Privacy policy

Effective October 4, 2026. Topname.ai is operated by Edamame Labs.

What we collect

We use your email for one-time-code login and account identification. Signed-in chats and saved domains are stored in our database so you can access them across devices. Guest chats and saved domains stay in browser storage. When you first sign in, existing browser searches and saved domains are imported into that account.

We use hashed account or network identifiers and request counters to prevent abuse. Operational records contain error categories, request IDs, timestamps and duration; we do not intentionally include your email, prompt, verification code or credentials in these error records. Our hosting provider may separately keep request and network logs. Feedback includes your message and, when signed in, your email.

How we use and share data

Your description and relevant conversation context are sent to OpenRouter and the selected AI provider to generate names. Proposed domains are sent through Modal to Namecheap to check registration availability. Vercel hosts the website, Neon stores account data, and Resend delivers login codes. These providers process data under their own policies; provider retention practices can differ. Avoid including confidential or sensitive personal information in a naming request.

We do not sell your personal information. Registration links send you to a third-party registrar, whose privacy policy applies there. Some links may earn us a commission.

Storage and your choices

Signed-in chats and saved domains remain until you remove them or request account-data deletion. Unsaving a domain removes its content from account storage; a version marker remains to prevent another device from restoring it. Browser backups may retain unsynced or conflicting changes until you clear this site’s browser data. Clearing browser data removes guest history and local backups.

Login codes expire after 10 minutes and sessions expire after 30 days. Rate-limit counters expire within their quota window and are cleaned up during later searches. We remove operational event records older than 30 days when recording new events. Feedback is kept while needed to handle the request. Infrastructure backups may retain deleted data for the provider’s backup period.

To request access, correction, or deletion of account data, sign in and submit a privacy request. You can also use that form for privacy questions. We will verify ownership before taking action.

Cookies and security

We use essential, secure HTTP-only cookies for login and browser storage for searches, bookmarks and recovery copies. Account data is accessed through authenticated server endpoints. No system can guarantee absolute security.

Changes

We may update this policy as the Beta evolves. The effective date above identifies the current version.