Key points
- Private, free, no ads. One person (the Operator) runs this workspace for the people they invite. We don't sell your personal information for money or share it for advertising, but some free AI providers may use your messages to improve their own products (section 6).
- What we keep. We keep your account, your chats (including AI replies), uploaded images, memories and settings. We also keep security records such as sign-ins, IP addresses, device type and approximate location.
- Admins can read and search chats while "Admins can read chats" is on, which is the default. Opening a chat, viewing its images and searching inside messages are logged. Workspace backups can include everyone's chats.
- Your messages go to outside AI companies. To answer you, your messages are sent to third-party AI providers on their free tiers: Groq, Google (Gemini API), and OpenRouter and the model hosts it uses. The messages go with your display name, recent chat history, instructions, memories and attachments. Google's free tier may use them to improve its products and let human reviewers read them. The exception is a model the Operator may run on their own computer ("Your own AI"): messages it answers are processed there, not by an outside AI company (section 6). Don't enter sensitive information.
- Support requests. When you report a problem, or tell the AI that something in FLUXBOT is broken, a support request goes to the admins. It includes your message and some details about what happened, such as your last message in that chat, the last error you saw and your device type (section 2.5).
- Admins stay anonymous to you. Messages and replies from admins appear as "FLUXBOT" or as "Admin 001", "Admin 002" and so on, never with a real name. Admins can change or delete things in your account without telling you. Those changes are recorded in the activity log (section 4).
- Hosting. Data is stored with Netlify in the United States. The Service is set up to encrypt the contents, and Netlify encrypts stored data too. Traffic passes through Cloudflare.
- Cookies. There is one strictly necessary sign-in cookie. There is no analytics, advertising or tracking.
- Adults only. The Service is for people aged 18 or older.
- Your choices. You can delete your own chats, memories and signed-in devices, and turn memory off. You can ask the Operator for a copy of your information or to delete your account.
- Automatic deletion. Automatic records are deleted after 90, 180 or 365 days depending on the type, and closed support requests after a year. No system is perfectly secure.
This summary is here to help you. The full policy below gives the details.
1 Who we are and what this covers
This Privacy Policy explains how the person who operates this workspace (the "Operator", "we", "us" or "our") collects, uses, shares and protects information about people who use FLUXBOT. FLUXBOT is the private, invite-only AI chat workspace at fluxbot.cc and cardinalgo.org, together with any backup address that runs the same workspace (the "Service"). Every address uses the same accounts and data.
The Operator is a private individual, or that person's small business, who owns the workspace and runs the Service for themselves and for people they invite. It is free and it is not a company product. The Operator decides how your information is used; in data protection terms, the Operator is the "controller".
The Operator can give other people the Admin role to help run the workspace. Admins can see the information described in section 4, and admins agree in the Terms to use it only to help run the workspace and to keep it confidential.
This policy doesn't cover the outside companies the Service uses. They have their own privacy policies (see sections 5 and 6).
This policy is a notice about our practices. It is not a contract and does not create contractual rights or obligations. Your use of the Service is governed by our Terms of Use.
2 Information we collect
2.1 Account information
- Your username, display name and role (Admin, Inviter or Member). Your display name (or your username, if you haven't set one) is sent to the AI with every message, so consider using a first name or nickname.
- Your password is stored only as a salted scrypt hash, never in plain text, and admins can't look it up in the app. Admins never see a password you choose. If an admin creates your account or resets your password, they see the temporary password they set; the app will usually ask you to choose your own the next time you sign in, and if it doesn't, change it yourself. Like any website, your password passes through our hosting and network providers when you sign in.
- When your account was created and who invited you.
- Settings admins control for your account: your daily message limit, your assigned AI model and whether your account is paused.
- Which version of the Terms and Privacy Policy you accepted, and when. The Operator can turn this acceptance step on or off; while it is off, nobody is asked to tick a box.
- If you create invite links: the note you add, when each link expires, and who joined through it and when.
2.2 Your chats and content
- Chats:
- chat titles and your messages;
- the AI's replies, including any "reasoning" text the model returns;
- which model answered.
