Your data, explained.
Understand how your workspace works and keep a copy of the data that matters to you.
Account and sign-in
We store your username, birth year and encrypted email in Cloudflare D1. Passwords are hashed with a server-only pepper. Session cookies are HttpOnly, secure over HTTPS and inaccessible to page scripts.
Private chats stay on your device
Saved conversations, projects, files and generated artifacts are encrypted in your browser’s IndexedDB. They are not automatically backed up to our server. Clearing browser storage can erase them. Use encrypted database export before changing devices or clearing data. You choose the transfer passphrase; we cannot recover it.
Models and API keys
Provider keys are encrypted in the server vault and are never returned to the browser after saving. The messages and files required to answer your request pass through our API to your chosen model provider. That provider processes them under its own policy.
Temporary chats and public sharing
Temporary chat content stays in memory and is excluded from saved history and exports. Requests still reach your selected model. Publishing a share link explicitly saves an encrypted snapshot on the server, accessible to anyone with the link for seven days or until you revoke it. API keys, system prompts and attachments are excluded.
Visits, devices and approximate location
Optional analytics is enabled only after you accept it. It stores page visits, browser, device category and an approximate country/city supplied by Cloudflare. A random browser identifier is hashed before storage; an account ID can be associated with a signed-in visit. We do not request GPS or store chat text in analytics. Security sign-in events record device and approximate location separately to protect accounts.
Email and support
Account emails are sent through the configured Gmail SMTP sender. Password reset tokens are hashed, expire after 30 minutes and work once. Contact form messages are encrypted in the internal inbox. Cloudflare Turnstile receives the information needed for its anti-bot challenge. Do not include passwords or provider keys in support requests.
Your controls
Delete chats and projects locally, revoke shares and remove provider credentials at any time. Account deletion removes server account data and this device’s local database. Exported files and copies on other devices remain under your control. Optional analytics expires after 90 days and can be disabled from Cookie settings.
Account & database transfer · Contact us · pimxagent@gmail.com