Privacy · updated August 25, 2026

How Teranode Review handles submitted content.

A review necessarily sends the submitted answer and relevant context to external model providers. This notice explains that path, what Teranode stores for workbench, account, and paid Review flows, and the choices that change retention.

Do not submit client identifiers, account numbers, addresses, contact details, government identifiers, credentials, privileged material, or information your firm has not approved for this workflow.

Review input

What the operator submits.

The workbench accepts an AI-generated or human-authored source, the original decision question, recommendation, optional facts or constraints, and a confirmation that no client-identifying information is present. An AI source includes its model vendor and model. A human source includes the originating team or role. Teranode applies an identifier-detection backstop before inference, but the operator and firm remain responsible for the submission.

Advertising measurement

Advertising measurement is optional and consent-controlled.

Teranode may be configured with browser Pixels from OpenAI Ads, X Ads, and Meta Ads. Each network is absent unless its public configuration switch is set. Teranode asks once before loading any configured network. Choosing Allow measurement permits acquisition measurement only on the public home and pricing pages and on an exact approved /connect campaign arrival for that network. The approved campaign pairs are chatgpt / consumer_second_opinion, x / consumer_second_opinion_x, and meta / consumer_second_opinion_meta. Unknown, duplicate, bearer-like, control-character, cross-network, or malformed parameters fail closed. The /review , account, login, checkout return, and other private work surfaces are excluded from acquisition loading.

The same shared choice permits completed-order measurement only after Teranode's authenticated server status confirms that a paid Review credit was durably granted. OpenAI receives order_created, X receives the separately configured purchase conversion event, and Meta receives Purchase. Every command contains the public Review pack identifier, quantity one, and the same pseudonymous local purchase UUID. OpenAI also receives a fixed public product label, its content type, and an event option that opts out of future personalization. The UUID is supplied as each provider's event or conversion identifier for correlation and supported deduplication. Delivery is at least once: in particular, Meta's browser eventID does not guarantee deduplication between separate browser retries when no server event exists. Teranode does not supply your email, phone, name, Review text, payment amount, currency, Stripe identifiers, or card details. Meta's Purchase intentionally omits value and currency to enforce this minimization rule.

Provider SDKs may add technical fields, including event time, source and referrer URL paths, configuration data, opaque attribution references when present, and random browser identifiers. These SDK-added fields are controlled by the provider code and may change under its policies.

Completed-order measurement runs in a URL-clean, form-free, same-origin document and is unloaded before the signed-in account page returns. Each configured adapter receives the same minimized event. A partial queue, failed SDK, timeout, navigation, or document teardown is nonterminal and retains the bounded recovery target for a retry with the same UUID. No browser Pixel failure can block purchase fulfillment.

The /connect campaign page contains optional Review input fields. Teranode does not put their contents or other account data into Pixel commands. However, after you allow measurement, each configured third-party script allowed for that exact campaign runs on the page and can technically access its document and same-origin browser storage, including text entered while it remains loaded and any existing tab-scoped checkout recovery queue. OpenAI automatic advanced matching must remain disabled in its provider controls. Teranode queues X's automatic advanced matching, automatic configuration, data-layer tracking, and dwell tracking settings as off before X configuration. Teranode disables Meta automatic configuration before its two-argument init and does not provide advanced-matching identity data. Observable provider proof remains required before any campaign is enabled. Vercel's separate infrastructure telemetry is not controlled by this advertising-measurement choice.

With consent, OpenAI's current SDK may keep oaiq_consent local storage until cleared, __oaiq_consent and __oppref first-party cookies for up to 30 days, __obref for up to 365 days, and a per-Pixel oaiq_cs: session marker. X may keep first-party _twclid and _twpid cookies for about 390 days. Meta may keep first-party _fbp and _fbc cookies for about 90 days. SDK behavior and lifetimes can change under each provider's policies.

Choosing Decline blocks future SDK loading and measurement, applies available runtime revocation, attempts to remove the known eligible first-party cookies and OpenAI storage markers above, and forces a fresh document after X has loaded because X provides no documented in-page revocation command. A browser may prevent deletion, and Teranode cannot remove cookies stored on a provider's own domain. The saved Teranode Allow or Decline preference remains in local storage until you change it or clear browser data. You can change it through Privacy choices, review X's settings in its personalization controls, and review Meta's settings in its Ad preferences.

During checkout, this tab may keep up to ten recovery entries. Each entry contains a version, local purchase UUID, Stripe Checkout Session identifier, creation time, and last measurement-attempt time. A Session-only fallback is used when the purchase entry could not be recovered. Entries older than 24 hours are ignored and removed on the next read; durably expired, reversed, or otherwise ineligible entries are removed earlier. A browser cancellation is not treated as durable payment authority and does not delete a recovery entry. A conversion fan-out is removed only after every enabled conversion adapter queues or deduplicates the stable UUID, every requested SDK reports loaded, and a bounded batch dwell completes. Partial queues, SDK failures, timeouts, navigation interruption, or page teardown retain the entry for a bounded retry. The measurement document adds only one bounded lookup identity and timestamps for at most ten minutes, then synchronously removes that stage before any status request or SDK request. Because that document is same-origin, existing same-origin browser storage, eligible cookies, and the tab-scoped checkout recovery queue remain available to code in it; Teranode does not supply those values to any Pixel command. The document rechecks authenticated server status before measuring. URL identifiers are removed before any SDK request, including when the user is signed out or browser storage is blocked. If storage is blocked, recovery can continue only while the current page remains open.

