Privacy Policy

How your data is handled

What we store, why, and the optional extra protection you can turn on for your conversations.

This page explains what account and conversation data AI Chat Console collects, why, how it's used to provide the service, who it's shared with, how long it's kept, and the privacy controls available to you — including the optional chat encryption at rest feature described in detail below. This is a general-purpose policy covering the platform as a whole, not just encryption.

Last updated: August 15, 2026.

Jump to: Information we collect · How we use it · Chat encryption · Third-party AI providers · Payments · Retention & deletion · Security · Your rights · Children's privacy · Changes

Information we collect

Account information

Conversation data

Usage, billing & technical data

API keys (BYOK)

If your plan allows "bring your own key" and you choose to add your own provider API key, it is encrypted at rest (AES-256) using the same key-management approach described below, independent of whether you've turned on chat encryption.

How we use your information

🔒 Chat encryption at rest

In Preferences → Privacy, you can turn on "Encrypt my chats". It is off by default — nothing changes for your account unless you explicitly enable it.

What it does

When enabled, your message content, chat titles, and image/video/audio generation prompts are encrypted (AES-256) before being stored in the database. If someone were to gain unauthorized access to a database backup or export — a stolen backup file, a leaked SQL dump, a compromised low-privilege database credential — your conversations would appear as unreadable ciphertext rather than plain text.

What it does not do

This is server-side encryption, not end-to-end encryption. AI Chat Console's own servers still process your messages in readable form while handling your request — that's how we're able to send them to the AI model and generate a reply. This feature protects against a stolen database copy; it does not hide messages from the operator of this service.

What you gain in exchange

Turning it on or off

Enabling it converts your existing chat history in the background (a progress bar shows how far along it is — safe to close the page and come back, it resumes automatically). Disabling it reverses the process and search comes back once decryption finishes.

⚠️ Software limits of this encryption feature

The technical constraints below apply regardless of your own setting, so you know exactly what "encrypted" does and doesn't mean here.

Third-party AI providers & Zero Data Retention

To generate a response, your message is sent to the AI provider/model you selected (OpenAI, Anthropic, Google Gemini, xAI/Grok, Cloudflare Workers AI, Mistral, DeepSeek, Pruna AI, OpenRouter, or others depending on what's configured on this instance). Each provider processes your request under its own data-handling and retention terms, which are outside our control — please review the provider's own policy if you have concerns about a specific model.

Some background features — rolling context summaries, auto-memory extraction, and Draw-mode follow-up detection (see above) — are not always sent to the same provider/model you picked for your reply. The site administrator can configure these to use a separate, typically lower-cost model instead; only a short excerpt of recent conversation (never full history, and never raw generated image/audio/video files) is sent for these specific calls.

Where a provider offers a Zero Data Retention (ZDR) option, you can enable ZDR mode in Preferences to request it be used wherever available, and optionally restrict the model picker to only ZDR-capable models.

If you bring your own API key (BYOK) on a plan that allows it, your requests for that provider are billed and rate-limited by your own account with that provider directly, not ours.

Payments

Subscription and pay-as-you-go payments are processed by a third-party payment gateway (Stripe, SSLCommerz, or a manual/offline method the operator has configured) — we never see or store your full card number. Only transaction metadata needed for billing records (amount, date, plan, status) is kept on our side.

Data retention & deletion

Security measures

Your rights & choices

Children's privacy

This service is not directed to children and is not knowingly used to collect personal information from anyone under the minimum age required by applicable law in their jurisdiction.

Changes to this policy

We may update this page as the service evolves (for example, adding a new AI provider or a new privacy control). The "Last updated" date at the top reflects the most recent revision. Continued use of the service after a change constitutes acceptance of the updated policy.

Questions about privacy or data handling? Contact support.