Privacy Policy

How your data is handled

What we store, why, and the optional extra protection you can turn on for your conversations.

This page explains what account and conversation data AI Chat Console collects, why, how it's used to provide the service, who it's shared with, how long it's kept, and the privacy controls available to you — including the optional chat encryption at rest feature described in detail below. This is a general-purpose policy covering the platform as a whole, not just encryption.

Last updated: September 29, 2026.

Jump to: Information we collect · How we use it · Chat encryption · Third-party AI providers · Payments · Retention & deletion · Security · Your rights · Sensitive information & Modules · Controlling what the AI remembers · Browser extension · Children's privacy · Changes

Information we collect

Account information

Conversation data

Usage, billing & technical data

API keys (BYOK)

If your plan allows "bring your own key" and you choose to add your own provider API key, it is encrypted at rest (AES-256) using the same key-management approach described below, independent of whether you've turned on chat encryption.

How we use your information

🔒 Chat encryption at rest

In Preferences → Privacy, you can turn on "Encrypt my chats". It is off by default — nothing changes for your account unless you explicitly enable it.

What it does

When enabled, your message content, chat titles, and image/video/audio generation prompts are encrypted (AES-256) before being stored in the database. If someone were to gain unauthorized access to a database backup or export — a stolen backup file, a leaked SQL dump, a compromised low-privilege database credential — your conversations would appear as unreadable ciphertext rather than plain text.

What it does not do

This is server-side encryption, not end-to-end encryption. AI Chat Console's own servers still process your messages in readable form while handling your request — that's how we're able to send them to the AI model and generate a reply. This feature protects against a stolen database copy; it does not hide messages from the operator of this service.

What you gain in exchange

Turning it on or off

Enabling it converts your existing chat history in the background (a progress bar shows how far along it is — safe to close the page and come back, it resumes automatically). Disabling it reverses the process and search comes back once decryption finishes.

⚠️ Software limits of this encryption feature

The technical constraints below apply regardless of your own setting, so you know exactly what "encrypted" does and doesn't mean here.

Third-party AI providers & Zero Data Retention

To generate a response, your message is sent to the AI provider/model you selected (OpenAI, Anthropic, Google Gemini, xAI/Grok, Cloudflare Workers AI, Mistral, DeepSeek, Pruna AI, OpenRouter, or others depending on what's configured on this instance). Each provider processes your request under its own data-handling and retention terms, which are outside our control — please review the provider's own policy if you have concerns about a specific model.

Some background features — auto-titling, rolling context summaries, auto-memory extraction, search-query rewriting, prompt enhancement and Draw-mode follow-up detection — are not always sent to the same provider/model you picked for your reply. The site administrator can configure these to use a separate, typically lower-cost model instead; only a short excerpt of recent conversation (never full history, and never raw generated image/audio/video files) is sent for these specific calls. When ZDR mode applies to your chat, these background calls are re-routed to a zero-retention model as well, or skipped entirely if none is available — they are never quietly sent to a model outside the arrangement.

Zero Data Retention (ZDR)

Zero Data Retention is a contractual arrangement between this site's operator and the AI provider, not something that can be switched on from a request. OpenAI grants it subject to prior approval at the organisation level; Anthropic enables it per organisation through its sales team and excludes certain designated models from it entirely. Accordingly, ZDR mode is only offered here for providers where the operator has confirmed a signed agreement is in place — if none has been confirmed, ZDR mode reports that it is unavailable rather than implying a guarantee that does not exist.

Where it is available, you can enable ZDR mode in Preferences, and optionally restrict the model picker to ZDR-covered models only. We additionally send each provider's available privacy controls on every such request (for example OpenAI's store: false, and a routing preference on OpenRouter that avoids providers which train on prompts). These controls are useful in their own right but are not by themselves zero retention.

⚠️ What ZDR does not cover

Web search. If web search is enabled for a message, a query derived from what you typed is sent to a third-party search provider (Tavily, Serper, Brave Search, Exa or Parallel, depending on configuration) and the resulting pages are fetched. Those providers receive your query under their own terms and retention policies, which are outside our control and outside any ZDR arrangement.

Voice input. Audio you record is sent to a third-party transcription provider to be turned into text, under that provider's own terms.

Both features are opt-in. If a conversation must stay within a zero-retention boundary, leave web search off and do not use voice input for it.

If you bring your own API key (BYOK) on a plan that allows it, your requests for that provider are billed and rate-limited by your own account with that provider directly, not ours.

Payments

Subscription and pay-as-you-go payments are processed by a third-party payment gateway (Stripe, SSLCommerz, or a manual/offline method the operator has configured) — we never see or store your full card number. Only transaction metadata needed for billing records (amount, date, plan, status) is kept on our side.

Data retention & deletion

Security measures

Your rights & choices

Sensitive information & regulated Modules

Some Modules — the guided tools in the app — invite you to paste or upload material in areas that are sensitive by nature: contracts, financial statements, health questions, CVs and candidate details. What you put into them is treated exactly like any other chat content, which means the following is worth knowing before you paste.

We do not use the content of your Module runs to train models, and we do not sell it. What the Terms say about relying on that output — that it is a draft for a qualified person to review — is separate from, and additional to, everything on this page.

Controlling what the AI remembers

Memory is how the assistant carries facts about you from one conversation to the next. It is entirely under your control, at three levels:

Everything stored is listed in your account, where each item can be edited or deleted individually. Deleting a memory removes it from all future conversations. Facts learned inside a project are stored against that project and are not used in chats outside it.

Automatic extraction reads the conversation it runs on in order to identify durable facts. Where it runs, it is subject to the same provider terms and Zero-Data-Retention settings as any other message. It does not run for chats with the memory switch off.

Browser extension

The extension does not read pages in the background. No page content leaves your browser until you explicitly capture it — the current page, another open tab, or a screenshot — and send it as part of a message.

What you capture is then treated exactly like text you typed: stored with the conversation, and passed to the AI provider you selected under that provider’s terms. Nothing about the extension creates a separate data path or a separate retention rule.

Authentication. The extension holds a revocable access token rather than your password, kept in the browser’s extension storage where ordinary web pages cannot reach it. You can revoke it from your account at any time; doing so signs the extension out without affecting your password or other sessions.

Browsing history is not collected. The extension has no access to pages you have not deliberately handed to it.

Children's privacy

This service is not directed to children and is not knowingly used to collect personal information from anyone under the minimum age required by applicable law in their jurisdiction.

Changes to this policy

We may update this page as the service evolves (for example, adding a new AI provider or a new privacy control). The "Last updated" date at the top reflects the most recent revision. Continued use of the service after a change constitutes acceptance of the updated policy.

Questions about privacy or data handling? Contact support.