Privacy Notice
Last updated .
What we collect
We collect signup and verification details, availability-waitlist email addresses and stated access interests, a keyed hash of the network address used for promotional activation or waitlist abuse controls and, when mobile verification is used, a keyed hash and last four digits of a verified mobile number, its country and carrier line-type classification and SMS consent records. We also collect hashed API-key metadata, payment-provider account and transaction identifiers, promotional and purchased credit records, request timing, token counts, requested and resolved model identifiers, charges, status codes, latency, abuse signals, and campaign attribution needed to operate, secure, and improve Newton’s.
Browser and network verification
Limited launch accounts may use Cloudflare Turnstile instead of mobile verification. Cloudflare evaluates browser and network signals to confirm the request is human. Newton’s uses a keyed, one-way network identifier—not a raw address in a promotional-account record—to enforce one grant per network during the rolling eligibility window. A saved API key can be exchanged for a secure dashboard session. If a builder with a key-only account loses every active key and every browser session, Newton’s cannot recover that account without a separately verified identity.
Mobile verification
We send the number you submit to Twilio to format and validate it, classify its carrier line type, assess verification abuse, and deliver and check a one-time SMS security code. Promotional access is limited to numbers classified as mobile; VoIP, landline, toll-free, invalid, and unclassified numbers are rejected. Newton’s does not store the complete phone number in its account database. We retain a keyed, one-way phone identity hash, the last four digits, country, line type, consent and verification timestamps, and provider reference identifiers needed for sign-in, fraud prevention, and enforcing one promotional grant per identity. Twilio processes the full number under its own privacy and retention terms.
Prompt handling
Newton’s does not sell builder prompts or outputs. To deliver inference, Newton’s sends prompts, other supported request content, and model responses to the configured inference provider for the selected model. Newton’s may use configured inference processors or model providers for particular models, and the processor used may vary by model and available capacity. Upstream processors may perform content review and risk filtering, use encrypted or deidentified request-and-response data for service optimization, aggregate statistics, troubleshooting, and safety, and preserve relevant logs when they suspect a violation or receive a legal request. Each processor and model provider applies its own data and retention terms; Newton’s branding does not change those practices. Contact founders@newtons.dev for the current subprocessor list before sending production data. Public API responses identify Newton’s as the gateway; they do not identify Newton’s commercial provider accounts.
Payments and fraud prevention
Payment-card details are collected and processed by our payment provider rather than stored by Newton’s. Stripe Checkout may collect your payment receipt email when you add prepaid credits. We receive account, checkout, invoice, payment status, amount, currency, renewal, cancellation, refund, and dispute identifiers and limited billing details needed to credit the correct account, prevent duplicate grants, address fraud, and maintain an auditable record of credits and payments.
Security and retention
API keys and promotion network identifiers are stored as one-way hashes. Complete phone numbers and SMS codes are not intentionally written to the Newton’s account database. Raw prompts and outputs are not intentionally written to Newton’s Activity records. Operational and financial metadata is retained as needed for security, billing, fraud prevention, debugging, dispute resolution, and legal obligations. Upstream processors may have separate retention practices. Do not send secrets or regulated personal data unless a separately signed agreement expressly permits it.
Newton’s API keys authenticate requests to Newton’s and are not forwarded as provider credentials. Some upstream models may use an account-scoped provider credential that Newton’s stores encrypted at rest and can revoke independently. Other models may use Newton’s shared upstream service credentials. Credential isolation therefore depends on the published model and current provider configuration and is not guaranteed for every request.
Service providers
We use infrastructure, mobile verification, fraud-prevention, payment, analytics, and configured inference providers to deliver the service. Newton’s does not publish its commercial provider account details in public API responses. The processor used for a selected model may vary by capacity and qualification status.
Advertising measurement
During Newton’s United States paid beta, we use limited interaction data—such as page, signup, activation, checkout, and confirmed-payment events; campaign identifiers; browser or click identifiers; IP address; and user agent—to measure campaign performance and prevent fraud. We do not send prompts, outputs, API keys, email content, credentials, or payment-card details for advertising measurement. You may select “Do not share for advertising” below at any time. Newton’s also honors an active Global Privacy Control browser signal. Default advertising measurement is not authorized by this notice outside the United States launch scope.
Advertising measurement choices
Current choice: Allowed. You can change this choice at any time.
Your requests
Request access, correction, deletion, or export by emailing founders@newtons.dev. Some transaction, security, and credit records may be retained when required for legal, accounting, fraud-prevention, or dispute-resolution purposes.