Privacy Policy

Last updated: May 2026

mini-on-ai sells digital products (Claude Code skills, prompt packs) and operates F1, a BYOK proxy for the Anthropic API. This page explains exactly what we collect, why, who sees it, and what you can do about it. Plain English — no dark patterns.

The short version: We collect the minimum to run the business — your email if you sign up for the newsletter or buy a product, payment info via Stripe (which we never see in full), and for F1 only: API usage metadata (token counts, USD cost, status) and your encrypted Anthropic key. We never store your prompts or responses. We never sell or share your data.

If you sign up for the newsletter

We collect: your email address.

We use it to: send the weekly "One AI Workflow a Week" email (one per Friday).

Where it's stored: Brevo (EU-based). You can unsubscribe with one click from any email.

We never share newsletter addresses with anyone, including affiliates.

If you buy a product on Gumroad

Gumroad handles the entire checkout, payment, and delivery flow. We see only: the order ID, product, price, your email, and your country. We never see card details.

For F1 subscriptions purchased via Stripe: same principle. Stripe handles the card; we see the customer email and subscription tier.

If you use F1 (BYOK Anthropic proxy)

F1 has its own dedicated security page that goes deeper: /f1/security. Summary of what we store:

We never store the body of any request or response. This is a hard policy enforced at the code level; the Worker source is MIT-licensed and public at github.com/mini-on-ai/f1.

Who sees your data (subprocessors)

No analytics SDKs, no tracking pixels, no ad networks. The only third-party JavaScript on the site is Cloudflare Web Analytics (privacy-preserving, no cookies). Full subprocessor list with data-sharing details: /f1/security#subprocessors.

Cookies

The site itself sets no cookies. The dashboard and product pages use localStorage only to remember your dark-mode preference. Cloudflare may set a session cookie for bot detection — that's at the infrastructure layer and we have no access to it.

How long we keep things

Your rights

You can, at any time:

To exercise any of these, email hello@mini-on-ai.com. We respond within 7 days.

About the brand

mini-on-ai is operated by an anonymous solo founder. We acknowledge this creates a trust asymmetry for a product that handles credentials. Our mitigation: the F1 Worker source is MIT-licensed and public, encryption is verifiable in the code, and our subprocessors (Cloudflare, Stripe, Brevo, Anthropic) are all recognizable infrastructure providers you can evaluate independently. See /f1/security for the full reasoning.

Changes to this policy

If we make material changes, we'll update the "Last updated" date at the top and email anyone whose data is materially affected. The full revision history is in the git log of our public site repo.

Contact

Privacy questions: hello@mini-on-ai.com
Security disclosures: security@mini-on-ai.com (see also /.well-known/security.txt)