Privacy policy

Last updated 2026-09-27

Cyberdeck is built to know as little about you as possible. This policy lists everything the operator of Cyberdeck ("we") stores, for how long, and what we deliberately do not collect. If this page and the service ever disagree, contact us at https://t.me/Cyberdeck_support.

Summary

  • No email, phone number, name or payment card is ever requested.
  • We do not store plaintext prompts or answers, your IP address or your browser details.
  • Personal history stays in your browser. Explicitly shared team history is stored as encrypted snapshots.
  • Messages are processed by third-party inference infrastructure that runs the models. It sees message content while generating the answer; its published policy is not to retain it.
  • Optional web search is off by default. Enabling it lets the model derive queries from your question and recent context and sends those queries to external search infrastructure; retrieved snippets are then sent to the model.

What we store

DataWhyKept for
Keyed hash (HMAC-SHA256) of your account key — never the key itselfLogging you inUntil you delete the account
Plan, plan expiry, start of the current credit cycleProviding your subscription, including redeemed giveawaysUntil you delete the account
Account creation date and last active date (calendar day, UTC — no time of day)Removing abandoned free accountsFree accounts without unspent pack credits are deleted after 180 days without activity
Keyed hashes of session tokens, with an expiryKeeping you logged in30 days, or until you log out
Keyed hashes of API keys, the first characters of each key, the name you gave it, creation dayAuthenticating API requests; letting you recognise and revoke keysUntil you revoke the key or delete the account
Keyed hashes of pending CAPTCHA challenges and one-use signup tokens, with work requirement and expiry — no account link, IP or browser detailsPreventing automated signup bursts and replay, including after a restartDeleted on successful use; validity is 3 minutes for challenges and 2 minutes for signup tokens. Expired records are cleared on signup activity or the next scheduled cleanup, within six hours while the service is running.
Aggregate successful-signup counts by minute, including the total from unattributed clients such as Tor — no individual identifiersAdapting signup work and limiting anonymous signup burstsA rolling 60–61 minute window; older counts are cleared on signup activity or the next scheduled cleanup, within six hours while the service is running.
Total credits used per account per calendar day (UTC), including budgets reserved by active requestsEnforcing plan limits35 days; older totals needed by an unfinished funding receipt remain until settlement or recovery
Temporary inference/search funding receipt: random receipt ID, account/lender IDs, UTC day and reserved/observed credit amounts — no content or exact request timePreventing concurrent overspending and refunding unused budgets after failuresUntil settlement, or recovery at the next server startup after an interruption; related daily totals are retained until then if needed for a correct refund
If you use a team: which accounts are in it, the nickname the owner gives you, your borrow cap, and credits you drew from teammates per dayPooling credits; members see plan and credit totals. Personal chats are not shared automatically.Membership until you leave or the team is disbanded; daily totals 35 days, except those needed by an unfinished funding receipt
Optional shared chats: encrypted titles, instructions, messages, search queries/source snapshots and branch links; public key fingerprint, team/chat IDs, revisions, update times and ciphertext sizesSharing history between authenticated team members who hold the browser-generated keyUntil a member deletes the snapshot, the team is disbanded or the owner's account is deleted; leaving a team does not delete its history
Payment records linked to your account: payment method, plan, number of months, USD amount, status; for BTCPay its invoice id; for stablecoins our receiving address, the exact amount requested, the payment window and the paying transaction hashActivating a plan once the payment confirms30 days after the invoice is paid, expired or invalid
Giveaway-code HMACs, issued plans, batch identifiers, creation/activation deadlines, redemption or revocation times and the redeeming account linkApplying the issued free subscription cycle once and limiting each account to one code per giveaway batchUntil the activation deadline and the next cleanup, within six hours while running. Deleting the account removes its link without making the code usable again.

The records above are also included in database backups, which are kept for up to 7 days longer than the periods shown and then deleted. Shared-chat payloads remain encrypted in these backups.

The operator keeps a private issuance file to distribute giveaway codes. It contains the codes, not account IDs or conversation data; the database stores only their keyed hashes. Issuance files are managed separately by the operator and are not automatically erased by database cleanup. Codes cannot activate a plan after their deadline.

What we do not store

  • Plaintext prompts, pasted content, model outputs, web-search queries or retrieved snippets. Shared-history storage contains ciphertext instead.
  • IP addresses, user agents, device fingerprints, or a history linking accounts to individual inference timestamps. Shared snapshots have update times.
  • Access logs. Our web server is configured without access logging. For rate limiting, IP addresses are hashed with a random key that exists only in memory and is replaced every time the service restarts; they are never written to disk.
  • Analytics, tracking pixels, third-party scripts, fonts or CDNs. Every file is served from our own server.

Operational incident notices contain service/model identifiers, an error category, a check time and account-health information such as the provider's prepaid balance. They contain no user/account identifiers, prompts or answers. They may be written to operational logs or delivered to the operator's notification service; they are not a chat or request history.

Signup CAPTCHA computation and verification are self-hosted. Its code and WebAssembly files come from our server; no CAPTCHA provider receives your requests, and browser-fingerprinting checks are disabled. It requires JavaScript, Web Workers and WebAssembly for new accounts; existing account-key login does not require it.

