Legal
Privacy Policy
Effective: 2026-08-13 · Last updated: 2026-08-13
These documents are written to match how OpenChat-1 actually works today — not marketing fluff. If our practices change, we will update the date above and the pages linked in the footer.
1. Who we are
This Privacy Policy describes how OpenChat-1 (“we”, “us”, “the Service”), available at openchat.one and related deployments, handles personal information. We operate a multi-model chat product grounded in multi-sector datasets, agent tooling, API access, and prepaid credits.
Honesty first: we are a small / early-stage product. Our infrastructure may include managed cloud hosts (e.g. Vercel), a managed Postgres database (e.g. Neon), payment processors, AI model providers, and—when configured—a secure tunnel to a private data lake operated by us. We do not pretend otherwise.
2. What this policy covers (and what it does not)
- Covers: personal data about you as a user or visitor of the Service.
- Does not turn public datasets into “your data”: much of our lake is aggregated open / third-party market, climate, satellite, and statistical data. Those sources have their own licenses and privacy regimes. We are not the original controller of that third-party content.
- Does not control AI providers: when you send a prompt, the model provider may process it under their policies (see §6).
3. Information we collect
Depending on how you use the Service, we may collect:
- Account data: name, email address, password (stored as a one-way hash — we cannot read your password), organization / workspace name.
- Session & security: session cookies or tokens, approximate timestamps, IP address, user agent, rate-limit counters, captcha challenge results, and similar anti-abuse signals.
- Billing & credits: credit balances, free-prompt flags, subscription status, and payment-related identifiers. Card payments, if offered, are processed by Stripe (we do not store full card numbers). Crypto payments (e.g. USDC on Solana) use public blockchain addresses and transaction IDs you provide or generate — blockchains are public by design.
- API keys: keys we issue for the Data API (hashed where applicable). If you store your own third-party API keys (BYOK) in the product, we treat them as secrets: they are intended for server-side use only and must not be exposed to browsers. No encryption scheme is perfect; do not upload keys you cannot rotate.
- Chat & product usage: prompts, tool/agent configurations, selected models, and responses as needed to run the feature and debit credits. We may keep logs for debugging, abuse prevention, and billing disputes for a limited period.
- Support: messages you send us by email or in-product forms.
We do not knowingly scrape your private email inbox, contacts, device photos, or microphone without an explicit product feature you turn on (we do not currently offer those features).
4. How we use information
- Provide, operate, and secure the Service
- Authenticate you and enforce rate limits / free-tier rules
- Process credits, subscriptions, and prevent fraud
- Route prompts to AI providers you select (or our defaults)
- Improve reliability, debug outages, and measure aggregate usage
- Comply with law and respond to lawful requests
- Communicate service notices (security, terms changes, billing)
We do not sell your personal information. We do not run third-party advertising pixels that track you across the web for ad retargeting as part of the core product. If that ever changes, we will update this policy first.
5. Cookies and similar tech
We use cookies / local storage primarily for authentication sessions and essential preferences. The Service is not designed around cross-site advertising cookies. Blocking all cookies may prevent sign-in from working.
6. AI model providers (important)
Chat and agent features send prompt text (and sometimes tool outputs or retrieved dataset slices) to third-party model APIs such as OpenRouter and/or xAI, and optionally providers you configure with your own keys (e.g. Replicate).
- Those providers process content under their own privacy policies and data-retention practices. We do not control their training policies.
- Do not put secrets, passwords, private keys, health records, or other highly sensitive personal data into prompts unless you accept that third parties may process them.
- Default models and routing may change as we improve the product.
7. Data lake, datasets, and the home-lake bridge
Our multi-sector data lake is primarily non-personal or aggregated third-party data (markets, climate, satellite metadata, open government stats, etc.). Access from production may go through a secure, authenticated bridge to infrastructure we operate.
- Bridge credentials are server-side secrets; they are not meant for browsers or public repos.
- Dataset downloads / API records are subject to each source’s license and to our Terms of Service.
- If a dataset accidentally contains personal data from an upstream source, notify us at privacy@openchat.one so we can remediate.
8. Who we share data with
We share personal data only as needed:
- Processors: hosting (e.g. Vercel), database (e.g. Neon/Postgres), email delivery if enabled, Stripe for cards, blockchain networks for crypto payments, AI APIs for chat completions.
- Legal: if required by law, valid legal process, or to protect rights, safety, and security.
- Business transfer: if we merge, sell assets, or restructure, data may transfer under equivalent protections with notice where required.
We do not sell personal data to data brokers. We do not share your prompts with other customers as a product feature.
9. Retention
- Account data: while your account is active
- Billing / credit ledger: as long as needed for accounting, fraud prevention, and legal retention (often years)
- Chat logs / operational logs: typically shorter operational windows unless needed for abuse or dispute handling
- After account deletion requests: we delete or anonymize personal data we control within a reasonable period, except where law or legitimate security needs require retention
Public blockchains cannot be “deleted.” Crypto payment history on-chain remains public forever.
10. Security
We use industry-standard measures appropriate to our size: TLS in transit on public endpoints, hashed passwords, restricted server secrets, path-allowlisted lake bridge with bearer + request signing, and least-privilege access where practical.
No system is perfectly secure. You are responsible for password strength, API key hygiene, and not posting secrets into chats or public tickets.
11. International transfers
We and our processors may process data in the United States and other countries. If you access the Service from the EU/UK or elsewhere, you understand data may cross borders. Where required, we rely on appropriate transfer mechanisms used by our infrastructure providers.
12. Your rights
Depending on where you live, you may have rights to access, correct, delete, or export personal data, or to object to / restrict certain processing. Email privacy@openchat.one with the subject “Privacy request” and enough detail to verify you control the account. We may need to confirm identity before acting.
You can also close your account by contacting support. Some residual records (e.g. invoices, fraud logs) may remain as allowed by law.
13. Children
The Service is not directed to children under 16 (or the higher age required in your jurisdiction). We do not knowingly collect personal data from children. If you believe a child registered, contact us and we will delete the account.
14. Do Not Track / automated decision-making
We do not respond to browser “Do Not Track” signals in a special way beyond our general practices. We do not use personal data for fully automated decisions that produce legal or similarly significant effects about you (e.g. credit scoring). Credit balances and rate limits are ordinary product metering.
15. Changes
We will update this page when practices change materially and revise the “Last updated” date. Continued use after the effective date means you acknowledge the updated policy. For significant adverse changes, we will attempt reasonable notice (e.g. site banner or email if we have it).
16. Contact
Privacy: privacy@openchat.one
Legal: legal@openchat.one
If your jurisdiction requires a physical mailing address for privacy notices, request it at the email above and we will provide the current operator address we use for formal notices.