NanoGPT Privacy Policy

Last Updated: August 15, 2026

Effective for new users: August 15, 2026

Effective for existing users: September 14, 2026

NanoGPT LLC ("NanoGPT," "we," "us," or "our") is committed to protecting your privacy and ensuring the security of your personal information. Our policy is to collect and store only the minimum information necessary to provide our services.

This Privacy Policy describes our practices regarding information we collect from or about you when you use our website, platform, services, and features, including all associated software applications (collectively, "Services").

If you first use the Services on or after August 15, 2026, this Privacy Policy applies when you first use the Services. If you used the Services before that date, the prior Privacy Policy continues to apply through September 13, 2026, and this version applies beginning September 14, 2026. You may request a copy of the prior Privacy Policy at support@nanogpt.com.

Scope

This Privacy Policy applies to personal information collected through:

  • Our website and any webpages that link to this Privacy Policy;
  • Our applications, features, and services (including APIs) that link to this Privacy Policy;
  • Interactions with third-party sites or services where our Services are embedded and link to this Privacy Policy.

Capitalized terms not defined in this Privacy Policy have the meanings given in our Terms of Service.

Personal information we collect

We collect very limited personal information when you use our Services, communicate with us, or create an account. We do not sell personal information and we do not use personal information for targeted advertising. Our commitment is to never sell or share your information for advertising purposes and not to use any shared information to infer characteristics about users.

  • Account Information: If you choose to create an account, we collect your email address, and may also store your name, profile image, a hashed version of your password, passkey (WebAuthn) credential handles, and two-factor authentication settings. This information is necessary to provide login, authentication, and account security features. You can also use our services without creating an account by using an anonymous session. We support multiple authentication methods, including email and password, Google OAuth, GitHub OAuth, and WebAuthn/passkeys. When you sign in via Google or GitHub, we receive limited profile information (such as your name, email, and profile image) from those providers in accordance with their privacy policies.
  • Payment Information: When you make payments, we use third-party payment processors. For credit or debit card payments we use Stripe as our payment processor. While we never see or store your credit card data, Stripe collects and stores certain personal information related to your payment transactions. This information is subject to Stripe's privacy policy and data retention practices and we are unable to remove this ourselves. You can request deletion of your personal information directly from Stripe by visiting their data deletion request page. For cryptocurrency or other payment methods, we may use processors such as BTCPay Server, Nanswap, or BoomFi; these providers may collect and process transaction details (such as wallet addresses, transaction identifiers, and amounts) under their own privacy policies. We receive limited transaction metadata to credit your account.
  • Communication Information: If you communicate with us, we may collect your name, contact information, and the contents of your messages to the extent that you choose to share these details with us.
  • Social Media Information: When you interact with our pages on third-party sites like X and Discord, we may collect information you choose to provide, such as your contact details.

Information Related to Your Use of the Services

We minimize data collection and avoid linking it to your IP address wherever possible:

