NanoGPT Privacy Policy
Last Updated: August 15, 2026
Effective for new users: August 15, 2026
Effective for existing users: September 14, 2026
NanoGPT LLC ("NanoGPT," "we," "us," or "our") is committed to protecting your privacy and ensuring the security of your personal information. Our policy is to collect and store only the minimum information necessary to provide our services.
This Privacy Policy describes our practices regarding information we collect from or about you when you use our website, platform, services, and features, including all associated software applications (collectively, "Services").
If you first use the Services on or after August 15, 2026, this Privacy Policy applies when you first use the Services. If you used the Services before that date, the prior Privacy Policy continues to apply through September 13, 2026, and this version applies beginning September 14, 2026. You may request a copy of the prior Privacy Policy at support@nanogpt.com.
Scope
This Privacy Policy applies to personal information collected through:
- Our website and any webpages that link to this Privacy Policy;
- Our applications, features, and services (including APIs) that link to this Privacy Policy;
- Interactions with third-party sites or services where our Services are embedded and link to this Privacy Policy.
Capitalized terms not defined in this Privacy Policy have the meanings given in our Terms of Service.
Personal information we collect
We collect very limited personal information when you use our Services, communicate with us, or create an account. We do not sell personal information and we do not use personal information for targeted advertising. Our commitment is to never sell or share your information for advertising purposes and not to use any shared information to infer characteristics about users.
- Account Information: If you choose to create an account, we collect your email address, and may also store your name, profile image, a hashed version of your password, passkey (WebAuthn) credential handles, and two-factor authentication settings. This information is necessary to provide login, authentication, and account security features. You can also use our services without creating an account by using an anonymous session. We support multiple authentication methods, including email and password, Google OAuth, GitHub OAuth, and WebAuthn/passkeys. When you sign in via Google or GitHub, we receive limited profile information (such as your name, email, and profile image) from those providers in accordance with their privacy policies.
- Payment Information: When you make payments, we use third-party payment processors. For credit or debit card payments we use Stripe as our payment processor. While we never see or store your credit card data, Stripe collects and stores certain personal information related to your payment transactions. This information is subject to Stripe's privacy policy and data retention practices and we are unable to remove this ourselves. You can request deletion of your personal information directly from Stripe by visiting their data deletion request page. For cryptocurrency or other payment methods, we may use processors such as BTCPay Server, Nanswap, or BoomFi; these providers may collect and process transaction details (such as wallet addresses, transaction identifiers, and amounts) under their own privacy policies. We receive limited transaction metadata to credit your account.
- Communication Information: If you communicate with us, we may collect your name, contact information, and the contents of your messages to the extent that you choose to share these details with us.
- Social Media Information: When you interact with our pages on third-party sites like X and Discord, we may collect information you choose to provide, such as your contact details.
Information Related to Your Use of the Services
We minimize data collection and avoid linking it to your IP address wherever possible:
- Prompts and Conversations: By default, we do NOT store prompt or conversation content on our servers. If you enable optional features such as conversation sync or sharing, we store the necessary content (encrypted where applicable) so those features can work.
- Optional API Request Logging and Support Debugging: API-key owners may opt in to encrypted storage of new /v1/chat/completions request and response bodies in private object storage for a selected retention period of 1 to 30 days. The database retains the associated ownership, consent, request metadata, expiry, encryption reference, and opaque object key rather than the captured body. These private request logs are off by default and are available to the API-key owner. A separate, off-by-default setting allows authorized NanoGPT staff to inspect only logs captured while that support-access setting is enabled for debugging and support. This permission does not authorize model training or general product-improvement use. Turning support access off immediately revokes staff access to retained logs without deleting the owner's private copies; disabling request logging or clearing logs deletes the stored copies.
- Responses API: Our OpenAI-compatible Responses API can store request and response data encrypted (AES-256-GCM) to support conversation threading, response retrieval, and background processing. When Responses API storage is enabled, stored records are retained for up to 7 days by default, and data is automatically deleted after expiration. You can set the store parameter to false to disable local Responses API storage for a request. When storage is enabled, retention is configurable per request with retentionDays or retention_days from 0 to 365 days; setting retention to 0 disables retention for that request. User and team default retention settings are also available through API endpoints. See the Responses API retention documentation for the exact request fields and settings APIs. You may also provide your own encryption key (via the X-Encryption-Key header) for customer-managed encryption at rest. This key is provided with API requests and used server-side to encrypt/decrypt stored responses, and is not persisted by us.
