Effective At: July 30, 2026
Last Updated: August 15, 2026
At Secret Chat, privacy isn't a feature—it's our foundation. This Privacy Policy explains how we handle your information when you use our service. We've written it in plain language because transparency matters.
Our Core Privacy Commitment
There is no chat archive on our servers, and nobody here reads your conversations. Your chats with AI models happen through our platform, but we are not a party to them. All conversation data is stored locally in your browser (messages in IndexedDB, files in OPFS), not on our servers.
Two precisions, because the honest version of this claim is more useful to you than the absolute one. First, a prompt does exist on our side briefly — that is how the answer reaches you: it is held only for as long as it takes to deliver the reply to your browser, deleted as soon as your browser collects it, and deleted automatically within 24 hours if it never does. It is never indexed, never associated with your account, and never used to train anything. Second, prompts pass an automated safety classifier before they are sent to a model, described under "Automated Safety Screening" below. That is a machine check, not a person reading your chat.
What We Don't Collect
Let's start with what matters most to you:
- Your Conversations: We do not keep your prompts, the AI's responses, or any part of your chat history. Nothing is retained once your browser has the answer, and no chat history exists on our servers to be searched, exported or handed over.
- Your Projects and Threads: All organizational structures you create (projects, threads, message edits) are stored exclusively in your browser's local storage.
- Your Uploaded Files: When you upload images or PDFs, we strip metadata and process them ephemerally. We do not retain copies of your files.
- User Profiles or Behavioral Data: We do not build profiles of you, track your behavior across the web, or use your data for advertising.
What We Do Collect
To provide and improve Secret Chat, we collect minimal information:
1. Payment and billing information
When you purchase credits or digital access, payments may be processed by third-party payment providers.
Card payments are processed by our payment provider, Creem (creem.io). For more details on how Creem handles your data, see Creem's Privacy Policy.
Crypto payments are processed by Volet.com. For more details on how Volet handles your data, see Volet's Privacy Notice.
We do not store full card numbers, card validity dates, card security codes, crypto private keys, seed phrases, or full wallet credentials on our servers.
For payment processing, fraud prevention, accounting, support, legal compliance, and service delivery, we may process and store payment-related records such as:
- payment amount;
- currency;
- selected payment method;
- payment status;
- payment date;
- order ID;
- transaction ID or payment reference;
- invoice/receipt data;
- customer email, where provided;
- provider response data necessary to confirm and support the payment.
For crypto payments, payment-related records may also include:
- selected cryptocurrency;
- selected blockchain network, if applicable;
- transaction hash, if available;
- wallet/payment address generated by the provider, if available;
- payment expiration time, if applicable;
- confirmation status.
2. Your account and credits
Secret Chat uses an email-only account — registration requires only an email address, with no names, no phone numbers, and no personal details. Your credit balance is associated with your email-only account. You are solely responsible for securing your account credentials. If you lose access to them, we cannot recover your credits or data.
3. Technical and usage data
We collect limited, anonymized technical information to ensure the service functions properly:
- Server Logs: IP addresses, request timestamps, and error codes are logged temporarily for security monitoring and troubleshooting. These logs are retained for a maximum of 30 days.
- Aggregate Analytics: We may collect anonymous usage statistics (e.g., total number of requests, feature usage patterns) to understand how the service is used and to improve performance. This data is not linked to individual users or sessions.
4. Support communications
If you contact our support team, we retain your email address and the content of your messages to provide assistance. This information is kept only as long as necessary to resolve your inquiry.
How Your Data is Stored
Local browser storage
All of your chat history, projects, and settings are stored in your browser using IndexedDB for messages and OPFS (Origin Private File System) for files. This means:
- We cannot access this data. It never leaves your device unless you explicitly export it.
- You control it. You can delete it at any time by clearing your browser's cache or using the in-app delete functions.
- It is device-specific. If you switch browsers or devices, your data will not automatically transfer unless you manually export and import it.
Important: Clearing your browser data will permanently delete your local chat history. We cannot recover it for you.
Third-Party AI Model Providers
Secret Chat is a gateway to multiple AI models (including GPT, Claude, Gemini, Grok, DeepSeek, Venice, and others). When you send a prompt, we forward it to the selected model provider via their API.
Our contractual guarantees
We only work with providers that offer zero data retention APIs or commit to deleting session data immediately after processing. For each message, you can view a Session Privacy Report that confirms the provider's data handling policy.
Provider-specific policies
Each AI model provider operates under their own terms of service and privacy policy:
- OpenAI (GPT): openai.com/policies/privacy-policy
- Anthropic (Claude): anthropic.com/privacy
- Google (Gemini): policies.google.com/privacy
- xAI (Grok): x.ai/legal/privacy-policy
- Venice: venice.ai/legal/privacy-policy
- OpenRouter (DeepSeek USA): openrouter.ai/privacy and openrouter.ai/terms
We recommend reviewing these policies to understand how each provider handles data sent through their APIs.
