Privacy Policy

Effective At: July 30, 2026
Last Updated: September 23, 2026

At Secret Chat, privacy isn't a feature—it's our foundation. This Privacy Policy explains how we handle your information when you use our service. We've written it in plain language because transparency matters. It covers our website, our web app and our browser extension — for the extension specifically, see Our Browser Extension below.

Our Core Privacy Commitment

There is no chat archive on our servers, and nobody here reads your conversations. Your chats with AI models happen through our platform, but we are not a party to them. All conversation data is stored locally in your browser (messages in IndexedDB, files in OPFS), not on our servers.

Two precisions, because the honest version of this claim is more useful to you than the absolute one. First, a prompt does exist on our side briefly — that is how the answer reaches you: it is held only for as long as it takes to deliver the reply to your browser, deleted as soon as your browser collects it, and deleted automatically within 24 hours if it never does. It is never indexed, never associated with your account, and never used to train anything. Second, prompts pass an automated safety classifier before they are sent to a model, described under "Automated Safety Screening" below. That is a machine check, not a person reading your chat.

Our Browser Extension

This section covers Secret Chat AI — Private AI Chat Sidebar, our browser extension for Google Chrome, Microsoft Edge and Mozilla Firefox. It is part of this policy rather than a separate one, because the extension is a sidebar frame around the same web app the rest of this page describes: everything stated elsewhere here applies to it identically.

What the extension itself does

The extension shows our web app (https://app.secret-chat.ai) in the browser's side panel, so you can chat alongside the page you are reading. It does nothing else. It contains no content scripts, no analytics, no trackers and no advertising code, and it loads no remotely hosted code. It does not read the pages you visit, your browsing history, your tabs, your bookmarks, your downloads or your cookies, and it keeps no storage of its own.

It has exactly one function beyond displaying the app: when the app asks it to open a link — the prices page, or a legal page like this one — it opens that link in an ordinary browser tab, because our website declines to be displayed inside a frame. It acts on such a request only when the request comes from https://app.secret-chat.ai and only for https:// addresses.

The extension requests access to two hosts and no others: https://app.secret-chat.ai/*, the app shown in the panel, and https://gateway.secret-chat.ai/*, the API that app calls. Both are ours. They are required because in a side panel the top-level document is the extension itself, so the app runs as a third-party frame; without host permissions the browser would treat the app's own session cookie and its own local chat storage as third-party, and you would be signed out — and cut off from the chat history stored in your browser — every time you opened the panel. No other website is reachable by this extension.

The panel grants the app access to the microphone and to the clipboard, so that voice input and copy buttons work in the sidebar as they do in a tab. Your browser still asks for the microphone permission separately, and nothing is captured unless you press the voice button.

What data is collected

The extension collects no data on its own account. What follows is what the web app inside it handles — identical in the sidebar and in a browser tab:

  • Personally identifiable information: an email address, and only if you choose to register. No name, no phone number, no other personal details. There is a free daily allowance, so the app can be used without an account at all.
  • Personal communications: the messages you send, the files you attach and any voice input you record — collected for the single purpose of obtaining an answer from the AI model you selected.
  • Authentication information: the session cookie and session identifiers that keep you signed in and tie your credit balance to your account.
  • Location: the country a request comes from, derived from the IP address. Country level only — never a precise location — and used for our own visit statistics.
  • Technical and log data (not one of the store data categories): IP addresses, request timestamps and error codes, plus the browser user-agent, referring site and campaign parameters of your first visit to our website.
  • Financial and payment information: the payment records listed under "Payment and billing information" below, if you buy credits. Purchases happen on our website in an ordinary tab, not inside the panel, and card and wallet credentials are handled by the payment provider, never by us.

The files you attach and the voice input you record are part of the message you choose to send, and are handled as such. We do not collect health information, contacts, credentials for any other service, or a record of your browsing, and we collect no content from any web page you visit — the extension has no access to page content at all.

How that data is used

Each item is used only for the purpose it was collected for: your messages to obtain the answer you asked for, your email address for account access and payment, session identifiers to keep you signed in, payment records to complete and support your purchase, and technical data for security, troubleshooting and aggregate statistics. None of it is used to build a profile of you, to advertise to you, or to train any AI model.

Your prompt reaches the model provider anonymously in a specific and limited sense: no account identifier travels with it, and the record on the provider's side carries our gateway's credentials and server address, not your name, your account or your IP. That describes the link, not the words. Secret Chat AI removes you from your queries — it does not remove the data from your messages. Whatever you type is sent verbatim, so removing names, numbers and identifiers before you send remains your own judgement to make.