- Organization: 👍/👎 votes, pins, folders and share links.
- Uploads: images you attach (up to 4 MB each) are stored with their file name, type, size and upload time. Documents are read in your browser; only their file name, size and extracted text are stored, inside the chat message. The original document file is not uploaded.
- Memories: short facts you ask the Service to remember, and any an admin adds to your account (see section 4). They are added to the instructions of every chat. A message that starts with words like "remember that…" or "don't forget…" is saved as a memory automatically. You can turn memory off in Settings, which stops saving memories and sending them to the AI.
- Settings: custom instructions, theme, voice choice and similar preferences.
2.3 Voice
- Speaking a message. When you use voice input, your recording is sent to Groq to be turned into text. The Service does not store the recording; the resulting text becomes part of your message. Your browser asks for microphone permission, and the microphone is used only when you start voice input.
- Read-aloud. Reply text is either sent to Groq to create speech or read by your browser's built-in voice. Some built-in voices are processed online by your browser or operating system maker, under their own policies.
2.4 Security and usage records (collected automatically)
- Activity log and sign-in history. Each entry has the time, the action (such as signing in, changing a password, an admin opening a chat or an admin changing something in your account), who did it (and to whom) and the IP address. Sign-in entries also record the device type (for example "Chrome on Windows") and approximate location (city, region or country), which comes from the location headers Netlify and Cloudflare add based on your IP address. Some entries include a chat's title (when it's shared or opened by an admin) or the words an admin searched for.
- Failed sign-in attempts, with similar details, plus short-lived rate-limit and lockout counters.
- Signed-in devices: device type, approximate place, IP address, and when each was first and last seen. We also keep your last-seen time.
- Daily message counts per person and per model, including voice use.
- Workspace statistics: message counts per person, model and mode per day.
- Reply feedback: your vote, any comment you add, and a 300-character snippet of the reply.
- Content-filter records. If an admin turns the filter on and it blocks or flags one of your messages, we keep your name, which chat it was in, the matched words, whether it was blocked or flagged, and the first 400 characters of your latest message.
- Notifications admins send you, including replies to your support requests, and whether you've read them. Admins also keep a list of the last 50 notifications sent, with their text and recipients.
2.5 Support requests and problem reports
When you ask for help or report a problem, for example with the Report a problem button, the Service stores a support request (a "ticket") with:
- your message, and the kind of request (bug, question, feedback or other);
- your username and display name, and when you sent it;
- whether it came from the button or from a chat, and which chat, if any;
- the page you were on and the last error message the app showed you, if there was one;
- what you said: for a report filed from a chat, your last message in that chat (up to 1,000 characters);
- your device type (for example "Chrome on Windows"), worked out from your browser's user agent;
- its status (open, being worked on or closed) and any replies.
Reports the AI files for you. While chat reports are turned on (the default), the AI is told that if you say something in FLUXBOT itself is broken, or ask to reach the team, it should end its reply with a one-sentence summary of the problem. The app then sends that summary to the admins as a ticket, together with your last message, the chat it came from and the last error shown, and a note under the reply tells you it was sent. The AI decides when to do this, so it may file a report you didn't mean to send, or miss one you wanted; you can ask an admin to delete a ticket. Admins can turn chat reports off.
Who sees tickets.
- All admins can read every ticket, including any message quoted from your chat, even while "Admins can read chats" is off.
- Admins get a notification with your display name and the start of your message, and the activity log records the first 80 characters of it.
- Replies reach you in your 🔔 notifications. They are signed "FLUXBOT Support" or "Admin 001" and so on, never with an admin's real name.
- You can see your own tickets and the replies to them.
Email. If you email the Operator, for example at the support address shown in the app or the contact address in section 16, the Operator receives your email address, your message and any attachments through the Operator's email provider. Those emails are kept in the Operator's mailbox, outside the Service.
2.6 Information our providers receive when you connect
- Netlify and Cloudflare process your IP address, browser user agent, the addresses you request and other technical request data, so they can deliver and protect the Service.
