AI key settings
Connect your own OpenAI, Anthropic or Google key to generate roadmaps on your own provider account. Your key is stored only in this browser, never on our servers or in your account.
How your key is protected
This page is maintained by the app owner to answer common questions about how a pasted AI provider key is handled. It describes the controls built into this app — it is not an independent audit or certification.
Nothing is stored in this browser.
Masked in the interface
Key fields are password inputs and saved keys show only the first and last four characters, with an explicit reveal toggle.
Encrypted before it is written
Your passphrase derives an AES-256-GCM key (PBKDF2-SHA256, 250,000 iterations) in your browser. Only the ciphertext reaches local storage.
Never stored on our servers
The key is not saved to our database or your account. Testing a key forwards it once to the provider you chose and it is discarded after the response.
Never written to logs
Server and browser log paths run through a redaction layer that scrubs API-key and bearer-token patterns before anything is recorded.
Your passphrase is never stored or transmitted, so it cannot be recovered — if you lose it, remove the key and paste a new one. You can revoke a key here at any time; if you think it was exposed, also delete it in your provider's dashboard.
Your key is encrypted in this browser using AES-256-GCM before it is saved. The passphrase is something you make up to unlock it. The passphrase itself is never stored or sent anywhere — if you lose it, you'll need to paste the key again.