- Optional PII Redaction: If you enable PII redaction, we route the relevant request and response content through Grepture before forwarding to the selected model provider and before returning the response to you. This feature is for private information inside prompts, messages, context, and responses; we normally do not attach your NanoGPT account name, email, or other account metadata to model-provider requests. Grepture receives the request and response content necessary to detect, mask, and restore supported PII categories, and may process operational metadata and traffic-log data as described in Grepture's Privacy Policy. Grepture's subprocessors are listed on its Subprocessors page, and further company information is available in Grepture's Impressum.
- Memory & Global Memory Sync: Memory is disabled by default. If enabled, Global Memory items are stored in your browser until you explicitly enable sync. Recoverable sync encrypts stored snapshots but NanoGPT infrastructure can decrypt them; it is not zero-knowledge. Passphrase mode encrypts snapshots in your browser before upload, and NanoGPT cannot read or recover those contents. You can view, edit, disable, delete, or clear memory. The default remote suggestion analyzer uses a TEE-backed provider route, but your browser sends the analyzed excerpts to NanoGPT in plaintext before NanoGPT forwards them; this is not browser-to-enclave Private Mode. A custom remote analyzer may not use a TEE. The optional local browser analyzer keeps analysis on the device, but saved memory may still be sent to the chat model when Memory is used. Saved items remain stored until you delete or clear them; disabled or expired items are excluded from active use but may remain stored. Capacity is configurable in Memory settings.
- Google Drive Integration: If you use our Google Drive import feature, we request read-only access to your Google Drive files through Google OAuth. We download only the file you select and copy it to NanoGPT-managed object storage or your configured Bring Your Own Storage bucket so it can be attached to a request. No single maximum retention period applies to these stored copies. Removing an item from your local library or deleting your account does not necessarily delete the remote object immediately; content in your own bucket remains subject to the storage lifecycle you configure. Your use of Google Drive is also subject to Google's Privacy Policy.
- AI Detection and Plagiarism Checks: If you use our AI detection or plagiarism checking features, we send the text you submit to Pangram so it can process the detection request and return a report. Pangram processes that text under its own privacy policy and terms.
- CAPTCHA Verification: When you attempt to claim free Nano, we use Cloudflare Turnstile to verify that you are a human. Cloudflare may process your IP address and browser information as part of this verification. This data is subject to Cloudflare's Privacy Policy.
- IP Addresses: Our hosting and security systems necessarily process your IP address when you connect. NanoGPT does not attach IP addresses to prompts, model-provider requests, usage records, support tickets, or bug reports. Our application uses raw IP addresses temporarily in rate-limit and abuse-prevention systems, where they are automatically deleted after the relevant security window expires. Retention varies by control, and we do not publish individual thresholds because doing so could weaken those protections. Password-reset abuse protection may also store a keyed one-way identifier derived from an IP address as a separate security record. We do not intentionally write raw IP addresses into application log messages. Vercel, our hosting provider, separately processes network information such as IP addresses under its Privacy Policy; because Vercel does not publish a single IP-specific retention period covering all infrastructure records, we do not claim a fixed duration for Vercel's independent processing.
- Usage Data: We do not link any usage data to your IP address.
Image, Audio, Video, and Potential Biometric Processing
Some models accept or generate images, audio, or video and may perform processing that is regulated as biometric processing in some jurisdictions. Depending on the model and feature, this may include voice cloning or voice conversion, speaker identification, voice-preserving translation, face cloning, face transformation, or analysis of facial or vocal characteristics. A Model Provider may extract or generate data such as voiceprints, voice models, face geometry, or faceprints to fulfill the request.
When you use these features, NanoGPT transmits the media and related instructions to the Model Provider selected for the request. The Model Provider's handling, retention, and use of that data is governed by its own terms and privacy practices. NanoGPT's own storage of submitted or generated media follows the feature-specific storage and retention practices described in this Privacy Policy, including optional storage, sharing, sync, and Responses API features.