How it is stored, and for how long

  • Your conversations stay in your browser. Messages are stored in IndexedDB and files in OPFS, under the app's own origin, on your device. We hold no copy and cannot read them. Uninstalling the extension does not by itself erase them; deleting them in the app, or clearing the site's data in your browser, does — permanently, with no copy on our side to restore.
  • A prompt exists on our servers only in transit. It is deleted as soon as your browser collects the answer, and automatically within 24 hours if your browser never does. It is never indexed and never associated with your account.
  • Server logs (IP addresses, timestamps, error codes) are kept for a maximum of 30 days.
  • Safety-screening records, written when a prompt is refused as described under "Automated Safety Screening", are kept for 90 days and contain no prompt text.
  • Your account record, credit balance and payment records are kept for as long as you have an account, and afterwards only where accounting or legal obligations require it.
  • Session Privacy Reports you generate are archived so that we can answer later questions about what was deleted and when. They hold metadata only — model, provider, deletion status and provider response identifiers — never prompt text.

You can delete your chats and your account from within the app at any time; for anything else, write to . Your rights of access, deletion, portability and objection are set out under "Your Data Rights" below and apply to the extension exactly as they do to the website.

Who it is shared with

We share only what a given task requires, and only with:

  • The AI model provider you selected — your prompt, so that it can be answered. The providers and their own policies are listed under "Third-Party AI Model Providers" below. If you use the AI Council, you have selected a panel rather than a single model: the same prompt is sent to each provider on that panel, and to the provider of the referee model that compares their answers. Every one of those requests is made in the same way as any other — under our gateway's credentials, with no account identity attached — but the prompt reaches more than one provider, and each applies its own terms. The per-message Session Privacy Report names every model that took part.
  • An automated content classifier, which screens the prompt before it reaches a model, as described under "Automated Safety Screening".
  • Our payment providers — Creem for card payments, Volet for crypto payments — which handle the payment itself.
  • Our email delivery provider (Mailgun), which sends account verification, password-reset, payment and subscription messages to your address.
  • Our infrastructure providers — hosting, content delivery and object storage — which process data on our instructions in order to run the service.

We do not sell or rent your data, we show no advertising, and neither the extension nor the app it displays runs any third-party advertising or tracking code. We disclose your data to no one else except where a valid legal obligation requires it. What could be produced in response to such a request is set out in our Law Enforcement Guidelines.

Personal information about other people

A message you send may contain personal information about someone else — a name in a document you attach, a third party described in a question you ask. When it does, that information is transmitted to the AI provider you selected in the same way the rest of your message is — and, if you used the AI Council, to every provider on that panel — and it is subject to everything stated above. Secret Chat AI removes you from your queries; it does not remove the data from your messages. Deciding what to include about other people, and having any consent that requires, is yours to do before you press send. If personal information about you was sent to us by someone else in this way, write to and we will delete what we hold and can identify — which, given that prompts are not retained, is normally nothing.

Security of what we do hold

Data in transit is encrypted with TLS. Account passwords are stored only as salted hashes, database backups are encrypted with AES-256 before they leave our servers, and access to our systems is restricted to authorised personnel and logged. See "Data Security" below.

Our commitments for the extension

  • We do not sell or transfer user data to third parties, outside of the approved use cases described above.
  • We do not use or transfer user data for any purpose unrelated to the extension's single purpose, which is to display the Secret Chat AI web app in the browser's side panel.
  • We do not use or transfer user data to determine creditworthiness or for lending purposes.

Our use of user data obtained through the extension complies with the Chrome Web Store User Data Policy, including its Limited Use requirements.

What We Don't Collect

Let's start with what matters most to you:

  • Your Conversations: We do not keep your prompts, the AI's responses, or any part of your chat history. Nothing is retained once your browser has the answer, and no chat history exists on our servers to be searched, exported or handed over.
  • Your Projects and Threads: All organizational structures you create (projects, threads, message edits) are stored exclusively in your browser's local storage.
  • Your Uploaded Files: When you upload images or PDFs, we strip metadata and process them ephemerally. Other documents (Word, spreadsheets, PowerPoint, CSV, text, code, zip archives) are converted to plain text in your browser and only that text is sent with your message; the file itself is never uploaded. We do not retain copies of your files.
  • User Profiles or Behavioral Data: We do not build profiles of you, track your behavior across the web, or use your data for advertising.

What We Do Collect

To provide and improve Secret Chat, we collect minimal information:

1. Payment and billing information

When you purchase credits or digital access, payments may be processed by third-party payment providers.