- Google Fonts receives your IP address and user agent when your browser loads fonts from it. All other code is served from this site itself, except Cloudflare's Turnstile script, which the sign-in page loads from Cloudflare only if the Operator turns Turnstile on.
- Cloudflare Turnstile. If the Operator turns on Turnstile bot protection, Cloudflare checks signals from your browser to tell people from bots, and the Service sends Cloudflare your IP address with the check.
2.7 What we don't collect
- Payment details.
- Analytics, advertising identifiers or tracking pixels.
- Precise (GPS) location.
- Your contacts, or your email address unless you email the Operator.
- Information about you from data brokers or other websites.
If other people mention you in their chats, that information is stored in their chats and handled as their content.
3 How we use it, and why
| Purpose | Information used | Why we're allowed to |
|---|---|---|
| Provide the Service | Account details, chats, uploads, memories, settings, voice recordings (passed straight to Groq) | Needed to give you the service you signed up for. This covers creating your account, signing you in, storing and showing your chats, getting AI answers, voice and share links. |
| Keep it secure and stop abuse | Security records, IP addresses, device type, approximate location, failed sign-ins, content-filter records | Our legitimate interest in protecting you, other users and the Service. This covers rate limits and lockouts, bot checks, spotting suspicious sign-ins and enforcing the Terms. Sometimes the law also requires it. |
| Run the workspace | Usage counts, statistics, reply feedback, storage used, notifications, invite links | Our legitimate interest in running a small shared workspace fairly and within its free limits. This covers daily limits, assigning models, choosing better models and sending notices. |
| Answer support requests and fix problems | Support tickets and the details in section 2.5, emails you send the Operator | Needed to answer what you asked for, and our legitimate interest in finding and fixing problems and improving the Service. Reports the AI files from a chat rely on that legitimate interest; admins can turn them off. |
| Admin oversight | Chats, including searches inside messages, and your memories and settings (while "Admins can read chats" is on); content-filter records; activity log | Our legitimate interest in supervising how the workspace is used and enforcing its rules, and your consent in the Terms. You are told about this before you sign up and throughout the app. |
| Legal and safety | Any information, only as needed | To comply with the law and with valid legal requests, and to protect people's rights and safety. |
| Optional features | Microphone audio when you choose voice input | Your consent. You give it when you allow microphone access, and you can withdraw it at any time in your browser settings. |
We don't use your information for advertising or profiling, or for automated decisions that have legal or similarly significant effects on you. The Operator does not train AI models on your content. Section 6 explains what the AI providers themselves may do.
4 What admins can see and do
- Chats. While the workspace setting "Admins can read chats" is on (the default), admins can:
- see a list of everyone's chats and their titles;
- open and read any chat, read-only, including AI replies and uploaded images;
- search for words inside the messages of everyone's recent chats, and see short excerpts around the matches.
- People and security. Admins can see:
- names and usernames, and roles;
- last-seen times and usage counts;
- signed-in devices, IP addresses and approximate locations;
- sign-in history;
- reply feedback and content-filter records;
- support requests (section 2.5), whatever the "Admins can read chats" setting;
- invite links and who joined through them;
- storage used.
- Actions. Admins can:
- pause, sign out, reset or remove accounts, and change names, roles, limits and models;
- answer, close and delete support requests;
- send notifications;
- turn features off, or put the workspace in lockdown;
- sign everyone out;
- set the content filter and "safe mode";
- give the AI workspace-wide instructions and modes;
- delete old or unused images to free up storage.
- Account tools. Admins can manage what is inside other people's accounts (only the Operator can change the Operator's own account). They can:
- rename or delete your chats (deleting a chat also removes its images and share link);
- delete your uploaded images;
- view, add or delete your memories;
- view or reset your settings, including your custom instructions;
- clear your notifications and reset your message count for the day;
- set a new password for you;
- wipe everything in your account while keeping the account itself;
- download a copy of everything in your account (account details, chats, memories, settings, devices, notifications and a list of your uploads).
- How admins appear to you. You are never told the name of the admin who did something.
