Where your key goes, and where it does not.
Tellstone asks you to paste an API key into a web page. You should not do that on trust. This page says exactly what happens to it, and how to check for yourself that it is true.
§1The short version
- Tellstone is a set of files that run in your browser. There is no Tellstone server that your key, your prompts or your results pass through.
- Your key is sent to the endpoint you typed in, as the password of each request, and to nobody else.
- Nothing is stored: no cookies, no local storage, no account, no analytics, no tracking pixels, no third-party scripts or fonts.
§2Your key, step by step
- When you type it
- It sits in the form field, in this tab's memory.
- When a check runs
- Your browser sends it in the
Authorizationheader (orx-api-keyfor the Anthropic format) of requests that go straight to the base URL you entered. That is the only place it is sent. - When the check ends
- It is still only in the form field. It is not written to cookies, local storage, the address bar or anywhere on disk.
- When you copy or share a result
- The result holds base URLs, model ids and the report. The key is left out.
- When you close the tab
- It is gone.
Your browser may offer to save what you typed in a password field. That offer comes from your browser, and the choice is yours.
§3Who sees what
| Who | What they see |
|---|---|
| The endpoints you enter | Your key for that endpoint, the questions or attacks sent to it, your IP address. Whatever they do with requests is governed by their own policy. |
| The host that serves this site | What any web host sees when a page loads: your IP address, your browser type, which page was asked for. Never the key, and never the result. |
| Whoever you send a share link to | The base URLs, model ids and report inside it. The result travels after the # of the link, a part browsers do not send to servers. |
| Tellstone | Nothing. We do not receive your key, your endpoints, your system prompt or your results. |
§4Page by page
- Check. Sends the eight questions to the two endpoints you name. Nothing else leaves the page.
- Arena. Sends your system prompt, with one secret line added, and the attacks to the one endpoint you name. The system prompt is not stored and is not put in the copied result.
- Atlas. Loads our own collected answers from this site. If you place your own endpoint on the map, it is asked the eight questions from your browser, the same way as a check. When a live feed is connected, the map also listens to that feed for new answers.
- The demos. Run against pretend gateways inside the page. Nothing is sent anywhere.
§5Check it yourself
- Watch the traffic. Open your browser's developer tools, go to the Network tab, and run a check. You will see requests to the endpoints you entered and to nothing else.
- Read the code. The pages are plain, unminified JavaScript. The part that sends requests is one short file,
core/client.js. - See the lock. Every page carries a content security policy that forbids scripts from any other site. Even if we wanted to load a tracker, the browser would refuse.
§6If you would rather not trust any of this
- Run the demo first. It needs no key.
- Make a new key just for this, give it a small spending limit if your provider allows one, and delete it when you are done.
- Never paste a key that can do more than call models, such as one that can manage billing.
§7Our own data
The answers shown in the findings and the atlas were collected by us from model providers. They are replies to questions like "name a random animal". They contain no personal data.