Card payments are processed by our payment provider, Creem (creem.io). For more details on how Creem handles your data, see Creem's Privacy Policy.

Crypto payments are processed by Volet.com. For more details on how Volet handles your data, see Volet's Privacy Notice.

We do not store full card numbers, card validity dates, card security codes, crypto private keys, seed phrases, or full wallet credentials on our servers.

For payment processing, fraud prevention, accounting, support, legal compliance, and service delivery, we may process and store payment-related records such as:

  • payment amount;
  • currency;
  • selected payment method;
  • payment status;
  • payment date;
  • order ID;
  • transaction ID or payment reference;
  • invoice/receipt data;
  • customer email, where provided;
  • provider response data necessary to confirm and support the payment.

For crypto payments, payment-related records may also include:

  • selected cryptocurrency;
  • selected blockchain network, if applicable;
  • transaction hash, if available;
  • wallet/payment address generated by the provider, if available;
  • payment expiration time, if applicable;
  • confirmation status.

2. Your account and credits

Secret Chat uses an email-only account — registration requires only an email address, with no names, no phone numbers, and no personal details. Your credit balance is associated with your email-only account. You are solely responsible for securing your account credentials. If you lose access to them, we cannot recover your credits or data.

3. Technical and usage data

We collect limited, anonymized technical information to ensure the service functions properly:

  • Server Logs: IP addresses, request timestamps, and error codes are logged temporarily for security monitoring and troubleshooting. These logs are retained for a maximum of 30 days.
  • Aggregate Analytics: We may collect anonymous usage statistics (e.g., total number of requests, feature usage patterns) to understand how the service is used and to improve performance. This data is not linked to individual users or sessions.

4. Support communications

If you contact our support team, we retain your email address and the content of your messages to provide assistance. This information is kept only as long as necessary to resolve your inquiry.

How Your Data is Stored

Local browser storage

All of your chat history, projects, and settings are stored in your browser using IndexedDB for messages and OPFS (Origin Private File System) for files. This means:

  • We cannot access this data. The stored copy never leaves your device unless you export it. Sending a message is a separate and deliberate act: the prompt itself does go to the safety classifier and to the model provider you chose, because that is the only way an answer can come back.
  • You control it. You can delete it at any time by clearing your browser's cache or using the in-app delete functions.
  • It is device-specific. If you switch browsers or devices, your data will not automatically transfer unless you manually export and import it.

Important: Clearing your browser data will permanently delete your local chat history. We cannot recover it for you.

Third-Party AI Model Providers

Secret Chat is a gateway to multiple AI models (including GPT, Claude, Gemini, Grok, DeepSeek, Venice, and others). When you send a prompt, we forward it to the selected model provider via their API. When you send it to the AI Council, we forward the same prompt to each provider on the panel you selected, plus the provider of the referee model — so several of the providers listed below receive it, each under its own terms.

Our contractual guarantees

We choose providers and configurations that minimise what is kept: zero-retention API terms where a provider offers them, no-training terms throughout, and per-response deletion where the provider supports it. Say what that does and does not promise, because the honest version is the useful one — it is not a guarantee that nothing is held anywhere. Providers keep their own abuse-monitoring records under their own policies, some retain flagged content for extended periods, and some routes offer no per-response deletion at all. What is constant is the link, not the retention: the record on the provider's side carries our gateway's credentials and server address, not your name, your account or your IP.

For each message you can open a Session Privacy Report, which sets out, per model, what that provider's terms say about retention and whether the response was deleted at the provider. The report is generated when you ask for it, not kept for every message you send — and a copy of each report that is generated is archived, so that we can answer later questions about what was deleted and when. Those archived reports hold metadata only: model, provider, deletion status and provider response identifiers. Never prompt text.

Provider-specific policies

Each AI model provider operates under their own terms of service and privacy policy:

We recommend reviewing these policies to understand how each provider handles data sent through their APIs.

A note on DeepSeek USA. DeepSeek publishes its model weights openly, so the model can be run by parties other than DeepSeek — and we do not send your prompts to DeepSeek. Requests are routed through OpenRouter, and restricted to an allowlist of US-headquartered inference providers whose declared data policy is that they do not collect user data. DeepSeek's own privacy policy therefore does not govern these requests; OpenRouter's does, together with the policy of the US provider that serves each call. The provider that served your request is recorded in that message's Session Privacy Report.