NanoGPT does not itself sell submitted media or biometric data and does not use them to train models. Any separate rights or practices of a Model Provider are governed by that provider's terms and privacy policy.
If media contains another identifiable person, you must provide any legally required notice and obtain all rights, permissions, consents, and other lawful bases required to submit the media and use the selected feature. You must not submit another person's image, likeness, or voice for cloning, identification, or other biometric processing without that person's informed consent where consent is required by law.
We may collect limited product telemetry (for example, aggregate counts of how often certain interface features are used, such as quick-reply buttons) to evaluate feature usefulness and improve the service. For this telemetry, we use an in-house first-party system rather than third-party analytics tools for privacy reasons. This telemetry is aggregate-focused and does not include message content.
Outside of those optional content storage features, the only information we actively store for standard usage is metadata about prompt requests, such as input and output token counts, the model used, the cost we charged, any discounts applied, whether web search was used (for billing), whether memory was used (for billing), and the timestamp of the request. If you enable conversation sync or sharing, we also store encrypted snapshots that include the prompt content itself. This metadata is what powers the Usage page (entries are derived from timestamps, models, and token counts/costs).
Our platform uses your local browser storage to hold settings and conversation history. We also use a session cookie that contains a signed session identifier (and optional security flags, such as pending 2FA) so we can retrieve your session and balance from our servers. If you arrive via a referral or campaign link, we may set a referral/source cookie to attribute signups or payments. If you enable conversation sync, encrypted snapshots are stored in our cloud storage (or your own storage if you configure it), and you can delete them at any time. If you share a conversation, we store a share snapshot (encrypted if you choose) for the retention period you select so the link can work.
How we use personal information
We may use Personal Information explicitly provided to us for the following purposes:
- To process your payments and update your account balance;
- To communicate with you about our Services and events;
- To review, route, and respond to bug reports and suggestions you submit;
- To prevent fraud, unlawful activity, abuse, and misuse of the Services, and to protect the security and integrity of our systems;
- To comply with legal obligations and protect our rights, privacy, safety, or property, and/or that of our affiliates, you, or other third parties.
Disclosure of personal information
We may provide your Personal Information to third parties in the following limited circumstances:
- Service Providers: When you submit a prompt, it is passed directly to the relevant service provider (such as OpenAI, Anthropic, Sakana AI, or another LLM provider). While we do not store prompt or conversation content by default (unless you enable optional features like conversation sync or sharing), these service providers may store and process this information according to their own privacy policies. If you provide personal information within the prompts that you send, these service providers will have access to this personal information. We enforce a minimum-retention and maximum-deletion posture across all model providers we onboard, including applying the strictest retention and deletion settings each provider makes available to us. However, providers operate their own infrastructure and may still retain data under their own legal obligations and privacy policies. For credit card processing, we use Stripe, which collects and processes payment information according to their own privacy policy.
- Messaging & Notification Tools: To help our team respond quickly, bug reports and suggestions you submit through our website may be forwarded to internal messaging services (such as Discord) and may include the content you choose to provide.
- Important Note on Provider Data Policies: While we only send prompts to the providers that we use, without sending along your IP or any other identifying personal information other than that which you yourself put into the prompt, keep in mind that our providers may still collect or store these prompts under their own data retention practices. We require minimum retention and maximum deletion controls across all providers we use, but we cannot independently guarantee provider-side non-retention beyond each provider's stated commitments. This also applies to routes labeled Zero Data Retention: ZDR is a best-effort routing classification based on the provider's claim, not independent visibility into or verification of its servers and internal setup.
- Exercise caution and avoid submitting personal or sensitive information in your prompts, especially when using models from providers with indefinite data retention policies.
- Legal Requirements: We may share limited Personal Information if required by law or to protect our rights and the safety of our users.
Aggregated and De-identified Information
We may process information in aggregated or de-identified form so it cannot reasonably be used to identify you. We use this information to:
- Analyze and improve the performance and reliability of our Services;
- Understand usage trends and feature preferences;
- Publish or share high-level statistics about our Services.
Your rights
Depending on location, individuals may have certain statutory rights in relation to their Personal Information. For example, you may have the right to:
- Access your Personal Information and information relating to how it is processed.