Inference path

Who receives the review content.

The browser sends the input to a Teranode endpoint hosted on Vercel. The server constructs a separate prompt for each assigned review lens and sends it through OpenRouter to the selected model provider. When the source is AI-generated, its model vendor is excluded from those assignments. A human-authored source is not attributed to a model vendor.

The request sets OpenRouter's per-request ZDR and data-collection-deny controls. OpenRouter documents those controls as routing only to endpoints covered by its Zero Data Retention policy and providers that do not collect user data; handling remains governed by OpenRouter's terms. These are routing-policy controls; Teranode does not operate the routing or inference providers' infrastructure. Current subprocessors are listed on Trust.

Workbench default retention

Browser-returned reviews without account purchase.

For the standard workbench path that is not tied to a paid Review credit account, the review endpoint does not write the submitted question, answer, context, or completed review to the Teranode firm record database. It returns the structured review and a server-issued integrity token to the browser. Infrastructure providers may process request metadata required to operate and protect their services.

Closing the browser before attestation may remove the working copy from the interface. Teranode does not promise browser recovery.

The operator may download an unattested local draft containing the source input, issued review and integrity token, work-in-progress dispositions, and reviewer fields. Downloading a draft does not file it or store it in Teranode's firm record database. The operator and firm are responsible for handling the downloaded file under their policies.

Accounts and paid Reviews

What is stored when you connect or buy a credit.

When you create a Review account or connect a host chatbot to the consumer Review path, Teranode stores account identifiers needed to operate the service, including a verified email address, host connection bindings, promotional and purchased credit balances, and a content-free credit ledger (grants, holds, consumption, releases). Signing in is not a subscription: Teranode writes to that address only about your own account and Reviews. Occasional notes from the founder are a separate opt-in you choose at sign-in, kept on their own list with an unsubscribe link in every message, never sold and never used for advertising.

A paid or credit-backed Review persists server-side state required to prepare, authorize, run, and retrieve that Review. That can include a de-identified prepared packet, execution state, cost and provider call metadata, integrity material, and the issued findings for account retrieval. This is separate from the optional firm archive attestation path described below.

Self-serve credit purchases are processed by Stripe. Stripe receives payment details and billing metadata according to its terms. Teranode stores payment references needed for fulfillment and reconciliation (for example Checkout session and payment identifiers), not your full card number. Refund and dispute events from Stripe may update credit and reconciliation state.

Attestation

What is sent when a reviewer creates the record.

Attestation sends the complete review, dispositions and any written bases, reviewer name and role, optional registration identifier, final decision, and integrity token to the server. The server checks the payload and constructs a timestamped review record with the human-entered attestation. Reviewer name, role, and optional registration identifier are supplied by the reviewer or firm; Teranode does not independently verify them. The SHA-256 fingerprint is a comparison value, not a digital signature.

Without an authenticated firm archive session, the record is returned without archive storage. The operator may print or download that copy, but Teranode does not store it in the firm record database.

Firm archive records

An authenticated firm archive stores the complete record.

When an authenticated firm creates the attestation, Teranode stores the complete record in a firm-scoped database. That includes the source question and answer, supplied context, source and reviewer provenance, findings, limitations, reviewer questions, dispositions, reviewer identity fields, final decision, timestamps, and fingerprint.

The archive is a Teranode service copy and is not represented as the firm's required books-and-records system. Retention, deletion, export, and contractual requirements are addressed with the firm before production use.

Site telemetry and subprocessors

Hosting, models, and payments process operational data.

The site uses Vercel hosting, Analytics, and Speed Insights. These services may process device, network, page, performance, and request metadata according to their service configuration and terms. Teranode does not use this notice to claim that infrastructure logs contain no IP addresses or other operational identifiers.

Model inference is routed through OpenRouter to selected model providers as described above. Identity for consumer connect may use an OpenID provider (Auth0 or equivalent) configured for the Service. Credit checkout uses Stripe. See also Trust for the current control summary.

Requests and contact

Ask about a record or this notice.

For a privacy request, identify the firm account or Review account email, review ID if any, and the action requested without sending the record contents by email. Write to privacy@teranode.ai or support@teranode.ai. Requests are evaluated against the applicable agreement and law.

Changes

This notice changes when the data path changes.

Material changes to providers, content retention, or archive storage will be reflected in this notice and its updated date. Firms under contract receive any notice required by their agreement.

Teranode Support

Talk to Teranode Support.

If you need help understanding Teranode, call 1-888-837-6950 (888-TER-6950). What it is, how to connect it to ChatGPT, Claude, or Grok, the privacy statement and how the product implements it, and who we are. That is what this line is for. The call is on Grok.

A Review of a specific case still starts at teranode.ai/connect. The line is not for walking through a pasted case. Findings are not advice.

Read the implemented controls on Securityand the end-to-end data path on Trust.