How CometWeb uses AI
This page serves the transparency measures of the EU AI Act (Art. 4 — AI literacy, and Art. 50 — informing people they are interacting with AI-generated output). CometWeb is not a high-risk AI system, so the Chapter III obligations do not apply to it. We explain which models we use, what for, what their limits are, and what rights you have.
What we use
CometWeb does not build its own AI models. We use language models (LLMs) from third-party providers via their APIs. Which model runs depends on the path you choose in settings.
Standard path (default)
OpenRouter gateway (US) for most AI calls; OpenAI models (including direct api.openai.com when project/third-party context is privacy-rewritten), plus Anthropic and DeepSeek only as OpenRouter slugs — never direct api.deepseek.com. On the standard path we do not agree to model training on your data. Provider retention follows each vendor’s policy; we do not claim verified Zero Data Retention across providers (direct OpenAI ZDR may be self-asserted until account evidence is filed).
Extended path (opt-in)
You enable it knowingly in Settings. The model may use the submitted data for further training, so before sending we apply the full four-layer personal-data redaction (the standard path runs layers 0 and 1).
What AI can and cannot do
AI can
- Summarise analytics data (GSC, GA4, Bing) into readable insights.
- Propose SEO/UX/performance action priorities.
- Draft fixes (fix-pack) and comment on changes.
AI cannot
- Fetch fresh data from the internet in real time.
- Guarantee correctness — it can hallucinate or be wrong.
- Make business decisions for you — every decision is yours.
What we strip before sending to the model
On the free (opt-in) path we strip personal data before sending the context:
- Email addresses
- IP addresses (v4, v6)
- Phone numbers
- Credit cards (Luhn-validated)
- PESEL, IBAN
- URL query strings and fragments
- First and last names (GUS PL dictionary)
- Street addresses, postal codes, cities with a postal code in context
- GA4 identifiers (client_id, user_pseudo_id)
- Social media profile URLs (LinkedIn, Facebook, etc.)
- Court case reference numbers (Art. 10 GDPR)
- Health / medical terms (Art. 9 GDPR)
- Dates of birth written as prose ("ur. DD.MM.YYYY")
This is pseudonymisation, not full anonymisation under GDPR. Once data is incorporated into a model, removal may be impossible — we disclose this when enabling consent.
Sub-processors
| Name | Role | Country |
|---|---|---|
| Hostinger (Hostinger Operations UAB) | hosting_database_email | EU (LT) |
| Auth0 / Okta | authentication | US/EU |
| Stripe | payments | IE/US |
| Cloudflare | edge_waf_turnstile | US/EU |
| OpenRouter | llm_gateway_primary | US |
| OpenAI (via OpenRouter and direct API) | llm | US |
| DeepSeek (via OpenRouter only) | llm_slug | CN (via US gateway) |
| Perplexity (via OpenRouter) | ai_sov_via_openrouter | US |
| SearchApi LLC | serp_active | US |
| Google (GSC / GA4) | analytics_source | US |
| Microsoft (Bing Webmaster, Clarity) | analytics_source | US/EU |
| Yandex (opt-in integration) | analytics_source_optional | RU |
The current, authoritative register (role, country and transfer mechanism) is published at /api/auth/policy/sub-processors and in the Privacy Policy.
Current policy versions
Loading...
Your rights
- Download a copy of your data (Art. 15/20 GDPR) — /settings/data.
- Withdraw consent at any time (Art. 7.3) — Settings → AI training consent.
- Object to processing (Art. 21) — form at /settings/data.
- Delete account (Art. 17) — /settings/data; 30-day recovery window.
- Consent history with proof (Art. 7.1) — /settings/data.
- Research dataset contribution (Art. 6(1)(a), opt-in) — /research and /settings/data.
Data protection contact
We have not designated a Data Protection Officer — we are not required to under Art. 37(1) GDPR. For matters related to AI data processing — questions, objections, complaints — write directly to the controller:
We respond within 30 days (Art. 12.3 GDPR).