A note on DeepSeek USA. DeepSeek publishes its model weights openly, so the model can be run by parties other than DeepSeek — and we do not send your prompts to DeepSeek. Requests are routed through OpenRouter, and restricted to an allowlist of US-headquartered inference providers whose declared data policy is that they do not collect user data. DeepSeek's own privacy policy therefore does not govern these requests; OpenRouter's does, together with the policy of the US provider that serves each call. The provider that served your request is recorded in that message's Session Privacy Report.
Automated Safety Screening
Before a prompt is sent to a model, it is checked by an automated content classifier. We disclose this because you should not have to discover it: it means your prompt is submitted to that classifier — a third-party service — in addition to the model you chose, and this applies to every model in the line-up.
What the check produces is a set of category scores, not a copy of your text for us to keep. How strictly it is applied depends on the model you selected; a small set of categories — sexual content involving minors, and threats of violence against a person or a group — is refused on every model regardless. A blocked prompt is never sent to a model and costs you no credits.
When a prompt is refused for one of those few always-blocked categories, we record that it happened: the category, the model, the timestamp and the account or session identifier — never the text of the prompt. These records are kept for 90 days, are not used to profile you, are not shown anywhere in the product, and do not by themselves trigger any report to anyone. They exist so that we can enforce our Acceptable Use Policy and answer a valid legal request truthfully. Ordinary moderation refusals — a model declining a topic it does not cover — are not recorded at all.
Classifiers are wrong in both directions. A refusal is not an accusation, and you can tell us about a mistaken one at .
Cookies and Tracking Technologies
We use cookies and similar technologies to provide essential functionality:
Strictly necessary cookies
These cookies are required for the service to function. They enable features like session management and security. You cannot disable them without losing core functionality.
Analytics cookies (optional)
We may use privacy-respecting analytics tools (such as Plausible or a similar service that does not track individual users) to understand aggregate site usage. If implemented, you will be able to opt out of these cookies via a banner or settings page.
We do not use third-party advertising cookies or tracking pixels.
Your Data Rights
Depending on your location, you may have certain rights regarding your personal data under laws like the GDPR (Europe) or CCPA (California).
Right to access
You can request a copy of any personal data we hold about you. Since we keep no conversation history, this is limited to your account email, payment and billing records, support correspondence, and — if any exist for your account — the safety-screening records described above. Our Law Enforcement Guidelines set out the same list from the other direction: exactly what could be produced in response to a valid legal request.
Right to deletion
You can request deletion of your payment and billing information. Contact us at with your request. Note that we may be required to retain certain records for legal or accounting purposes.
Right to portability
You can export your local chat data at any time using the in-app export feature. This data is yours and can be transferred to another service.
Right to object
You can object to our processing of your data for analytics purposes by disabling optional cookies or contacting us.
To exercise any of these rights, email us at .
Data Security
We take security seriously and implement industry-standard measures to protect your information:
- Encryption in Transit: All data transmitted between your browser and our servers is encrypted using TLS (Transport Layer Security).
- Metadata Stripping: When you upload images or PDFs, we automatically remove EXIF and other metadata before processing.
- Minimal Data Retention: We retain the absolute minimum data necessary to provide the service and comply with legal obligations.
- Access Controls: Access to our systems is restricted to authorized personnel only and is logged for audit purposes.
However, no system is completely secure. While we strive to protect your data, we cannot guarantee absolute security. You are responsible for maintaining the security of your device and your account credentials.
International Data Transfers
Secret Chat is operated from Montenegro. If you access our service from outside this region, your limited personal data (such as payment information) may be transferred to and processed in Montenegro or other countries where our service providers operate.
We ensure that any such transfers comply with applicable data protection laws, including the use of standard contractual clauses where required.
Children's Privacy
Secret Chat is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have inadvertently collected data from a child, we will delete it promptly.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. When we make significant changes, we will notify you by:
- Posting a notice on our website or within the app.
- Updating the "Last Updated" date at the top of this policy.
We encourage you to review this policy periodically. Your continued use of Secret Chat after changes are posted constitutes your acceptance of the updated policy.
Marketing Consent
We do not require users to participate in marketing campaigns in order to use the Service. If we offer newsletters, promotions, or marketing messages, users may opt in voluntarily and may unsubscribe or withdraw consent at any time.
We do not sell users' personal data. We do not share personal data with third parties for their own marketing purposes without the user's explicit consent.
Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
Email:
Opossum DOO
Herzeg-Novi, Montenegro