Privacy Policy
Last updated
In short: We do not train on your conversations. We do not log message content by default. Delete your account and your conversations, files and memories are gone within 30 days — we keep only payment records and safety records, because the law requires it.
What we collect
- Account details — your email address or phone number, and a display name if you set one.
- Your conversations — the messages you send and the answers you receive, so you can come back to them.
- Files you upload — and text extracted from them, so the assistant can answer questions about them.
- Usage records — how many tokens each request used, so we can bill accurately and detect abuse. These records do not contain your message content.
- Payment records — the amount, method and reference of each payment. We never see or store your card details, wallet PIN or banking credentials.
What we do not do
- We do not train models on your conversations. Not our own models, and we do not permit our providers to.
- We do not log message content by default. Content logging is off in every environment except a developer machine, and the service refuses to start with it enabled anywhere else.
- We do not sell your data or share it with advertisers.
Who else processes your data
Answering a message means sending your conversation to a model provider. Which providers we use, and where they operate, is listed on our sub-processors page. If your billing country is in the EU or UK, requests are routed only to providers operating under terms our legal review has cleared for that purpose.
How long we keep things
- Conversations, files and memories — until you delete them, or until 30 days after you delete your account.
- Payment records — seven years, because tax law requires it. After account deletion these are stripped of anything identifying you.
- Safety records — kept after deletion without your identity attached, so that someone suspended for serious abuse cannot simply register again. We rely on our legitimate interest in keeping the service safe.
- Payment provider messages — the raw records are erased after 30 days; only the reference is kept.
Deleting your account
Delete your account from Settings. Your sessions end immediately and you cannot sign in. For 30 days you can still cancel and get everything back. After that, your conversations, files, memories and any provider keys you stored are permanently erased.
Your rights
You can ask for a copy of your data, ask us to correct it, or ask us to delete it. Write to privacy@guftagu.ai and we will respond within 30 days. If you are in the EU or UK you also have the right to complain to your data protection authority.
Children
Guftagu is not for anyone under 13, and under 18s need a parent or guardian to agree on their behalf. We do not knowingly collect data from children.
Security
Traffic is encrypted in transit. Passwords are hashed with Argon2id and cannot be recovered by us or by anyone who obtains our database. Provider keys you supply are encrypted with a key held in a managed key service. To report a vulnerability, write to security@guftagu.ai.
Changes
If we change this policy in a way that materially affects you, we will email you before it takes effect.