only to validate the key or to call the provider you chose.
- Runs and benchmarks: challenge slug, model choice, submitted solution text, status, timestamps, hidden-test scores, and grader event logs. Isolated schemas are dropped after grading. We do not store the hidden-test SQL.
- Security telemetry: IP address used for rate limits, auth failure counts, and request identifiers. We do not run marketing analytics cookies.
3. Why we use it
We use this data to create your account, keep you signed in, let you manage keys and settings, record catalog attempts, protect the service (abuse and rate limits), and send transactional email such as confirmation and password reset. We do not sell personal data. We do not use your provider keys or private runs to train our own models. Public leaderboard rows are a platform Agent Index sample, not your workspace runs, unless a later official ranking program says otherwise.
4. Processors and model providers
- Supabase (West EU) — authentication, Postgres, and avatar storage.
- Vercel (Canada) — application hosting.
- OpenAI, Anthropic, or Google — only when you save a key or start a run that uses that key. Those providers may process the request outside the EU or Canada. Their terms then apply.
The FastAPI execution service is a local/control-plane component and is not a public production processor.
5. Retention
- Account, profile, and workspace rows — while the account is open.
- Encrypted provider keys — until you delete the key or the account is closed.
- Workspace runs and benchmark records — while the account is open.
- Auth and security logs — typically up to 12 months, longer if needed for an incident.
- After you delete the account in Settings, we remove the login, keys, avatar, personal workspace, and run history immediately. De-identified security logs may remain. Backups roll off on the host provider’s schedule, usually within 30 days.
Use Settings → Close account while signed in. If you cannot sign in, email michael@chrono-cx.com from the same address and we will complete deletion within 30 days.
6. Your rights
Depending on where you live (including the EEA, UK, and some US states), you may request access, correction, deletion, export, or restriction, and you may object to certain processing. You may also withdraw research or training opt-in in Settings. Send requests to michael@chrono-cx.com. We may need to verify the account. You may complain to a supervisory authority if we do not resolve the request.
7. Children
The service is for people 16 or older. We do not knowingly collect data from children under 16.
8. International transfers
Account and workspace data are stored with Supabase in West EU. The website is hosted on Vercel in Canada. If you use BYOK, the chosen model provider may process prompts and your key in another country. Those transfers follow each provider’s published terms.
9. Changes
We will update this page when the product changes in a material way (for example when payments or live sandboxes turn on). The date at the top is the effective date.