- Notifications and support replies from the Operator appear as "FLUXBOT" or "FLUXBOT Support", and so do automatic notices such as a support request being closed. Notifications and replies from other admins appear under a number, such as "Admin 001" or "Admin 002".
- Most changes admins make to your account, such as the account tools above (other than password changes) and changes to your role, limit or model, are not announced to you. If an admin other than the Operator resets or sets your password, you get a notification from their "Admin" number. When the Operator does it, you are not notified.
- Changes admins make to your account are recorded in the activity log (kept 90 days) under the admin's real username, which the Operator and other admins can see.
- Backups. Only the Operator (the workspace owner account) can download or restore a full backup of the workspace.
- While "Admins can read chats" is on, a backup includes everyone's chats, memories and settings, and optionally uploaded images. While it is off, chats, memories, settings and images are left out.
- Backups always include accounts (with password hashes, never passwords), invite links, share links, notifications, support requests, reply feedback, content-filter records, statistics, workspace settings, failed sign-in records and the activity log (with IP addresses).
- Optionally, a backup can include the workspace's AI provider API keys.
- Backups don't include device lists, daily usage counts or last-seen times.
- The Operator. The Operator runs the storage and holds the encryption key, so the Operator could technically access stored data even when chat viewing is off. For example, this could happen during maintenance, restoring a backup, investigating abuse or responding to a legal requirement.
5 Who receives your information
5.1 Service providers
These companies process information so the Service can work. They follow their own terms and privacy policies.
| Company | What it does | What it receives |
|---|---|---|
| Netlify, Inc. (US) | Hosts the website, runs the server code and stores the database (Netlify Blobs) |
|
| Cloudflare, Inc. (US, global network) | Domain name service, network proxy, HTTPS, attack and bot protection, and optional Turnstile check at sign-in |
|
| Groq, Inc. (US) | AI answers from open models such as GPT-OSS and Qwen, speech-to-text (Whisper) and read-aloud voices (Orpheus) |
|
| Google LLC: Gemini API (US) | AI answers from Gemini and Gemma models (free tier) |
|
| OpenRouter, Inc. (US) and upstream model hosts | Routes requests to many AI model hosts. The Service uses only its free (":free") models. |
|
| The Operator's own computer ("Your own AI"), if connected | Runs an AI model on a computer the Operator controls. It appears in the model menu under the name the Operator gives it, such as "My PC". |
|
| The Operator's email provider | Delivers and stores email sent to the support and contact addresses |
|
| Google Fonts (Google LLC) | Supplies the web fonts the pages use, such as Inter, Orbitron and Exo 2 |
|
5.2 Other people in the workspace
- Admins can see what section 4 describes, including your support requests.
- If you create a share link for a chat, signed-in members who open it see that chat and your display name, until you turn the link off.
- If you create an invite link, anyone who opens it sees your display name and any note you add.
5.3 Legal reasons and safety
We may disclose information if we believe in good faith that it is needed for one of these reasons:
- to comply with a law, subpoena, court order or other legal process;
- to enforce our Terms;
- to detect or stop fraud, abuse or security problems;
- to protect the rights, property or safety of the Operator, users or others.
Apparent child sexual exploitation will be reported to the National Center for Missing & Exploited Children.
5.4 If the workspace changes hands
The Operator may hand the workspace over to another person or organization, or may become unable to run it. In that case, the information may pass to whoever takes over. We will ask them to keep following this policy for existing information, or to tell you about any changes and ask you to accept them.
5.5 With your permission
We may share information in other ways when you ask us to or agree to it. Other than as described in this policy, we don't give your information to anyone else.
6 What AI providers do with your messages
What is sent. Each time you send a message, the chosen AI provider receives all of the following:
- your message;
- recent chat history;
- your display name (or your username if you didn't set one);
- the system instructions: the workspace name, today's date, the workspace instructions admins set, the selected mode, the safe-mode instruction if it is on, the instruction for filing problem reports (with the support address) while chat reports are on, and your custom instructions;
- your saved memories, unless you turned memory off;
- any attached document text and images.
If "auto-switch" is on and the first provider fails, the same content is sent to backup providers, which may include a provider you didn't choose. One message can therefore reach more than one provider.
