Back to the roadmap builder

AI key settings

Connect your own OpenAI, Anthropic or Google key to generate roadmaps on your own provider account. Your key is stored only in this browser, never on our servers or in your account.

How your key is protected

This page is maintained by the app owner to answer common questions about how a pasted AI provider key is handled. It describes the controls built into this app — it is not an independent audit or certification.

No key saved

Nothing is stored in this browser.

  • Masked in the interface

    Key fields are password inputs and saved keys show only the first and last four characters, with an explicit reveal toggle.

  • Encrypted before it is written

    Your passphrase derives an AES-256-GCM key (PBKDF2-SHA256, 250,000 iterations) in your browser. Only the ciphertext reaches local storage.

  • Never stored on our servers

    The key is not saved to our database or your account. Testing a key forwards it once to the provider you chose and it is discarded after the response.

  • Never written to logs

    Server and browser log paths run through a redaction layer that scrubs API-key and bearer-token patterns before anything is recorded.

Your passphrase is never stored or transmitted, so it cannot be recovered — if you lose it, remove the key and paste a new one. You can revoke a key here at any time; if you think it was exposed, also delete it in your provider's dashboard.

Your key is encrypted in this browser using AES-256-GCM before it is saved. The passphrase is something you make up to unlock it. The passphrase itself is never stored or sent anywhere — if you lose it, you'll need to paste the key again.