- Delete your Personal Information from our records.
- Rectify or update your Personal Information.
- Transfer your Personal Information to a third party (right to data portability).
- Restrict how we process your Personal Information.
- Withdraw your consent where we rely on consent as the legal basis for processing at any time.
- Object to how we process your Personal Information.
- Lodge a complaint with your local data protection authority.
Children
Our Services are not directed to or intended for anyone under 18, and you must be at least 18 to use them. If we learn that we have collected personal information from someone under 18, we will take reasonable steps to delete it and prevent further use of the Services.
Security and Retention
We implement commercially reasonable administrative, technical, and physical safeguards designed to protect your Personal Information. For cloud storage of media and user-uploaded content, we use Amazon Web Services (AWS) S3. Data stored in AWS is subject to AWS's Privacy Notice. However, no Internet transmission is ever fully secure. We retain Personal Information only for as long as necessary to provide our Services or comply with legal obligations.
The safety and security of your information also depends on you. If you use a password to access any part of our Services, you are responsible for keeping it confidential and for not sharing it with anyone.
Third-Party Services
Our Services may link to or integrate with third-party websites, applications, or services. This Privacy Policy does not apply to those third parties, and we are not responsible for their privacy practices. Please review the applicable privacy policies of any third-party services you use.
- Web Search & Browsing Providers: Linkup Privacy Policy, Tavily Privacy Policy, Exa Privacy Policy, Kagi Privacy Policy, Brave Search Privacy Notice, Perplexity Privacy Policy, Valyu Privacy Policy.
- Audio & Media Generation: Some audio, image, and video generation features use third-party providers (such as FAL AI, Runware, WaveSpeed, and Replicate) to process prompts or media inputs and return outputs. Data shared with these providers is subject to their respective privacy policies: FAL AI Privacy Policy, Runware Privacy Policy, WaveSpeed Privacy Policy, Replicate Privacy Policy.
- Content Extraction & Transcripts: Firecrawl Privacy Policy, YouTube Transcript Privacy Policy.
- AI Detection & Plagiarism Checks: Pangram Privacy Policy.
- PII Redaction: Grepture Privacy Policy, Grepture Terms of Service, Grepture Subprocessors, and Grepture Impressum.
- Payment Providers: Stripe Privacy Policy, BTCPay Server Privacy Policy, Nanswap Privacy Policy, BoomFi Privacy Policy.
Changes to this Privacy Policy
We may update this Privacy Policy from time to time. We will post the updated Privacy Policy on this page and update the "Last Updated" date above. If we make material changes to how we collect, use, or disclose personal information, or to rights described in this Privacy Policy, we will provide account holders at least 30 days' advance notice by email or an in-product notification when we have valid contact information. We may make changes effective sooner when reasonably necessary to comply with law or address an urgent security, safety, or abuse issue.
How to contact us
If you have any questions or concerns about this Privacy Policy, please contact our NanoGPT Support Team at support@nanogpt.com.
List of AI Model Providers Terms
AI Model Provider Terms: When using our Services, depending on which model is used, you agree to abide by the terms of the respective AI model providers:
- 01.AI: If you use 01.AI models, you agree to abide by the 01.AI terms.
- AI21: If you use AI21 models, you agree to abide by the AI21 privacy policy.
- AionLabs: If you use AionLabs models, you agree to abide by the AionLabs terms.
- Alibaba: If you use Alibaba models, you agree to abide by the Alibaba Cloud terms.
- Amazon Bedrock: If you use Amazon Bedrock models, you agree to abide by the AWS Service terms.
- Ambient: If you use Ambient models, you agree to abide by the Ambient terms of service, Ambient privacy policy, and Ambient data handling policy.
- AtlasCloud: If you use AtlasCloud models, you agree to abide by the AtlasCloud privacy policy.
- Baseten: If you use Baseten models, you agree to abide by the Baseten terms of service and Baseten privacy policy.
- Baidu: If you use Baidu models, you agree to abide by the Baidu AI terms.
- Anthropic: If you use Anthropic models, you agree to abide by the Anthropic usage terms.
