Skip to privacy notice

Privacy Notice

Last updated .

What we collect

We collect signup and verification details, availability-waitlist email addresses and stated access interests, a keyed hash of the network address used for promotional activation or waitlist abuse controls and, when mobile verification is used, a keyed hash and last four digits of a verified mobile number, its country and carrier line-type classification and SMS consent records. We also collect hashed API-key metadata, payment-provider customer and transaction identifiers, promotional and purchased balance records, request timing, token counts, requested and resolved model identifiers, charges, status codes, latency, abuse signals, and campaign attribution needed to operate, secure, and improve Newton’s.

Browser and network verification

Limited launch accounts may use Cloudflare Turnstile instead of mobile verification. Cloudflare evaluates browser and network signals to confirm the request is human. Newton’s uses a keyed, one-way network identifier—not a raw address in the promotional-account ledger—to enforce one grant per network during the rolling eligibility window. A saved API key can be exchanged for a secure dashboard session. If a key-only customer loses every active key and every browser session, Newton’s cannot recover that account without a separately verified identity.

Mobile verification

We send the number you submit to Twilio to format and validate it, classify its carrier line type, assess verification abuse, and deliver and check a one-time SMS security code. Promotional access is limited to numbers classified as mobile; VoIP, landline, toll-free, invalid, and unclassified numbers are rejected. Newton’s does not store the complete phone number in its account database. We retain a keyed, one-way phone identity hash, the last four digits, country, line type, consent and verification timestamps, and provider reference identifiers needed for sign-in, fraud prevention, and enforcing one promotional grant per identity. Twilio processes the full number under its own privacy and retention terms.

Prompt handling

Newton’s does not sell customer prompts or outputs. To deliver inference, Newton’s sends prompts, other supported request content, and model responses to the upstream inference processor and routed model provider used by the selected published route. Yunwu API is a current inference processor. Newton’s may also use other configured inference suppliers or model providers for particular published routes, and the processor used may vary by route and available capacity. Upstream processors may perform content review and risk filtering, use encrypted or deidentified request-and-response data for service optimization, aggregate statistics, troubleshooting, and safety, and preserve relevant logs when they suspect a violation or receive a legal request. Each processor and routed model provider applies its own data and retention terms; Newton’s branding does not change those practices. Contact founders@newtons.dev for current subprocessor information before sending production data.

Payments and fraud prevention

Payment-card details are collected and processed by our payment provider rather than stored by Newton’s. Stripe Checkout may collect your payment receipt email when you start a Solo or Team membership or add Agents credit. We receive customer, checkout, subscription, invoice, payment status, amount, currency, renewal, cancellation, refund, and dispute identifiers and limited billing details needed to credit the correct account, prevent duplicate grants, address fraud, and maintain an auditable service-credit ledger.

Security and retention

API keys and promotion network identifiers are stored as one-way hashes. Complete phone numbers and SMS codes are not intentionally written to the Newton’s account database. Raw prompts and outputs are not intentionally written to the Newton’s usage ledger. Operational and financial metadata is retained as needed for security, billing, fraud prevention, debugging, dispute resolution, and legal obligations. Upstream processors may have separate retention practices. Do not send secrets or regulated personal data unless a separately signed agreement expressly permits it.

Newton’s customer API keys authenticate requests to Newton’s and are not forwarded as supplier credentials. Some upstream routes may use an account-scoped supplier credential that Newton’s stores encrypted at rest and can revoke independently. Other routes may use Newton’s shared upstream service credentials. Credential isolation therefore depends on the published route and current supplier configuration and is not guaranteed for every request.

Service providers

We use infrastructure, mobile verification, fraud-prevention, payment, analytics, and inference providers to deliver the service. Yunwu API is a current inference subprocessor, and other configured inference suppliers or routed model providers may process requests for particular published routes. Newton’s remains the customer-facing brand, but branding does not remove required subprocessor disclosures or the terms that apply to an underlying processor.

Advertising measurement

When advertising measurement is enabled, we may send limited interaction data—such as page and signup events, campaign identifiers, browser or click identifiers, IP address, and user agent—to advertising platforms to measure campaign performance and prevent fraud. We do not send prompts, outputs, API keys, or payment-card details for advertising measurement. Where required, this measurement is subject to consent choices and applicable opt-out rights.

Advertising measurement choices

Current choice: Not selected. You can change this choice at any time.

Your requests

Request access, correction, deletion, or export by emailing founders@newtons.dev. Some transaction, security, and ledger records may be retained when required for legal, accounting, fraud-prevention, or dispute-resolution purposes.