  • Prompts and Conversations: By default, we do NOT store prompt or conversation content on our servers. If you enable optional features such as conversation sync or sharing, we store the necessary content (encrypted where applicable) so those features can work.
  • Optional API Request Logging and Support Debugging: API-key owners may opt in to encrypted storage of new /v1/chat/completions request and response bodies in private object storage for a selected retention period of 1 to 30 days. The database retains the associated ownership, consent, request metadata, expiry, encryption reference, and opaque object key rather than the captured body. These private request logs are off by default and are available to the API-key owner. A separate, off-by-default setting allows authorized NanoGPT staff to inspect only logs captured while that support-access setting is enabled for debugging and support. This permission does not authorize model training or general product-improvement use. Turning support access off immediately revokes staff access to retained logs without deleting the owner's private copies; disabling request logging or clearing logs deletes the stored copies.
  • Responses API: Our OpenAI-compatible Responses API can store request and response data encrypted (AES-256-GCM) to support conversation threading, response retrieval, and background processing. When Responses API storage is enabled, stored records are retained for up to 7 days by default, and data is automatically deleted after expiration. You can set the store parameter to false to disable local Responses API storage for a request. When storage is enabled, retention is configurable per request with retentionDays or retention_days from 0 to 365 days; setting retention to 0 disables retention for that request. User and team default retention settings are also available through API endpoints. See the Responses API retention documentation for the exact request fields and settings APIs. You may also provide your own encryption key (via the X-Encryption-Key header) for customer-managed encryption at rest. This key is provided with API requests and used server-side to encrypt/decrypt stored responses, and is not persisted by us.
  • Optional PII Redaction: If you enable PII redaction, we route the relevant request and response content through Grepture before forwarding to the selected model provider and before returning the response to you. This feature is for private information inside prompts, messages, context, and responses; we normally do not attach your NanoGPT account name, email, or other account metadata to model-provider requests. Grepture receives the request and response content necessary to detect, mask, and restore supported PII categories, and may process operational metadata and traffic-log data as described in Grepture's Privacy Policy. Grepture's subprocessors are listed on its Subprocessors page, and further company information is available in Grepture's Impressum.
  • Memory & Global Memory Sync: Memory is disabled by default. If enabled, Global Memory items are stored in your browser until you explicitly enable sync. Recoverable sync encrypts stored snapshots but NanoGPT infrastructure can decrypt them; it is not zero-knowledge. Passphrase mode encrypts snapshots in your browser before upload, and NanoGPT cannot read or recover those contents. You can view, edit, disable, delete, or clear memory. The default remote suggestion analyzer uses a TEE-backed provider route, but your browser sends the analyzed excerpts to NanoGPT in plaintext before NanoGPT forwards them; this is not browser-to-enclave Private Mode. A custom remote analyzer may not use a TEE. The optional local browser analyzer keeps analysis on the device, but saved memory may still be sent to the chat model when Memory is used. Saved items remain stored until you delete or clear them; disabled or expired items are excluded from active use but may remain stored. Capacity is configurable in Memory settings.
  • Google Drive Integration: If you use our Google Drive import feature, we request read-only access to your Google Drive files through Google OAuth. We download only the file you select and copy it to NanoGPT-managed object storage or your configured Bring Your Own Storage bucket so it can be attached to a request. No single maximum retention period applies to these stored copies. Removing an item from your local library or deleting your account does not necessarily delete the remote object immediately; content in your own bucket remains subject to the storage lifecycle you configure. Your use of Google Drive is also subject to Google's Privacy Policy.
  • AI Detection and Plagiarism Checks: If you use our AI detection or plagiarism checking features, we send the text you submit to Pangram so it can process the detection request and return a report. Pangram processes that text under its own privacy policy and terms.
  • CAPTCHA Verification: When you attempt to claim free Nano, we use Cloudflare Turnstile to verify that you are a human. Cloudflare may process your IP address and browser information as part of this verification. This data is subject to Cloudflare's Privacy Policy.
  • IP Addresses: Our hosting and security systems necessarily process your IP address when you connect. NanoGPT does not attach IP addresses to prompts, model-provider requests, usage records, support tickets, or bug reports. Our application uses raw IP addresses temporarily in rate-limit and abuse-prevention systems, where they are automatically deleted after the relevant security window expires. Retention varies by control, and we do not publish individual thresholds because doing so could weaken those protections. Password-reset abuse protection may also store a keyed one-way identifier derived from an IP address as a separate security record. We do not intentionally write raw IP addresses into application log messages. Vercel, our hosting provider, separately processes network information such as IP addresses under its Privacy Policy; because Vercel does not publish a single IP-specific retention period covering all infrastructure records, we do not claim a fixed duration for Vercel's independent processing.
  • Usage Data: We do not link any usage data to your IP address.

Image, Audio, Video, and Potential Biometric Processing

Some models accept or generate images, audio, or video and may perform processing that is regulated as biometric processing in some jurisdictions. Depending on the model and feature, this may include voice cloning or voice conversion, speaker identification, voice-preserving translation, face cloning, face transformation, or analysis of facial or vocal characteristics. A Model Provider may extract or generate data such as voiceprints, voice models, face geometry, or faceprints to fulfill the request.

When you use these features, NanoGPT transmits the media and related instructions to the Model Provider selected for the request. The Model Provider's handling, retention, and use of that data is governed by its own terms and privacy practices. NanoGPT's own storage of submitted or generated media follows the feature-specific storage and retention practices described in this Privacy Policy, including optional storage, sharing, sync, and Responses API features.

NanoGPT does not itself sell submitted media or biometric data and does not use them to train models. Any separate rights or practices of a Model Provider are governed by that provider's terms and privacy policy.

If media contains another identifiable person, you must provide any legally required notice and obtain all rights, permissions, consents, and other lawful bases required to submit the media and use the selected feature. You must not submit another person's image, likeness, or voice for cloning, identification, or other biometric processing without that person's informed consent where consent is required by law.

We may collect limited product telemetry (for example, aggregate counts of how often certain interface features are used, such as quick-reply buttons) to evaluate feature usefulness and improve the service. For this telemetry, we use an in-house first-party system rather than third-party analytics tools for privacy reasons. This telemetry is aggregate-focused and does not include message content.

Outside of those optional content storage features, the only information we actively store for standard usage is metadata about prompt requests, such as input and output token counts, the model used, the cost we charged, any discounts applied, whether web search was used (for billing), whether memory was used (for billing), and the timestamp of the request. If you enable conversation sync or sharing, we also store encrypted snapshots that include the prompt content itself. This metadata is what powers the Usage page (entries are derived from timestamps, models, and token counts/costs).

