what we see and what we don't
Privacy Policy
Last updated: June 12, 2026
heads upPaid Loads is a demonstration project. This policy describes how the system is designed to handle data; in this demo build there is no production traffic to handle. The design still matters, so here it is.
1. The one-line version
We sell the spinner, not you. Paid Loads never reads your code, your prompts, or your chat with the agent. The product is engineered so that it can't: the telemetry our clients send has no field that could carry source code, prompt text, completions, or conversation content. Wait-state detection (figuring out when your agent is thinking) happens entirely on your machine, and what it learns stays there.
2. What we collect
- An anonymous device identifier. A random id generated at install time. Before you sign in, it identifies a machine and nothing else.
- Ad-event telemetry. For each ad shown: the ad id, the surface it appeared on (status bar, statusline, overlay), how many milliseconds it was visible, and whether it was clicked. This is the data that decides who gets billed and who gets paid, so we keep it precise — and minimal.
- Your email, after you sign in. Sign-in is via Google; we store the email (and display name, if provided) solely to attribute earnings to you and pay you. Signing in links your device id to your account.
- Advertiser details. If you buy ads: your email, your ad creative (text, URL, optional brand and icon), and your bid. Card details go to Stripe; we never see your card number.
- Basic client metadata. Extension/CLI version and platform, used for compatibility and the killswitch — so we can stop serving to a broken client version instead of breaking your editor.
3. What we never collect
- Source code, in any form, ever.
- Prompts, completions, or chat content from your agent.
- File names, project names, or directory paths.
- Keystrokes, screenshots, or anything else on your screen.
If a future feature would require any of the above, the correct assumption is that we won't build it.
4. IP addresses
Like every server on the internet, ours sees your IP address when your client connects. We process it transiently — in memory, for rate limiting and fraud detection — and do not store it alongside your ad events or your account. Short-lived operational logs that include IPs are rotated on the order of days.
5. How we use and share data
We use the data above to run the auction, verify impressions, credit earnings, pay you, bill advertisers, and catch fraud. That's the list.
We share data with Stripe (payments and payouts — they require identity information for Connect onboarding, governed by their own privacy policy) and with authorities if the law genuinely compels it. We do not sell your data, and we don't build advertising profiles: ads are ordered by auction rank, identical for everyone, targeted at precisely nobody. The advertiser's targeting strategy is "developers exist."
6. Retention
- Ad events and ledger entries are kept while your account is active, because they are the audit trail for money. As financial records, they may be retained after account closure for as long as fraud-review and legal obligations require.
- Account data (email, devices) is deleted on request, except the minimum needed to keep the financial audit trail coherent.
- Transient data (IPs, operational logs) ages out automatically on short rotation.
7. Cookies
One session cookie, set when you sign in, so you stay signed in. No third-party analytics trackers, no ad pixels. It would be a little rich for a privacy-conscious ad network to wallpaper its own website with surveillance.
8. Your choices
- Turn it off: toggle Paid Loads off in the extension, or uninstall — everything it changed is restored.
- Sign out: your device returns to anonymous mode and earns nothing.
- Delete your account: email us; see section 6 for what must persist (the money trail) and what doesn't (everything else).
9. Changes and contact
If this policy changes materially, we'll post the update here with a new date at the top. Questions, deletion requests, or healthy skepticism: privacy@paidloads.com.
