rubricaryalpha
ExploreValidatorDocsPricing
/
  • Authentication
  • Data we store
  • What the validator does with your text
Security

What the validator does with your text

The validator's job is to score a pasted prompt, not to keep a copy of it. For each submission:

  • The text is sent, for that one request, to whichever AI provider is currently configured to run the validator — Anthropic, OpenAI, or Google.
  • Rubricary does not retain the text afterward. It keeps a one-way hash of the trimmed text — used to detect a repeat submission and serve a cached score — and a hash of your IP address, used only to enforce the quotas below. Neither hash can be reversed back into the original text or address.
  • A scored result is cached under that hash for 24 hours, so an identical resubmission is answered instantly instead of calling a model again. The cache holds the score, not the prompt.
  • A local or preview deploy may answer from a simulated provider that calls no model and sends no data anywhere. That substitute is refused outright in production — the validator throws rather than serve a simulated score, so any result on the live site came from a real model.

The same request, wherever it comes from, is metered the same way:

  • A pasted prompt may be up to 12,000 characters; longer submissions are refused, not truncated.
  • An anonymous visitor gets 2 free validations before sign-in is required to continue.
  • Each IP address is capped at 10 model-backed validations per day, whether signed in or not.
  • A signed-in account is capped at 50 validations per day; the count resets at midnight UTC.

This applies identically to the validate_prompt tool on the MCP server — an agent goes through the same guard chain as a browser, not a way around it.

PreviousData we storeNextValidate a prompt
© 2026 rubricarydocsapipricingsecuritystatustermsprivacyv0.9.3 · 9e073c4All systems operational