Automated Safety Screening

Before a prompt is sent to a model, it is checked by automated content screening. We disclose this because you should not have to discover it: it means your prompt is submitted to a third-party screening service in addition to the model you chose, and this applies to every model in the line-up. The text you send — your own words and any documents you attach — is screened by Creem, our payment provider, through its Moderation API; it is sent without your account, your email or any other identifier. Pictures you attach are screened by OpenAI's moderation classifier.

What the check produces is a verdict, not a copy of your text for us to keep. Text is held to one content policy whichever model you picked. For pictures, how strictly the check is applied depends on the model you selected, and a small set of categories — sexual content involving minors, and threats of violence against a person or a group — is refused on every model regardless. A blocked prompt is never sent to a model. The screening of your text is charged to you — a fraction of a credit per check, whether the prompt passes or is refused.

When a prompt is refused, we record that it happened: the screening verdict (or, for a picture refused in one of the always-blocked categories, that category), the model, the timestamp and the account or session identifier — never the text of the prompt. These records are kept for 90 days, are not used to profile you, are not shown anywhere in the product, and do not by themselves trigger any report to anyone. They exist so that we can enforce our Acceptable Use Policy and answer a valid legal request truthfully. A picture refused only because a model is screened more strictly is not recorded.

Classifiers are wrong in both directions. A refusal is not an accusation, and you can tell us about a mistaken one at .

Cookies and Tracking Technologies

We use cookies and similar technologies to provide essential functionality:

Strictly necessary cookies

These cookies are required for the service to function. They enable features like session management and security. You cannot disable them without losing core functionality.

Analytics cookies (optional)

We may use privacy-respecting analytics tools (such as Plausible or a similar service that does not track individual users) to understand aggregate site usage. If implemented, you will be able to opt out of these cookies via a banner or settings page.

We do not use third-party advertising cookies or tracking pixels.

Your Data Rights

Depending on your location, you may have certain rights regarding your personal data under laws like the GDPR (Europe) or CCPA (California).

Right to access

You can request a copy of any personal data we hold about you. Since we keep no conversation history, that comes to: your account record (email address, registration date, email verification status); payment and billing records, including credit grants and usage totals; credit usage totals, meaning how many credits were spent on which model and when — accounting data that records that a model was used, never what was said to it; server logs (IP addresses, request timestamps and error codes, kept at most 30 days); visit attribution from your first visit (referring site, landing page, campaign parameters, country and browser user-agent); support correspondence; any Session Privacy Reports generated when you asked us to delete a response at a provider; and — if any exist for your account — the safety-screening records described above. Our Law Enforcement Guidelines set out the same list from the other direction: exactly what could be produced in response to a valid legal request.

Right to deletion

You can request deletion of your payment and billing information. Contact us at with your request. Note that we may be required to retain certain records for legal or accounting purposes.

Right to portability

You can export your local chat data at any time using the in-app export feature. This data is yours and can be transferred to another service.

Right to object

You can object to our processing of your data for analytics purposes by disabling optional cookies or contacting us.

To exercise any of these rights, email us at .

Data Security

We take security seriously and implement industry-standard measures to protect your information:

  • Encryption in Transit: All data transmitted between your browser and our servers is encrypted using TLS (Transport Layer Security).
  • Metadata Stripping: When you upload images or PDFs, we automatically remove EXIF and other metadata before processing.
  • Minimal Data Retention: We retain the absolute minimum data necessary to provide the service and comply with legal obligations.
  • Access Controls: Access to our systems is restricted to authorized personnel only and is logged for audit purposes.

However, no system is completely secure. While we strive to protect your data, we cannot guarantee absolute security. You are responsible for maintaining the security of your device and your account credentials.

International Data Transfers

Secret Chat is operated from Montenegro. If you access our service from outside this region, your limited personal data (such as payment information) may be transferred to and processed in Montenegro or other countries where our service providers operate.

We ensure that any such transfers comply with applicable data protection laws, including the use of standard contractual clauses where required.

Children's Privacy

Secret Chat is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have inadvertently collected data from a child, we will delete it promptly.

Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make significant changes, we will notify you by:

  • Posting a notice on our website or within the app.
  • Updating the "Last Updated" date at the top of this policy.

We encourage you to review this policy periodically. Your continued use of Secret Chat after changes are posted constitutes your acceptance of the updated policy.

Marketing Consent

We do not require users to participate in marketing campaigns in order to use the Service. If we offer newsletters, promotions, or marketing messages, users may opt in voluntarily and may unsubscribe or withdraw consent at any time.

We do not sell users' personal data. We do not share personal data with third parties for their own marketing purposes without the user's explicit consent.

Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

Email:
Opossum DOO
Herzeg-Novi, Montenegro