Your own AI. The Operator may connect an AI model that runs on their own computer. It shows up in the model menu under the name the Operator gives it, such as "My PC", and auto-switch can use it as a backup. A message answered by that model is processed on that computer, not by an outside AI company. It gets there through an encrypted tunnel, usually Cloudflare Tunnel. The bridge software that links the computer to the Service doesn't save messages, but the Operator controls that computer and the AI software on it, which may keep its own logs.
The summaries below come from each provider's own pages as checked on September 24, 2026. Providers can change their terms at any time, and the Operator does not control them.
- Groq
-
- Retention. Groq says it does not keep inputs or outputs by default. It may log them temporarily, for up to 30 days, to fix reliability problems or investigate suspected abuse. Data it keeps is stored in Google Cloud in the United States.
- Training. Groq's Services Agreement says it won't use inputs or outputs to train models without the customer's permission.
- Zero Data Retention. Groq offers this as an account setting.
- Google (Gemini API, free tier)
-
- Product improvement. Google's terms say that for unpaid services it uses the content submitted and the responses generated to provide, improve and develop its products and machine-learning technologies.
- Human review. Human reviewers may read, annotate and process inputs and outputs, after Google disconnects them from the account.
- Sensitive information. Google tells developers not to send sensitive, confidential or personal information to its unpaid services.
- Retention. Google also keeps prompts and outputs for 55 days to detect misuse. It states no retention period for data used to improve products.
- OpenRouter and its upstream hosts
-
- OpenRouter itself. It says it doesn't store prompts or responses unless the account owner opts in to logging, and doesn't use them for training. It does keep request metadata such as token counts and timing.
- Upstream hosts. OpenRouter passes requests to the host that runs the chosen model. For some free models, the host logs prompts and responses or uses them to train its models. Policies differ by model and change over time.
- Settings. OpenRouter account settings can exclude hosts that may train on data. Even so, assume that a free model's host may keep your messages.
What this means for you
Don't put health, financial, ID, password or other sensitive details in chats, memories or uploads, and don't include other people's personal information. Treat anything you send as something an outside company may keep and review.
7 No selling for money, no ads
- No selling for money, no ads. We don't sell your personal information for money and we don't share it for targeted advertising. Be aware: some AI providers we use on their free tiers, namely Google's Gemini API and some model hosts reached through OpenRouter's free models, may use what they receive to improve their own products as a condition of offering the service for free (see section 6). Some privacy laws could treat that as a "sale" or "sharing" of personal information. Choosing other models reduces this, but because of auto-switch it may not avoid it completely; it stops only if the Operator turns those providers off for the whole workspace or moves to their paid tiers. You can ask the Operator to do that.
- No ads or data brokers. There are no ads, no targeted advertising and no data brokers.
- Sensitive personal information. We use it only to provide the Service. For example, your username and password are used to sign you in. We don't use it to infer characteristics about you.
8 How long we keep information
| Information | How long it's kept |
|---|---|
| Chats, uploaded images, memories, settings | Until you delete them, your account is removed, or the Operator deletes them under the Terms (for example for inactivity, storage limits or shutting the Service down). Admins may also delete old or unused images to free up space. |
| Account record, including which Terms version you accepted and when | Until your account is removed. Each acceptance is also recorded in the activity log (90 days). |
| Last-seen time | Until your account is removed |
| Share links | Until you turn them off, delete the chat, or the account is removed |
| Invite links, including who joined through them | Until the link expires or is revoked, or the account that created it is removed |
| Support requests (tickets), including replies | Until an admin deletes them. Closed tickets are deleted automatically 1 year after they were last updated. All of your tickets are deleted when your account is removed. |
| Emails you send the Operator | In the Operator's mailbox, outside the Service, until the Operator deletes them |
| Notifications from admins | Until you clear them, until 50 newer ones replace them, or until the account is removed. Admins also keep a list of the last 50 notifications sent. |
| Signed-in devices list | Until you sign a device out, newer devices replace it, or the account is removed |
| Sign-in cookie | Up to 30 days, or until you sign out (signing out also ends the session on the server) |
| Activity log, including sign-in history and admin chat views and searches | 90 days |
| Failed sign-in records | 90 days |
| Content-filter records | 90 days |
| Daily message and voice counts | 90 days |
| Reply feedback | 180 days |
| Workspace statistics | 365 days |
| Rate-limit and lockout counters | About 2 days after the last attempt (active lockouts are kept until they end) |
| Voice recordings | Not stored by the Service |
| Backups downloaded by the Operator | As long as the Operator keeps the file. This is outside the Service's control. |
| Copies held by AI providers, Netlify and Cloudflare | Under their own policies (see section 6) |
- When clean-up runs. Automatic deletion runs when an admin opens the admin console, at most once a day. If no admin opens it for a while, records stay until the next time one does.
