sym is a code-reading service operated by s2ar (Cody Lee Walker, Canada). The hosted tier at api.s2ar.dev clones public git repositories you name, answers from them, and keeps the checkout for one hour. It never logs file contents, never trains on them, and never reads a private repository.
Paid calls are settled by Stripe (cards through Shared Payment Tokens, USDC through Tempo, and credit-pack checkouts), by an x402 facilitator (USDC on Base) when you pay from a wallet, and, for some credit packs, by Polar as merchant of record. Each sees only what its own flow requires (a payment credential, an amount, an email for the receipt). We keep a key hash, a balance and per-request usage counts; never a card number.
Only the image(s) in the request you send to the compression endpoint. starlens is a model, not a proxy into your conversation — it does not receive, store, or forward your prompts or your exchange with your downstream model.
One artifact: the sealed certificate for a request. It contains SHA-256 hashes of the input and output image, their pixel dimensions, and the measured witness drift — never the pixels themselves. Its purpose is re-verification: anyone can later confirm a certificate matches an image by hash. We also keep aggregate operational counters (request counts, bytes, latency) that contain no content.
Compression runs on servers we operate at Hivelocity (South Carolina, US). Traffic is encrypted in transit (TLS); access is authenticated by API key. We use no third-party analytics, trackers, or advertising. The compression engine is open source, so the data path is auditable end-to-end.
Because we retain no image content, there is nothing to export or delete on your behalf beyond the hash-only certificates. To ask about a certificate or request its deletion, email cody@s2ar.dev.
We'll post material changes here with a new effective date.