Privacy Policy

A short account of what EasyGPT (easygpt.app) keeps about you, where it goes and how long it lives. It is written from how the service actually works, not from a template: almost everything claimed here you can verify yourself, in the interface or in your browser settings.

What the service stores

For a registered user — an email address and a password, not the password itself but its irreversible fingerprint. It cannot be recovered from the database: forget it and the service issues a new one rather than reminding you of the old. The email serves one purpose, getting you back in; there are no newsletters.

Then everything you made yourself: chats and the messages in them, uploaded files, generated images, folders and their names. And technical records: your credit balance and the spend entries behind it (model, token counts, cost, time), product events such as "arrived", "sent a message", "signed up", and error records. None of them hold the text of your conversations: request bodies are never stored, and event names are a closed list with nowhere to put text.

Your name, phone number and postal address are neither asked for nor stored. The server does see your IP address: without it there is no way to cap floods of new guest records or password guessing. It reaches neither your account nor the analytics nor the error log.

Where your messages go

The service runs no models of its own. To get an answer, the text of your conversation goes to the OpenRouter aggregator, which passes it to the maker of the model you chose. These are foreign companies, their servers sit outside the operator's country, so your text crosses a border while it is processed. Without that transfer the service does not work at all. Who you are is not disclosed: neither your email nor your account identifier is in the request. Every request carries the "no_training" setting — a requirement to exclude providers that keep conversations for themselves.

Hence a simple rule: passwords, identity documents, card numbers and other people's secrets do not belong in the chat. Treat it as any public AI tool. One model needs a separate note: Sonar Pro Search is a search model by design, and every request to it goes out to internet search on the provider's side.

How long it lives

Chats, messages, files, images and the account itself — until you delete them. A session unused for 180 days stops working. A password reset link lives one hour and goes dark the moment it is used. Product events are kept 400 days, error records 30 days. A guest record with no chats and no spending deletes itself after 30 days. Credit spend entries are not deleted — they are the service's financial record — but on account deletion they stop pointing at a person. Backups are taken daily and the fourteen most recent kept, so deleted content leaves them within two weeks.

What you can do yourself

The Account page has two buttons, both working without an email to us or any waiting. "Download my data" builds a zip archive: every conversation in readable form, the same content as a machine-readable file, and all your files and images. "Delete account" erases chats and messages, files and images, sessions on every device, your email and the password fingerprint — database rows and contents on disk alike, with no way back; a registered user is asked for the password first. If what you need is not there — a statement of credit spending, say — write to us.

Guest mode

You can start without registering: a guest record is created on your first request, with no form to fill in. It has no email and no name — only a random token in your browser identifies it. Two consequences, better known in advance. Clearing your browser data or moving to another device means losing those conversations: nothing is left to restore them with. And a letter from a guest asking to hand over or delete their data cannot be acted on — the service cannot check that the writer owns those particular chats. Export and deletion are available to guests right in the interface, and that is the only route that works.

Cookies

Every cookie the service sets is its own. No third-party counter or advertising pixel sits on these pages, which is why there is no cookie banner: there is no one to agree with. easygpt_token is the session token, how the service knows whose conversations these are (400 days; the same token is mirrored in browser storage so the session survives a cookie clear-out). eg_vid is a random visitor tag for our own statistics (400 days). eg_src is the first-visit source: the domain you came from and the utm_* tags from the link (30 days). eg_lang is your chosen interface language (365 days). You can delete them in your browser at any time; for a guest that means losing the conversations.

Who is responsible and how to reach us

The operator of the service is Dmitry Gennadyevich Grigoryev, self-employed, TIN 211604578976, address: apt. 56, block 1, 18 P. V. Dementyeva St., Cheboksary, Chuvash Republic, 428010, Russia.

On any question about this data — from "what do you have on me" to "delete everything" — write to support@easygpt.app. The rules for using the service are in the terms of service. If something material changes — a new recipient of data, different retention — it will show in a new date below.