Skip to content
Security

Security

What leaves, leaves because you sent it. What stays, you can see.

No name to start.Email, name, and Apple ID are not required. The device makes a random id. The servers know you by that. Sign in with Apple is optional, and that account is not the server key.

Closed on the way.Traffic to our servers is HTTPS. Voice is a TLS websocket. The chat is not end-to-end encrypted: a model you talk to receives the turn.

The host is Cloudflare.Workers, D1, KV, Vectorize. That is where the product lives. The models in the table below are separate. They are not the host.

You can see it.Every mark is yours to read, change, or delete. Export exists. Delete account takes it off the servers.

Nothing sold.No shadow profile, no ad graph, no sale. The product uses PostHog by device id. Not the chat.

Crashes.Sentry gets a stack so the app can be fixed. Message text and marks are not meant to go there. A short device id may.

Who sees a message

A message you send can go to one of these, with the recent chat, the marks, and anything you attached. Each has its own policy. Name, email, and Apple ID do not go with the message.

ProviderUsed for
OpenAIChat · Image generation · Live voice · Speech to text
Google (Gemini)Chat · Image generation · Live voice
Anthropic (Claude)Chat
Kling (Kuaishou)Video generation
Tavily SearchWeb search
CloudflareServers and storage
Apple (APNs)Push delivery · Subscriptions
RevenueCatSubscriptions
GitHubRepository sync
PostHogProduct analytics
SentryCrash reports

List last changed: 2026-08-19

Who can open the servers

Production admin is the founder. Admin routes are locked. Voice, pictures, search, and code can be turned off without a redeploy.

The database is reached through Cloudflare auth on the worker binding. There is no shared database password.

If you found a hole

Write [email protected] with how to reproduce it. I read every report.

The legal wording is in Privacy and Terms.