Legal
Privacy Policy
Last updated: 1 October 2026
The short version
- When you run a review, the only code that leaves your machine is what your IDE (or your API call) sends with that request.
- It travels over HTTPS to MegaLens and, through OpenRouter, to the AI models that run the review; each result names the models that reviewed your code, and every provider involved is listed below.
- MegaLens never trains AI models on your code and never sells your code or your personal data, though each AI provider's own terms govern how it handles what it receives.
- What we store, for how long, and everything else is set out in full below.
1. Who we are
MegaLens.ai is operated by Outreach Solutions Pty Ltd, an Australian company. We are the data controller for the personal data processed through our platform.
Contact: [email protected]
2. What data we collect
| Category | Data | Purpose |
|---|---|---|
| Account | Email, display name, avatar (via OAuth) | Authentication, account management |
| Query content | Text you submit for analysis | Routed to AI providers for multi-AI analysis |
| API keys (accounts with own-key use) | Your OpenRouter API key, encrypted AES-256-GCM | Routing queries through your own API account |
| Billing | Stripe customer ID, subscription ID, plan and status, billing period dates, credit balance, payment and credit records (amounts, dates, type), overage and auto-recharge settings | Plan and pay-as-you-go billing (see 2.1) |
| Usage logs | Provider, model, token counts, cost, latency per call | Service improvement, cost tracking, abuse prevention |
| Review history | Session metadata, review queries, AI responses | Review continuity, product improvement |
2.1 Payments and billing data
- Payments are processed by Stripe. You enter your card details on Stripe's own pages (Stripe Checkout). We do not store card numbers.
- What we keep about your billing: your Stripe customer ID, your subscription ID, price, plan and status, the start and end dates of your billing period, whether it is set to end, your credit balance, and a ledger of credit entries (deposits, usage, refunds, adjustments and bonuses with their amounts, dates and any Stripe payment reference). We also keep your overage and auto-recharge settings.
- Stripe keeps its own payment records under its own terms and privacy policy.
- How long we keep billing records is in Section 8.
3. How your data flows through AI providers
MegaLens is a multi-AI review service. When you submit a query from your IDE, MegaLens selects up to four AI models from different companies to review it. Other models plan the review, check claims, and run a final check of the findings. Reviews through the REST API use a different lineup of models. This is the core of our service.
Important: Your queries are processed by third-party AI providers
Each query you submit is sent via OpenRouter (a US-based API gateway) to one or more of the AI providers listed below. These providers process your query content to generate responses. Provider selection may vary by task type, model availability, performance, or safety. While MegaLens requires OpenRouter, as its model-routing provider, to process data under applicable contractual data protection obligations, any downstream model providers operate and manage their own infrastructure independently.
MegaLens may route a request across multiple providers in a single run. The exact model or provider used for a given request may change over time as we update routing, benchmarking, safety controls, and service availability, provided they remain within our declared list of authorized sub-processors (see Section 10).
AI providers we use
| Provider | Headquarters |
|---|---|
| DeepSeek | China |
| Xiaomi (MiMo) | China |
| Moonshot AI (Kimi) | China |
| Zhipu AI (GLM) | China |
| Alibaba (Qwen), not used at present | China |
| MiniMax | China |
| xAI (Grok) | United States |
| Mistral (Mistral models) | France (EU) |
| Meta (Muse) | United States |
| Perplexity | United States |
| Google (Gemini) | United States |
| OpenAI (GPT) | United States |
| Anthropic (Claude) | United States |
What MegaLens does not do with your code or your data
MegaLens never trains AI models on your code or on the content of your reviews, and never sells your code or your personal data. The code your IDE sends is used to run the review you asked for. The AI providers listed above process it under their own terms, as set out in this section.
4. Data processing in China
Disclosure: Chinese AI providers
Six of the AI providers listed above are headquartered in the People's Republic of China. We use five of them at present. Alibaba (Qwen) is not used at present and stays listed because it may be used again. Under China's National Intelligence Law (2017), Cybersecurity Law (2017), and Data Security Law (2021), these companies may be required to cooperate with Chinese government intelligence operations.
By using MegaLens, you acknowledge that query content routed to these providers may be subject to Chinese law. We route all traffic through OpenRouter (US-based), but this does not prevent downstream providers from processing your data under their local legal obligations.
We recommend that you do not submit personally identifiable information or other highly sensitive content to MegaLens. You must not submit attorney-client privileged materials, trade secrets, export-controlled technical data, classified information, or content subject to ITAR restrictions to the Service.