Your conversations

Personal conversations live in your browser's IndexedDB. They leave your device for inference, or when you explicitly publish a copy to the team. You can export or delete personal chats from the account page. Clearing browser data permanently deletes local chats — we have no personal-history copy.

Team snapshots are encrypted with AES-256-GCM in your browser, including titles, instructions, messages, reasoning, saved web-search queries and sources, and branch links. The server stores a public fingerprint, not the independent 256-bit team key. The key travels in the secret fragment of an invitation or key link, which is not part of an HTTP request. Save a key link privately: your account key cannot recover it. A new member with the key can read existing team history. All members can edit or delete shared snapshots; private forks stay local until published.

Removing a member blocks subsequent server access and revokes outstanding membership invitations, but it cannot erase previously downloaded content or keys. Keys are not automatically rotated. Encryption protects stored snapshots, not a compromised browser, modified client code, or plaintext processed during inference.

When you send a message, the conversation so far travels over TLS to our server, which forwards it to the inference infrastructure running the model and streams the answer back. Our server holds the text only in memory for the duration of the request.

Third parties

Inference infrastructure

The models run on third-party inference infrastructure selected for privacy: providers whose published policy is not to retain prompts or outputs, and not to use them for training. Like most infrastructure providers, they reserve the right to inspect traffic for operational and abuse-prevention purposes. Language models need the plain text of your conversation to generate an answer, so that text is processed on hardware we do not own. We send it without your account key, IP address or any identifier, but we cannot technically verify what a provider does with the requests it processes. Do not send information you could not accept an infrastructure provider theoretically seeing.

Model names shown in the service (for example Specter and Quill) are our service names for open-weight or provider models; we choose and may change the model behind each name.

Optional web search

Search is off by default for each reply. If you enable it, the model derives one or more queries from your question and bounded recent conversation context. These generated queries travel through our server to external search infrastructure. We do not forward your account key, IP address or raw conversation history to that search service, but generated queries may contain details from your messages. Do not enable search for sensitive content. Retrieved snippets and source URLs are sent to the inference provider as context for your answer.

The configured search route is selected for a published zero-data-retention policy. This is a provider policy, not end-to-end encryption, and we cannot independently verify its enforcement. We keep queries and results in server memory only for the request, without plaintext logs. Saved search snapshots follow the same browser storage, plaintext export and encrypted team-storage rules as messages; saved evidence can be sent again as context in later replies. Opening a source link visits an independent website under its own privacy policy.

Server hosting

Our own server also runs on rented infrastructure. The data listed above lives on it; we keep that list minimal precisely because infrastructure can be compromised or compelled.

Payments

We use no payment processor. When enabled, supported coins go through a BTCPay Server instance we run ourselves; it does not ask for your name, email or address, and we do not tell it which account an invoice belongs to. Enabled stablecoins (USDT, USDC) are sent straight to our own wallet: each payment request has a unique exact amount, and our server recognises your transfer by reading public blockchain data about our address from a blockchain node or API provider. That provider can see public sending addresses and amounts, but we do not send it your account identity. Only our own database links a payment to your account, for the period stated above. Available methods are shown at checkout.

Bitcoin, Lightning and stablecoin transfers are recorded on public ledgers: anyone can see that an address sent a given amount to ours. They are pseudonymous, not anonymous — especially if the sending wallet or exchange account is tied to your identity. Monero offers much stronger privacy and is what we recommend.

Cookies and local storage

We set one cookie: sid, an HttpOnly session cookie that expires after 30 days or when you log out. There are no tracking or advertising cookies. Personal chats and team keys are kept in IndexedDB. Invitation fragments are temporarily kept in sessionStorage across sign-in and removed after joining/unlocking. Your account key is stored in localStorage only if you tick "Remember account key on this device". Logging out does not erase local chats or team keys; use your browser's site-data controls to remove both.

Requests from authorities

We can provide only data we hold, as listed above. We have no stored plaintext conversation archive, team decryption keys or recorded IP history. Message content is nevertheless processed in memory during inference, as described above. We will not secretly add logging for a specific user.

Your controls

  • Export or delete personal chats from Account. Make a private copy of shared history to export it, or delete a shared snapshot from Team chat.
  • Revoke API keys at any time.
  • Delete your account from the account page. This immediately removes the account, its sessions, API keys, usage totals and payment records from our database. Deleting an owner's account disbands its team and deletes shared snapshots; a non-owner's contributions remain with the team. A redeemed giveaway code is unlinked from the account, not restored for reuse. Backups and teammates' copies can remain as described above. Remaining prepaid time is forfeited.

Security

All traffic is encrypted with TLS. Secrets we must recognise (account keys, session tokens, API keys) are stored only as keyed hashes. Because we cannot recover your account key, keep it safe — anyone who has it can use your account.

Age

The service is only for adults (18+). We do not knowingly provide it to anyone younger.

Changes

We will update the date at the top of this page when the policy changes. Material changes that reduce your privacy will be announced on the website before they take effect.

Contact

https://t.me/Cyberdeck_support