Privacy
What we never store
- Your prompts and answers. They pass through our API in memory and are not written to a database or to logs.
- Your saved chats in readable form. They're encrypted on your device with a key only your wallet can create. We hold the ciphertext only.
How a message travels
- Every model runs inside a hardware enclave (a trusted execution environment) at Phala, Chutes, NEAR AI or Tinfoil, reached through RedPill's attested gateway. Each answer comes with a receipt signed inside that gateway.
- Before a message reaches the model, our API sends it to a safety model (also in an enclave) that checks it only against the hard limits in the terms. This happens in memory.
- End-to-end encrypted models (marked E2EE, when you're signed in and in Chat): your browser encrypts each message to the enclave's key before it leaves your device, and our API only passes on ciphertext. To get that key, your browser asks RedPill (api.redpill.ai) directly for the enclave's attestation.
- Our API itself runs on an ordinary server (Railway), not yet in an enclave. For models that aren't end-to-end encrypted, that's why we say "never stored", and why we don't yet claim that nobody but the enclave could read a message on its way through.
What we keep
- Your wallet address, your credit balance and whether you turned on adult content.
- Usage: for each request, the model, the number of tokens, the cost and the time. Never the content.
- Payments: the transaction, amount, the country you gave, when you made the express request and when the wallet was screened against sanctions lists. Payments on Robinhood Chain are public on the blockchain anyway. We keep payment records as long as Norwegian bookkeeping law requires (normally five years).
- Refund requests and their status.
- Saved chats as ciphertext, with their size, random id and when they changed.
- Sessions and API keys, stored only as hashes.
- Free trial: a hash of the trial token and today's message count. No wallet, no IP address.
Our server logs record the method, path, status and duration of each request. They don't record IP addresses or content.
Who else processes data
- RedPill and the enclave providers run the models.
- Railway hosts our API and Vercel hosts this app. For encrypted chats your browser also contacts RedPill directly to fetch the enclave's key report. Like any host, they handle IP addresses to deliver the service.
- Your wallet and the blockchain are outside our control.
On your device
After you sign in, our API sets one session cookie that scripts can't read. The app keeps a few settings, the trial token and, if you unlock saved chats, the chat key (as a key that can't be exported) in your browser's storage. No analytics, no ads, no third-party scripts or fonts.
Your rights
You can burn a chat or all your saved chats in the app; they're deleted from our database at once. You can ask us for a copy of what we hold about your wallet, or to delete it (except payment records we must keep by law), and you can complain to Datatilsynet, the Norwegian data protection authority.