What we can see, and what we cannot
Being specific about this seems better than a vague promise.
What never reaches us: the contents of any file you open in a tool. Those run locally. There is no endpoint that accepts them.
What we do receive: requests for pages and API calls. Standard server logs — IP, path, timestamp, user agent. These are kept for debugging and rate limiting, not for profiling.
What is stored when you create an account: your username and profile details, your posts and comments, your credits balance, and an audit trail of administrative actions. If you bind an email address, we hold it for verification and account recovery.
What we do not do: sell data, run third-party analytics scripts, or embed advertising trackers. There is no analytics SDK in the client bundle.
If any of that changes, it will be stated in the terms rather than quietly added to a script tag.