- Removing an account deletes that person's chats, uploads, memories, settings, notifications, devices, daily counts, last-seen time, share links, support requests and the invite links they created. Entries about the person in the activity log, feedback, content-filter records and statistics are deleted when their own retention periods end.
- Restoring a backup. If the Operator restores a backup made before you deleted something, that data may come back. Tell the Operator and ask for it to be deleted again.
- Copies of one account. A copy of your account that an admin downloads (section 4) is kept on their device for as long as they keep it, outside the Service's control.
- Caches. Deleted data may stay for a short time in provider caches.
- Longer holds. We may keep information longer where the law requires it, or to resolve disputes or investigate abuse.
9 How we protect information
- Encrypted connections. HTTPS only, with HSTS.
- Passwords. They are hashed with salted scrypt and never stored in plain text.
- Stored data. The Service is set up to encrypt the contents of the records and uploaded images it stores with AES-256-GCM before saving them, using a key kept in the server's settings and never sent to browsers. Some technical details, such as record names that include usernames and dates, and basic file details such as size and type, are not encrypted. Netlify also encrypts stored data at rest.
- Sign-in sessions.
- On the live HTTPS site, the sign-in cookie is signed, HttpOnly, Secure and SameSite=Strict.
- Signing out ends the session on the server.
- You can see your devices and sign them out, and admins can sign everyone out.
- Protection against guessing and bots. Sign-in has rate limits and lockouts. Bot protection uses a hidden trap field, timing checks and optional Cloudflare Turnstile.
- Access checks. The Service is designed to check permissions on the server for every request, so that people can reach only their own records and chats shared with them, and only admins can use admin tools.
- Input checks. Input is validated, and only allowed fields are accepted.
- Security headers. Strict headers include a Content-Security-Policy and blocking of framing by other sites.
- API keys. AI provider API keys, and the key for the Operator's own AI, are kept on the server, encrypted, and are never shown in full in the app (admins see only the last four characters). Only the Operator can change them. They leave the server only if the Operator downloads a full backup and chooses to include them.
- Your own AI. The bridge on the Operator's computer only listens on that computer, accepts requests only with its secret key, and lets through only model lists and chat replies.
- Logging. Sign-ins and sensitive admin actions are logged.
No guarantee. No website, app or storage system is completely secure. We can't guarantee that information won't be accessed, disclosed, changed or destroyed, including at third-party providers.
Your part. Use a strong password you don't use elsewhere, sign out on shared devices, and tell an admin if something looks wrong.
If there is a breach. If we learn of a security breach that affects your personal information, we will notify you when and as the law requires. Because the Service usually doesn't have your email address, notice may be given in the app, on the sign-in page, or in another way the law allows.
10 Your choices and rights
10.1 Things you can do yourself in the app
- View and delete your chats.
- Delete saved memories, or turn memory off in Settings.
- Change your settings and custom instructions.
- Turn off share links.
- See your signed-in devices and sign them out.
- Clear notifications.
- See your support requests and the replies to them.
- Change your password.
- Choose not to use voice features.
- Clear this site's data in your browser to remove local preferences.
10.2 Requests to the Operator
You can ask the Operator to:
- give you access to, or a copy of, your personal information;
- correct it;
- delete your account and its data, or a support request;
- explain how it is used.
Contact the Operator (see section 16).