- Arcee AI: If you use Arcee AI models, you agree to abide by the Arcee AI privacy policy.
- Arli AI: If you use Arli AI models, you agree to abide by the Arli AI terms.
- Azure: If you use Azure models, you agree to abide by the Microsoft terms of use.
- Chutes: If you use Chutes models, you agree to abide by the Chutes terms.
- Cerebras: If you use Cerebras models, you agree to abide by the Cerebras privacy policy.
- Celeris: If you use Celeris models, your request and response content is processed under the Celeris privacy policy and Celeris terms of service.
- Pokee: If you use Pokee-Isaac, your request and response content is processed under the Pokee privacy policy and Pokee terms of service. Pokee states that developer API prompts and outputs are not used for training. Its infrastructure provider retains an approximately 120-character preview of each message for 1 day and stores the encrypted raw request payload for up to 7 days before automatic deletion.
- Cohere: If you use Cohere models, you agree to abide by the Cohere terms of use.
- CoreWeave: If you use CoreWeave-routed models, you agree to abide by the CoreWeave Terms of Service, Data Processing Agreement, and Privacy Policy.
- CrofAI: If you use CrofAI models, you agree to abide by the CrofAI terms of service and CrofAI privacy policy.
- DeepInfra: If you use DeepInfra models, you agree to abide by the DeepInfra terms.
- DeepSeek: If you use DeepSeek models, you agree to abide by the DeepSeek terms of use.
- DigitalOcean: If you use DigitalOcean models, you agree to abide by the DigitalOcean Privacy Policy and DigitalOcean Terms of Service.
- Modal: If you use Modal models, you agree to abide by the Modal privacy policy and Modal terms of service.
- DMind: If you use DMind models, you agree to abide by the DMind privacy policy.
- Doubao: If you use Doubao models, you agree to abide by the Doubao terms.
- FAL: If you use FAL models, you agree to abide by the FAL terms of service.
- Featherless: If you use Featherless models, you agree to abide by the Featherless terms.
- RouteCortex: If a model request is routed through RouteCortex, its request and response content is processed under the RouteCortex privacy policy and terms of service. RouteCortex states that prompts and completions are processed in memory and are not logged.
- Fireworks: If you use Fireworks models, you agree to abide by the Fireworks terms of service.
- Gemini: If you use Gemini models, you agree to abide by the Gemini usage terms.
- Gerra: If you use Gerra models, you agree to abide by the Gerra privacy policy.
- ZenMux: If a model is routed through ZenMux, your request and response content is processed under the ZenMux privacy policy and ZenMux terms of service. ZenMux does not currently publish a model-API zero-retention or training guarantee, so avoid including sensitive information.
- GMICloud: If you use GMICloud models, you agree to abide by the GMICloud terms and conditions.
- Gondola / Venice: If a model request is routed through Gondola, its request and response content may be processed by Gondola and its Venice upstream under the Gondola privacy policy, Gondola terms of service, Venice privacy policy, and Venice terms of service.
- Google Vertex: If you use Google Vertex AI models, you agree to abide by the Google Cloud terms.
- Google AI Studio: If you use Google AI Studio models, you agree to abide by the Google Cloud terms.
- Groq: If you use Groq models, you agree to abide by the Groq terms of use.
- H Company: If you use H Company models, you agree to abide by the H Company privacy policy.
- Hyperbolic: If you use Hyperbolic models, you agree to abide by the Hyperbolic privacy policy.
- Infermatic: If you use Infermatic models, you agree to abide by the Infermatic privacy policy.
- Inflection: If you use Inflection models, you agree to abide by the Inflection developer terms.
- Inceptron: If you use Inceptron models, you agree to abide by the Inceptron privacy policy and Inceptron terms of service.
- Io Net: If you use Io Net models, you agree to abide by the io.net terms and io.net privacy policy.
- Lilac: If you use Lilac models, you agree to abide by the Lilac privacy policy and Lilac's applicable service terms.
- Mara: If you use Mara models, you agree to abide by the Mara AI policies.
- Minimax: If you use Minimax models, you agree to abide by the Minimax terms of service.
- Mistral: If you use Mistral models, you agree to abide by the Mistral terms of use.
