Privacy Notice
Last updated .
What we collect
We collect signup and verification details, a keyed hash of the network address used for a promotional activation and, when mobile verification is used, a keyed hash and last four digits of a verified mobile number, its country and carrier line-type classification and SMS consent records. We also collect hashed API-key metadata, payment-provider customer and transaction identifiers, promotional and purchased balance records, request timing, token counts, requested and resolved model identifiers, charges, status codes, latency, abuse signals, and campaign attribution needed to operate, secure, and improve Newton’s.
Browser and network verification
Limited launch accounts may use Cloudflare Turnstile instead of mobile verification. Cloudflare evaluates browser and network signals to confirm the request is human. Newton’s uses a keyed, one-way network identifier—not a raw address in the promotional-account ledger—to enforce one grant per network during the rolling eligibility window. A saved API key can be exchanged for a secure dashboard session. If a key-only customer loses every active key and every browser session, Newton’s cannot recover that account without a separately verified identity.
Mobile verification
We send the number you submit to Twilio to format and validate it, classify its carrier line type, assess verification abuse, and deliver and check a one-time SMS security code. Promotional access is limited to numbers classified as mobile; VoIP, landline, toll-free, invalid, and unclassified numbers are rejected. Newton’s does not store the complete phone number in its account database. We retain a keyed, one-way phone identity hash, the last four digits, country, line type, consent and verification timestamps, and provider reference identifiers needed for sign-in, fraud prevention, and enforcing one promotional grant per identity. Twilio processes the full number under its own privacy and retention terms.
Prompt handling
Newton’s does not sell customer prompts or outputs. To deliver inference, we currently send prompts, other supported request content, and model responses through Yunwu API, our inference processor and subprocessor. Yunwu may forward this content to overseas model providers, perform content review and risk filtering, and use encrypted and deidentified request-and-response data for service optimization, aggregate statistics, troubleshooting, and safety. Yunwu may preserve relevant logs when it suspects a violation or receives a legal request. Yunwu and routed model providers apply their own data terms and retention practices; white-label routing does not change those practices.
Payments and fraud prevention
Payment-card details are collected and processed by our payment provider rather than stored by Newton’s. Stripe Checkout may collect your payment receipt email when you choose to add credit. We receive identifiers, payment status, amount, currency, refunds, disputes, and limited billing details needed to credit the correct account, prevent duplicate grants, address fraud, and maintain an auditable service-credit ledger.
Security and retention
API keys and promotion network identifiers are stored as one-way hashes. Complete phone numbers and SMS codes are not intentionally written to the Newton’s account database. Raw prompts and outputs are not intentionally written to the Newton’s usage ledger. Operational and financial metadata is retained as needed for security, billing, fraud prevention, debugging, dispute resolution, and legal obligations. Upstream processors may have separate retention practices. Do not send secrets or regulated personal data unless a separately signed agreement expressly permits it.
Service providers
We use infrastructure, mobile verification, fraud-prevention, payment, analytics, and inference providers to deliver the service. Yunwu API is our current inference subprocessor. Newton’s remains the customer-facing brand, but branding does not remove required subprocessor disclosures or the terms that apply to an underlying processor.
Advertising measurement
When advertising measurement is enabled, we may send limited interaction data—such as page and signup events, campaign identifiers, browser or click identifiers, IP address, and user agent—to advertising platforms to measure campaign performance and prevent fraud. We do not send prompts, outputs, API keys, or payment-card details for advertising measurement. Where required, this measurement is subject to consent choices and applicable opt-out rights.
Your requests
Request access, correction, deletion, or export by emailing founders@newtons.dev. Some transaction, security, and ledger records may be retained when required for legal, accounting, fraud-prevention, or dispute-resolution purposes.
NEWTON’S