Privacy
Last updated September 2026.
What is stored
| Data | Purpose | Kept |
|---|---|---|
| Visitor id cookie (random, first-party) | Counts usage against the free limits; links past builds to this browser | 1 year |
| Consent cookie | Records that the consent notice was accepted | 1 year |
| Device signal hash (screen, time zone, language, graphics renderer, canvas rendering) | Part of the visitor key, so clearing a cookie does not reset the limit | With the visitor record: 90 days after the last visit without an account |
| Network prefix (first three numbers of the IP address), browser family | Part of the visitor key | With the visitor record |
| Full IP address | Rate limiting and abuse blocking; regional defaults such as currency and which stores to link; request logs at the hosting provider | Up to 90 days |
| Google Analytics cookies (_ga, _ga_*) and the events they send | Page views, tool usage and outbound clicks, so the site can see which tools get used and where visitors leave. With Google signals on, also demographic and interest reports and audience lists used for advertising on Google (advanced audiences) | Cookies 2 years; reports up to 14 months at Google |
| Chat transcript: your messages, the replies, each parts list, and a two-sentence summary | Past builds and reopening a chat; context for parsing a follow-up message. The transcript is never sent to the language model | 30 days after the last message without an account; 1 year with an account, or until the account is deleted |
| Usage counts per hour and day | Free limits | 7 days |
| Outbound store clicks (part, store, visitor) | Measure which parts get bought; affiliate reporting | Until deleted |
| Email address (only if you sign in) | Account sign-in with emailed codes; saved builds across devices | Until the account is deleted |
| Free-text requests sent to the language model | Only when the rule parser cannot read a message; the message and the session summary are sent to Anthropic's API, and the parsed result is cached by message hash | Cache until cleared; token counts logged for 1 year |
What is not stored
Passwords do not exist. Google Analytics is the only third-party script, and it loads only after the consent notice is accepted.
Third parties
Hosting and sign-in run on Amazon Web Services (S3, CloudFront, Lambda, Aurora, Cognito) in the United States. When the rule-based parser cannot read a message, that message is sent to Anthropic's API under their commercial terms. Store links go to Amazon and Newegg; those sites have their own policies and may pay custompc.ai a commission.
Google Analytics
After the consent notice is accepted, Google Analytics 4 may load and send Google the page address, a random client id from the _ga cookie, the visitor's IP address, browser details, and events such as builds made and store links clicked. Google uses the IP address to estimate location and then discards it, per Google's documentation on IP handling. Google processes this data under its partner sites policy.
Google signals may be turned on. It links visits to Google accounts that have Ads Personalization switched on, which adds demographic and interest reports and lets custompc.ai build audience lists (Google calls these advanced audiences) for advertising on Google. Google explains the feature at Activate Google signals. Visitors can switch off Ads Personalization at My Ad Center, or block Google Analytics entirely with the Google Analytics opt-out add-on.
IP addresses
Every request carries the visitor's IP address. custompc.ai uses it to limit how many requests one address can make, to block abuse, and to pick regional defaults such as currency and which stores to link. The first three numbers of the address go into the visitor key. The full address is stored with the visitor record, with each chat, with each language-model call, and in hosting request logs, all for up to 90 days. Google Analytics also receives it, as described above.
Your choices
Declining the consent notice keeps every cookie off and Google Analytics unloaded; the tools then stay off. Withdrawing consent on the settings page clears the cookies and marks the visitor record; the tools stop until consent is given again. Deleting an account removes the email, saved builds and preferences. Questions go to privacy@custompc.ai.
Automated clients
The MCP endpoint and the API are open to software agents. They are counted by network address and user agent for the same limits, and no cookie is set for them.