Report vulnerabilities through GitHub private vulnerability reporting. Never attach private usage logs or commercial rate agreements to public issues.
The hosted app has connect-src 'none', no analytics, and no persistence. The CLI reads the two requested inputs and writes only an explicitly requested new file. Receipts contain identifiers, aggregates, rates metadata, and hashes but not prompts or model outputs.