What we do
Offer anonymous use; keep memory off by default; encrypt data in transit and at rest with configured providers; isolate user records; redact operational logs; and send only aggregate, content-free product events to general analytics.
What we do not do
We do not sell private chat data, target advertising with conversation content, silently train on conversations, or include journal entries in model context without explicit user action.
Your controls
Delete individual conversations, inspect and erase memory, export account data, or permanently delete the account. Identity verification protects export and deletion actions from abuse.
Retention
Anonymous question content is ephemeral in the default design. Authenticated history follows the user’s history setting. Safety and abuse-prevention events retain the minimum classified metadata; reported excerpts are retained only for review and audit. Exact periods are configurable and documented before launch.
Vendors and access
Production data flows are inventoried across hosting, database/authentication, AI, Stripe, email, analytics, and error monitoring. Administrative access is least-privilege and audited. No admin screen enables casual browsing of private conversations.