Overview
ModelBank (modelbank.ai, “we”) is a public website about AI model status, prices and deprecations. We collect as little as possible: browsing needs no account, and alerts can be used without one. This policy explains what we collect, why, and how you control it.
What we collect
Account data: if you sign up, your email, display name, avatar URL and a salted hash of your password (we never see your plain-text password).
Social sign-in: with GitHub or Google we receive only your account ID, email, name and avatar. We do not access repositories, contacts or other data, and we do not store the provider’s access token.
Alert channels: browser push subscription endpoints and encryption keys, chat webhook URLs you enter, and the topics you follow.
Security & abuse prevention: login sessions, a one-way hashed IP digest (used for rate limiting, cannot be reversed), and your browser’s user agent.
Content you submit, e.g. “I’m having problems too” reports (service, time and an anonymous digest only).
How we use it
To provide sign-in and subscription management; to send the outage, recovery, price and deprecation alerts you choose; to send account emails (verification, password reset); and to prevent abuse.
We do not sell your data, use it for ad targeting, or share it with third parties except where required by law.
Cookies
We use only essential cookies: a session cookie (HttpOnly, 30 days), a “signed in” hint cookie, and a 10-minute security cookie during social sign-in. Your language preference, recently viewed items and on-device subscriptions are kept in your browser’s local storage. No advertising or cross-site tracking cookies.
Service providers
Hosting and database: Cloudflare. Social sign-in: GitHub and Google. Browser push is delivered through your browser vendor’s push service (e.g. Google FCM, Mozilla, Apple). Chat alerts go to the platform you configure (Slack, Discord, Feishu, DingTalk, WeCom, …). Account emails may be sent via Brevo.
Retention & deletion
You can delete your account at any time under Settings; your account, sign-in methods, sessions and linked subscriptions are removed immediately. Delivery logs are kept for 30 days and alert records for 90 days; broken push channels are cleaned up automatically.
You can remove any alert channel at any time from the alert panel or your account, or disable notifications for this site in your browser.
Security
HTTPS everywhere; passwords hashed with salted PBKDF2-SHA256; only hashes of session tokens are stored; rate-limited sign-in and sign-up; the admin area is additionally protected by Cloudflare Access.
Children
This site is intended for developers and professionals and is not directed at children under 13.
Changes & contact
If we update this policy we will change the date at the top. Questions or deletion requests: [email protected].