If you are subject to contractual, regulatory, export-control, or internal security restrictions on external AI processing, you are responsible for determining whether you are permitted to submit the relevant content through the Service.
5. International data transfers
MegaLens is operated from Australia. Your data may be transferred to and processed in:
- United States: Supabase (database hosting), Stripe (payments), OpenRouter (API gateway), Cloudflare (CDN and proxy), xAI, Meta, Perplexity, Google, OpenAI, Anthropic
- China: DeepSeek, Xiaomi, Moonshot AI, Zhipu AI, MiniMax, and Alibaba (not used at present)
- European Union: Mistral AI (France), Netcup (Germany, server hosting)
- Switzerland: Migadu (sign-in emails)
For EU/UK users: Transfers to countries without an EU adequacy decision (including China and the United States) are conducted on the basis of your explicit, informed consent. When you create an account, you tick a box to agree to the Terms of Service and this Privacy Policy, which describes these transfers. We record the time you ticked it and the versions of both documents. Accounts created before we added this box have no such record. You may withdraw consent at any time by discontinuing use of the service, but this will limit our ability to provide the service.
We are working toward implementing Standard Contractual Clauses (SCCs) with our key sub-processors. Until these are in place, consent is our primary transfer mechanism for non-adequate jurisdictions.
6. API key handling
Your own keys
Own-key use is no longer offered to new customers. It remains on accounts where we have switched it on. On those accounts, an OpenRouter API key you provide is encrypted using AES-256-GCM before storage. The encryption key is managed server-side and is never exposed to client applications.
Credits (pay-as-you-go)
For users who pay with credits, we create a per-user OpenRouter API key on your behalf using OpenRouter's Provisioning API. This key is stored AES-256-GCM encrypted. Its spend limit is synchronized with your MegaLens balance — if your balance reaches zero, the key is disabled on OpenRouter to prevent unauthorized charges.
You may request deletion of your stored API keys at any time. You can delete a stored key yourself at any time, whatever your plan or subscription status.
Plans
Reviews paid by a plan allowance run on MegaLens's own provider account, so no key of yours is stored for them.
7. Lawful basis for processing (GDPR)
| Processing activity | Lawful basis |
|---|---|
| Account creation and authentication | Contract (Art. 6(1)(b)) |
| Query processing through AI providers | Contract + explicit consent for cross-border transfers |
| Billing and payment processing | Contract (Art. 6(1)(b)) |
| Usage analytics and service improvement | Legitimate interest (Art. 6(1)(f)) |
8. Data retention
| Data type | Retention period |
|---|---|
| Account data | Until account deletion |
| Review history (free accounts) | Deleted 30 days after last activity |
| Review history (paid plans and pay-as-you-go credits) | Deleted 90 days after last activity |
| Usage logs (raw) | Deleted after 90 days |
| Usage logs (aggregated, anonymized) | Permanent (for service analytics) |
| Billing records (payment and credit ledger) | Kept for as long as accounting and tax law requires. They are unlinked from your account if you delete it |
| Subscription and customer records (Stripe IDs, plan, status, period dates) | Until account deletion |
| API keys | Until user deletion or account closure |
A cleanup job runs every day and deletes these records once their period ends. Two kinds of review are kept longer: a review charged to your credits, and your free first review. They are kept with the billing records, with their usage records.
You may request early deletion of your data at any time (see Section 9).
9. Your rights
Under GDPR (EU/UK users)
- Access — request a copy of your personal data
- Rectification — correct inaccurate data
- Erasure — request deletion of your data
- Restriction — limit how we process your data
- Portability — receive your data in a machine-readable format
- Objection — object to processing based on legitimate interest
- Withdraw consent — for processing based on consent
Under Australian Privacy Act (APP)
- Access (APP 12) — request access to your personal information
- Correction (APP 13) — request correction of inaccurate information
- Complaint — lodge a complaint with the OAIC (oaic.gov.au)
To exercise any right, email [email protected]. We respond within 30 days (GDPR) or 30 days (APP).
Account deletion: Deleting your account deletes your review history, usage events, API keys, and your subscription and customer records in our database. Deleting your account cancels any paid plan with Stripe immediately, with no refund for the rest of the period. If we cannot cancel the plan, your account is not deleted. Billing records are kept for legal reasons and are unlinked from your account. Aggregated, anonymized analytics data is retained. Per-call usage records are not removed when you delete your account. The daily cleanup deletes them after 90 days, except those tied to a billing record, which are kept with it.
