Privacy defaults
tos.wtf is built to read a document you already have, not to harvest it. There are no accounts. There is no silent training on pastes.
What we hold
When you analyze a document, the Worker keeps an ephemeral session: normalized text, SHA-256 hash, structured findings, and questions you ask in that session. Default lifetime is about 2 hours, then a Durable Object alarm deletes it.
Raw text is not written to R2 unless an operator sets STORE_RAW_IN_R2=true. Even then it is keyed by hash, not by you, and it is not a training corpus.
Opt-in training log
If — and only if — you tick the consent box, we may store {doc_hash, findings, question, answer, citations, feedback} in D1 for a future fine-tune. The full document body is omitted on purpose. Unticked means no such row is written.
Model provider
With an OpenCode Go API key configured, the document text is sent to OpenCode Zen Go (https://opencode.ai/zen/go/v1) to fill a fixed JSON schema. Default model is DeepSeek V4.1 Flash on Go (deepseek-v4.1-flash). Go’s processing follows OpenCode’s terms. Without a key, analysis stays on the Worker as a heuristic mock and nothing leaves the isolate for inference.
Not legal advice
Highlights and answers are a reading aid. They can be wrong. They are not a lawyer, not your lawyer, and not a substitute for one.