- Mixlayer: If you use Mixlayer models, you agree to abide by the Mixlayer terms of service and Mixlayer privacy policy.
- Moonshot AI: If you use Moonshot AI models, you agree to abide by the Moonshot AI privacy policy.
- MegaNova: If you use MegaNova models, you agree to abide by the MegaNova privacy policy.
- Neuralwatt: If you use Neuralwatt models, you agree to abide by the Neuralwatt terms of service and Neuralwatt privacy policy.
- NovitaAI: If you use NovitaAI models, you agree to abide by the NovitaAI terms of service.
- Ollama: If you use Ollama models, you agree to abide by the Ollama Cloud terms and privacy policy.
- Meta: If you use Meta Llama models, you agree to abide by the Meta privacy policy.
- OpenAI: If you use OpenAI models, you agree to abide by the OpenAI usage terms.
- Pangram: If you use Pangram AI detection or plagiarism checking, you agree to abide by the Pangram privacy policy and Pangram terms of service.
- Perplexity: If you use Perplexity models, you agree to abide by the Perplexity usage terms.
- Phala: If you use Phala models, you agree to abide by the Phala Cloud privacy policy and Phala Cloud terms.
- Poe: If you use Poe models, you agree to abide by the Poe terms of service and Poe privacy policy.
- PolyChat: If you use PolyChat models, you agree to abide by the PolyChat privacy policy.
- Poolside: If you use Poolside models, you agree to abide by the Poolside privacy policy.
- Replicate: If you use Replicate models, you agree to abide by the Replicate terms.
- SambaNova: If you use SambaNova models, you agree to abide by the SambaNova terms and conditions.
- Sakana AI (Fugu): If you use Sakana AI or Fugu models, you agree to abide by the Fugu Privacy Policy, Sakana Fugu Terms of Service, and Sakana Fugu Usage Policy.
- Sail Research: If you use Sail Research models, you agree to abide by the Sail Research Data Processing Addendum.
- StepFun: If you use StepFun models, you agree to abide by the StepFun privacy policy, StepFun terms of service, and StepFun data processing agreement.
- SiliconFlow: If you use SiliconFlow models, you agree to abide by the SiliconFlow privacy policy.
- StreamLake: If you use StreamLake models, you agree to abide by the StreamLake privacy policy and StreamLake user service agreement.
- TensorX: If you use TensorX models, you agree to abide by the TensorX terms and TensorX privacy policy.
- Together: If you use Together models, you agree to abide by the Together terms of service.
- Uomi: If you use Uomi models, you agree to abide by the Uomi terms of service and Uomi privacy policy.
- Vercel: If you use Vercel models, you agree to abide by the Vercel API Terms and AI Product Terms.
- Wafer: If you use Wafer-routed models, you agree to abide by the Wafer privacy policy, Wafer terms of service, and Wafer's Zero Data Retention commitments where applicable.
- SpaceXAI: If you use SpaceXAI models, you agree to abide by the SpaceXAI Privacy Policy and SpaceXAI Terms of Service.
- Xiaomi: If you use Xiaomi models, you agree to abide by the Xiaomi privacy policy.
- Akash: If you use Akash models, you agree to abide by the Akash privacy policy.
- Fetch AI: If you use Fetch AI models, you agree to abide by the Fetch AI privacy policy.
- Inception: If you use Inception models, you agree to abide by the Inception privacy policy.
- OpenRouter: If you use OpenRouter models, you agree to abide by the OpenRouter privacy policy.
- Parasail: If you use Parasail models, you agree to abide by the Parasail privacy policy.
- Redpill: If you use Redpill models, you agree to abide by the Redpill privacy policy.
- Tinfoil: If you use Tinfoil models, you agree to abide by the Tinfoil privacy policy.
- YouTube Transcript: If you use YouTube Transcript, you agree to abide by the YouTube Transcript privacy policy.
- Firecrawl: If you use Firecrawl, you agree to abide by the Firecrawl privacy policy.
- Runware: If you use Runware models, you agree to abide by the Runware privacy policy.
- WaveSpeed: If you use WaveSpeed models, you agree to abide by the WaveSpeed privacy policy.
- Zai: If you use Zai models, you agree to abide by the Zai privacy policy.