Docs/Trust
Privacy: what we keep
What askr stores about me, and what it does not.
Checked against the code on
Short version: we keep what we need to run your account and bill it, and nothing you say to a model.
Files you attach (pictures, PDFs, documents, audio, video) are stored on our server so a model can read them and so you can ask about them again. They go to the model's provider for that turn only, are deleted when you delete the chat or the file on the Files page, and are swept after seven days if never sent. Attach files.
| Thing | Kept? | Detail |
|---|---|---|
| Messages and replies | No | A conversation exists in the browser tab you typed it in. The API forwards your messages to the model and keeps none of them. |
| Images and clips you make | Yes | In your library, with the prompt, the model and the cost, served to you only. A temporary copy also exists on the model gateway for up to 24 hours. Ask and it is deleted. |
| Your email address | Yes | It is the account. |
| Sign-in codes and sessions | As hashes | SHA-256 only. A copy of the database contains nothing usable. |
| API keys | As hashes | The plain key exists only in your copy. Name, prefix and cap are kept so the wallet can list it. |
| Ledger | Yes | Every deposit and every charge: model, tokens, credits, time, and which key made it. This is your activity. |
| Deposit records | Yes | Address, asset, amounts, status, and the processor's payment id. Not the wallet you sent from. The processor issues the address and sees the payment; it does not learn who you are. |
| Card purchases | Yes | Amount, any tax, credits, Stripe's references, status, refunds and disputes, the IP address the checkout started from, and whether you accepted the terms. Your card details, name and billing address stay with Stripe and Link, Stripe's merchant of record, which sends your receipt. Pay by card. |
| Where it runs | A rented virtual server at OVH in the United Kingdom. Standard request logs (IP address, user agent, URL, time, status) rotate like any web server's. | |
| IP address | In flight | Used for rate limiting and in server logs, which rotate. Not tied to your account's ledger. |
| Anything for training | No | Nothing you type trains a model, ours or anyone's. |
Who else sees a request
The model's provider does, because it answers it. Today requests reach providers through a model gateway; the roadmap replaces that with direct routing. Your account identity does not travel with the request. Because there is no table of chat text on askr's side, a past conversation cannot be sent to you or deleted for you: it was never held. Copies that reached the gateway and the provider follow their retention rules.
A version labelled "by" a supplier, such as "Claude Opus 5 (direct)", runs at that supplier instead. Your prompt, the conversation before it, any picture you attach and the reply go to that supplier, and only when you pick its version. No other supplier receives them; where a supplier passes a request on, its line below says so. A version marked ZERO RETENTION comes from a supplier whose terms say it keeps neither the prompt nor the reply. Each supplier, what it runs and what it keeps:
- Anthropic (chat). Anthropic's own API, for the Claude versions marked (direct). With each request it also gets a fixed code made from your account id, so it can tell one person's requests apart; never the id itself or your email. It keeps requests for 30 days under its commercial terms and does not train on them.
- OpenAI (chat). OpenAI's own API, for the GPT versions marked (direct). With each request it also gets a fixed code made from your account id, so it can tell one person's requests apart; never the id itself or your email. We ask it not to store the conversation; it keeps requests for up to 30 days to check for abuse and does not train on them.
- xAI (chat). xAI's own API, for the Grok versions marked (direct). With each request it also gets a fixed code made from your account id, so it can tell one person's requests apart; never the id itself or your email. We ask it not to store the conversation; it keeps requests for up to 30 days to check for abuse and does not train on them.
- fal (video and audio). It makes no zero-retention promise: fal keeps the request, with your prompt and any start frame, for 30 days, and the clip for at least 7. For audio it gets the text you have read, or the description of the song or sound, and the name of the voice you picked, under the same terms. For Seedance it also gets a fixed code made from your account id; never the id itself or your email.
When Search the web is on, the search terms the model chooses are sent to Brave Search; page fetches are made by askr's server, never from your browser. Neither carries your account.
The full policy is at /privacy.