10. Sub-processors
| Service | Provider | Location | Purpose |
|---|---|---|---|
| Database | Supabase Inc. | US | Data storage, authentication |
| Payments | Stripe Inc. | US | Subscription and PAYG billing |
| Advertising measurement | Reddit, Inc. | US | Conversion pixel on public pages and on the dashboard after your first review (see Section 11) |
| Server hosting | Netcup GmbH | Germany | Runs the MegaLens website and service |
| CDN and proxy | Cloudflare, Inc. | US | Delivers and protects traffic to megalens.ai |
| Sign-in email | Migadu | Switzerland | Sends sign-in and account emails |
| API gateway | OpenRouter | US | AI model routing |
| AI models | See Section 3 | US / China / EU | Query processing |
We will notify registered users of sub-processor changes via email at least 30 days before the change takes effect. You may object to a new sub-processor within that period by contacting [email protected].
11. Cookies and tracking
MegaLens uses strictly necessary cookies for authentication session management, one first-party cookie for campaign attribution, one third-party advertising pixel, and our own self-hosted analytics. Our analytics is self-hosted Umami. We do not use Google Analytics. The Reddit advertising pixel does send page and conversion events to Reddit, as described below.
Our analytics is Umami, running on our own server at analytics.megalens.ai. It sets no cookies and stores no identifier that can be linked back to you: each visit is counted using a one-way hash of your IP address, your browser, a server secret and a salt that changes over time, which cannot be reversed to recover your IP address. The IP address itself is never stored: there is no column for it anywhere in the analytics database. It records the page visited, the referring site, campaign parameters, and coarse facts about your device such as browser, operating system, screen size and country. On our advertising landing page it also records whether the video was played, how far down the page was read, which questions were opened, and which button was pressed. No data leaves this server and none of it is sold or shared.
| Name | Set by | Purpose | Lifetime |
|---|---|---|---|
| Supabase auth cookies | megalens.ai | Keeps you signed in. Strictly necessary. | Session / token lifetime |
ml_utm | megalens.ai (first party) | Records which advertising campaign brought you here, so we can tell which ads produce signups. Holds the campaign parameters from the link you arrived on, the page you landed on, and the referring site. Written only on a first visit carrying campaign parameters, and never overwritten afterwards. | 30 days |
| Reddit advertising pixel | reddit.com (third party) | Measures the results of our Reddit advertising. Reports a page view on every page, a content view on advertised pages, a signup event when an account is created, and an event when you complete your first review, sent from your dashboard. Reddit may use it to recognise you across sites. | Set by Reddit |
If you create an account through an advertising link, the campaign recorded in ml_utm is stored against your account so we can attribute the signup. It is used for our own reporting and is not sold or shared.
To refuse the advertising pixel, block third-party scripts from redditstatic.com and reddit.com in your browser or an ad blocker. To refuse our own analytics, block analytics.megalens.ai the same way, or switch on Do Not Track in your browser. Our analytics does not record your visit when Do Not Track is on. Refusing either does not affect your use of MegaLens. Clearing your cookies removes ml_utm.
12. Security measures
- API keys encrypted at rest using AES-256-GCM with per-record initialization vectors
- Row-Level Security (RLS) on every table that holds user data. Users can only access their own data
- HTTPS-only transport (TLS 1.2+)
- Stripe webhook signature verification
- Column-level grants hide encrypted key material from client queries
- Atomic billing operations with idempotency guards
13. Data breach notification
In the event of a data breach that poses a risk to your rights and freedoms, we will:
- Notify affected users within 72 hours (GDPR requirement)
- Notify the OAIC as required under Australia's Notifiable Data Breaches scheme
- Provide details of the breach, data affected, and remediation steps
14. Children
MegaLens is a B2B service not directed at individuals under 18. We do not knowingly collect data from children. If you believe a minor has provided us data, contact [email protected].
15. Changes to this policy
We may update this policy to reflect changes in our practices, sub-processors, or legal requirements. Material changes will be notified via email to registered users at least 14 days before taking effect. Your continued use after notification constitutes acceptance.
16. Data processing agreements
Enterprise customers who require a Data Processing Agreement (DPA) for compliance with GDPR, UK GDPR, or other data protection frameworks may request one by contacting [email protected]. Our DPA covers data processing scope, security obligations, sub-processor management, breach notification, and data subject rights assistance.
17. Contact
Outreach Solutions Pty Ltd
Email: [email protected]
Governing law: Laws of Victoria, Australia
For GDPR complaints, you may also contact your local data protection authority. For Australian complaints, contact the Office of the Australian Information Commissioner.
See also: Terms of Service