- Verification. We'll verify your request, usually by asking you to confirm it from your signed-in account.
- Timing. We'll try to respond within 45 days.
- Authorized agents. An agent can make a request for you with proof of authorization.
- When we can't comply. We may decline where the law allows. Examples: we can't verify you, the request would reveal someone else's information, or we must keep the information. Deleting data can't reach backup files the Operator has already downloaded, or copies AI providers hold under their own policies. Where practical, we'll tell you about any such limits.
- Appeals. If we decline, you can ask us to reconsider. If you're still unhappy, you can contact your state attorney general.
- No penalty. We won't treat you differently for using these rights.
10.3 California and other US states
Many state privacy laws, such as California's CCPA/CPRA, apply only to businesses that meet certain thresholds. A free, non-commercial workspace run by an individual may not be covered. We offer the choices above to everyone anyway.
In the last 12 months we collected these categories of information, from you, your device, admins and our hosting providers (for approximate location), for the purposes in section 3:
- identifiers (username, display name, IP address);
- account login credentials (username and a hashed password);
- internet or other electronic network activity (activity log, device type, usage counts);
- approximate geolocation (city, region, country);
- audio (voice recordings, passed to Groq and not stored);
- the content of your messages, uploads and support requests, which may include personal information you choose to enter.
We disclosed these categories to the service providers and AI providers listed in section 5. As section 7 explains, some free-tier AI providers may use what they receive for their own purposes.
10.4 If you are in the EEA, the UK or Switzerland
The Service is meant for people in the United States and is not offered to people in the European Economic Area, the United Kingdom or Switzerland. One reason is that Google's Gemini API terms allow only paid services to be offered to users there, and the Service uses Google's free tier.
If you use the Service from there anyway, data protection law gives you these rights:
- to access, correct or erase your data;
- to restrict how it is used, or to object, including to use based on legitimate interests;
- to receive your data in a portable form;
- to withdraw consent;
- to complain to your local data protection authority.
Contact the Operator to use them. The Operator has not appointed a representative in the EU or the UK.
11 Children and minors
- Adults only. The Service is for people aged 18 or older. It is not directed to children or teens, and we don't knowingly collect information from anyone under that age. If we learn that an account belongs to someone under the minimum age, we will delete the account and the data the Service stores about it. We can't delete copies already sent to AI providers.
- Google's age rule. Google's terms don't allow its free API to be used by anyone under 18, or in services likely to be used by people under 18. This is one reason the Service is for adults only.
- Parents and guardians. If you believe someone under the minimum age has an account, please contact the Operator.
12 Where information is stored
The Service is run from the United States:
- Netlify stores the database in a single US region (US East by default) and runs the server code in the US.
- Cloudflare handles traffic at a location in its global network, usually one near you.
- Groq stores any data it keeps in the US.
- Google, OpenRouter and the model hosts it uses may process data in the US and in other countries.
- The Operator's own computer, if the Operator connects their own AI, processes messages wherever that computer is.
By using the Service, you understand that your information is transferred to and processed in the United States, where data protection laws may differ from those where you live.
14 Do Not Track and Global Privacy Control
Do Not Track. We don't track you across other websites or show ads, so Do Not Track signals don't change anything.
Global Privacy Control. The Service doesn't act on Global Privacy Control signals automatically. We don't sell personal information for money; see section 7 for how some free-tier AI providers may use your messages, and how to avoid it.
15 Changes to this policy
- Updates. We may update this policy. The version number and effective date are shown at the top of this page.
- Accepting a new version. The Operator can turn acceptance in the app on or off. While it is on and the version changes, the app asks you to review and accept the new version before you can keep using the Service, and records which version you accepted and when. While it is off, the new version applies from its effective date.
- Small fixes. Typo or formatting fixes that don't change what we do may be made without a new version.
- Earlier versions. The Operator keeps copies of earlier versions. Ask the Operator if you need one.
16 Contact
- Operator
- the person who operates this workspace
- Contact address
- [email protected]
To make a privacy request or ask a question, contact the Operator at the address above. For help with the app itself, you can also use Report a problem in the app.