Our platform uses your local browser storage to hold settings and conversation history. We also use a session cookie that contains a signed session identifier (and optional security flags, such as pending 2FA) so we can retrieve your session and balance from our servers. If you arrive via a referral or campaign link, we may set a referral/source cookie to attribute signups or payments. If you enable conversation sync, encrypted snapshots are stored in our cloud storage (or your own storage if you configure it), and you can delete them at any time. If you share a conversation, we store a share snapshot (encrypted if you choose) for the retention period you select so the link can work.

How we use personal information

We may use Personal Information explicitly provided to us for the following purposes:

  • To process your payments and update your account balance;
  • To communicate with you about our Services and events;
  • To review, route, and respond to bug reports and suggestions you submit;
  • To prevent fraud, unlawful activity, abuse, and misuse of the Services, and to protect the security and integrity of our systems;
  • To comply with legal obligations and protect our rights, privacy, safety, or property, and/or that of our affiliates, you, or other third parties.

Disclosure of personal information

We may provide your Personal Information to third parties in the following limited circumstances:

  • Service Providers: When you submit a prompt, it is passed directly to the relevant service provider (such as OpenAI, Anthropic, Sakana AI, or another LLM provider). While we do not store prompt or conversation content by default (unless you enable optional features like conversation sync or sharing), these service providers may store and process this information according to their own privacy policies. If you provide personal information within the prompts that you send, these service providers will have access to this personal information. We enforce a minimum-retention and maximum-deletion posture across all model providers we onboard, including applying the strictest retention and deletion settings each provider makes available to us. However, providers operate their own infrastructure and may still retain data under their own legal obligations and privacy policies. For credit card processing, we use Stripe, which collects and processes payment information according to their own privacy policy.
  • Messaging & Notification Tools: To help our team respond quickly, bug reports and suggestions you submit through our website may be forwarded to internal messaging services (such as Discord) and may include the content you choose to provide.
  • Important Note on Provider Data Policies: While we only send prompts to the providers that we use, without sending along your IP or any other identifying personal information other than that which you yourself put into the prompt, keep in mind that our providers may still collect or store these prompts under their own data retention practices. We require minimum retention and maximum deletion controls across all providers we use, but we cannot independently guarantee provider-side non-retention beyond each provider's stated commitments. This also applies to routes labeled Zero Data Retention: ZDR is a best-effort routing classification based on the provider's claim, not independent visibility into or verification of its servers and internal setup.
  • Exercise caution and avoid submitting personal or sensitive information in your prompts, especially when using models from providers with indefinite data retention policies.
  • Legal Requirements: We may share limited Personal Information if required by law or to protect our rights and the safety of our users.

Aggregated and De-identified Information

We may process information in aggregated or de-identified form so it cannot reasonably be used to identify you. We use this information to:

  • Analyze and improve the performance and reliability of our Services;
  • Understand usage trends and feature preferences;
  • Publish or share high-level statistics about our Services.

Your rights

Depending on location, individuals may have certain statutory rights in relation to their Personal Information. For example, you may have the right to:

  • Access your Personal Information and information relating to how it is processed.
  • Delete your Personal Information from our records.
  • Rectify or update your Personal Information.
  • Transfer your Personal Information to a third party (right to data portability).
  • Restrict how we process your Personal Information.
  • Withdraw your consent where we rely on consent as the legal basis for processing at any time.
  • Object to how we process your Personal Information.
  • Lodge a complaint with your local data protection authority.

Children

Our Services are not directed to or intended for anyone under 18, and you must be at least 18 to use them. If we learn that we have collected personal information from someone under 18, we will take reasonable steps to delete it and prevent further use of the Services.

Security and Retention

We implement commercially reasonable administrative, technical, and physical safeguards designed to protect your Personal Information. For cloud storage of media and user-uploaded content, we use Amazon Web Services (AWS) S3. Data stored in AWS is subject to AWS's Privacy Notice. However, no Internet transmission is ever fully secure. We retain Personal Information only for as long as necessary to provide our Services or comply with legal obligations.

The safety and security of your information also depends on you. If you use a password to access any part of our Services, you are responsible for keeping it confidential and for not sharing it with anyone.

Third-Party Services

Our Services may link to or integrate with third-party websites, applications, or services. This Privacy Policy does not apply to those third parties, and we are not responsible for their privacy practices. Please review the applicable privacy policies of any third-party services you use.

Changes to this Privacy Policy

We may update this Privacy Policy from time to time. We will post the updated Privacy Policy on this page and update the "Last Updated" date above. If we make material changes to how we collect, use, or disclose personal information, or to rights described in this Privacy Policy, we will provide account holders at least 30 days' advance notice by email or an in-product notification when we have valid contact information. We may make changes effective sooner when reasonably necessary to comply with law or address an urgent security, safety, or abuse issue.

How to contact us

If you have any questions or concerns about this Privacy Policy, please contact our NanoGPT Support Team at support@nanogpt.com.

List of AI Model Providers Terms

AI Model Provider Terms: When using our Services, depending on which model is used, you agree to abide by the terms of the respective AI model providers: