Privacy policy
Last updated 2026-09-27
Cyberdeck is built to know as little about you as possible. This policy lists everything the operator of Cyberdeck ("we") stores, for how long, and what we deliberately do not collect. If this page and the service ever disagree, contact us at https://t.me/Cyberdeck_support.
Summary
- No email, phone number, name or payment card is ever requested.
- We do not store plaintext prompts or answers, your IP address or your browser details.
- Personal history stays in your browser. Explicitly shared team history is stored as encrypted snapshots.
- Messages are processed by third-party inference infrastructure that runs the models. It sees message content while generating the answer; its published policy is not to retain it.
- Optional web search is off by default. Enabling it lets the model derive queries from your question and recent context and sends those queries to external search infrastructure; retrieved snippets are then sent to the model.
What we store
| Data | Why | Kept for |
|---|---|---|
| Keyed hash (HMAC-SHA256) of your account key — never the key itself | Logging you in | Until you delete the account |
| Plan, plan expiry, start of the current credit cycle | Providing your subscription, including redeemed giveaways | Until you delete the account |
| Account creation date and last active date (calendar day, UTC — no time of day) | Removing abandoned free accounts | Free accounts without unspent pack credits are deleted after 180 days without activity |
| Keyed hashes of session tokens, with an expiry | Keeping you logged in | 30 days, or until you log out |
| Keyed hashes of API keys, the first characters of each key, the name you gave it, creation day | Authenticating API requests; letting you recognise and revoke keys | Until you revoke the key or delete the account |
| Keyed hashes of pending CAPTCHA challenges and one-use signup tokens, with work requirement and expiry — no account link, IP or browser details | Preventing automated signup bursts and replay, including after a restart | Deleted on successful use; validity is 3 minutes for challenges and 2 minutes for signup tokens. Expired records are cleared on signup activity or the next scheduled cleanup, within six hours while the service is running. |
| Aggregate successful-signup counts by minute, including the total from unattributed clients such as Tor — no individual identifiers | Adapting signup work and limiting anonymous signup bursts | A rolling 60–61 minute window; older counts are cleared on signup activity or the next scheduled cleanup, within six hours while the service is running. |
| Total credits used per account per calendar day (UTC), including budgets reserved by active requests | Enforcing plan limits | 35 days; older totals needed by an unfinished funding receipt remain until settlement or recovery |
| Temporary inference/search funding receipt: random receipt ID, account/lender IDs, UTC day and reserved/observed credit amounts — no content or exact request time | Preventing concurrent overspending and refunding unused budgets after failures | Until settlement, or recovery at the next server startup after an interruption; related daily totals are retained until then if needed for a correct refund |
| If you use a team: which accounts are in it, the nickname the owner gives you, your borrow cap, and credits you drew from teammates per day | Pooling credits; members see plan and credit totals. Personal chats are not shared automatically. | Membership until you leave or the team is disbanded; daily totals 35 days, except those needed by an unfinished funding receipt |
| Optional shared chats: encrypted titles, instructions, messages, search queries/source snapshots and branch links; public key fingerprint, team/chat IDs, revisions, update times and ciphertext sizes | Sharing history between authenticated team members who hold the browser-generated key | Until a member deletes the snapshot, the team is disbanded or the owner's account is deleted; leaving a team does not delete its history |
| Payment records linked to your account: payment method, plan, number of months, USD amount, status; for BTCPay its invoice id; for stablecoins our receiving address, the exact amount requested, the payment window and the paying transaction hash | Activating a plan once the payment confirms | 30 days after the invoice is paid, expired or invalid |
| Giveaway-code HMACs, issued plans, batch identifiers, creation/activation deadlines, redemption or revocation times and the redeeming account link | Applying the issued free subscription cycle once and limiting each account to one code per giveaway batch | Until the activation deadline and the next cleanup, within six hours while running. Deleting the account removes its link without making the code usable again. |
The records above are also included in database backups, which are kept for up to 7 days longer than the periods shown and then deleted. Shared-chat payloads remain encrypted in these backups.
The operator keeps a private issuance file to distribute giveaway codes. It contains the codes, not account IDs or conversation data; the database stores only their keyed hashes. Issuance files are managed separately by the operator and are not automatically erased by database cleanup. Codes cannot activate a plan after their deadline.
What we do not store
- Plaintext prompts, pasted content, model outputs, web-search queries or retrieved snippets. Shared-history storage contains ciphertext instead.
- IP addresses, user agents, device fingerprints, or a history linking accounts to individual inference timestamps. Shared snapshots have update times.
- Access logs. Our web server is configured without access logging. For rate limiting, IP addresses are hashed with a random key that exists only in memory and is replaced every time the service restarts; they are never written to disk.
- Analytics, tracking pixels, third-party scripts, fonts or CDNs. Every file is served from our own server.
Operational incident notices contain service/model identifiers, an error category, a check time and account-health information such as the provider's prepaid balance. They contain no user/account identifiers, prompts or answers. They may be written to operational logs or delivered to the operator's notification service; they are not a chat or request history.
Signup CAPTCHA computation and verification are self-hosted. Its code and WebAssembly files come from our server; no CAPTCHA provider receives your requests, and browser-fingerprinting checks are disabled. It requires JavaScript, Web Workers and WebAssembly for new accounts; existing account-key login does not require it.
Your conversations
Personal conversations live in your browser's IndexedDB. They leave your device for inference, or when you explicitly publish a copy to the team. You can export or delete personal chats from the account page. Clearing browser data permanently deletes local chats — we have no personal-history copy.
Team snapshots are encrypted with AES-256-GCM in your browser, including titles, instructions, messages, reasoning, saved web-search queries and sources, and branch links. The server stores a public fingerprint, not the independent 256-bit team key. The key travels in the secret fragment of an invitation or key link, which is not part of an HTTP request. Save a key link privately: your account key cannot recover it. A new member with the key can read existing team history. All members can edit or delete shared snapshots; private forks stay local until published.
Removing a member blocks subsequent server access and revokes outstanding membership invitations, but it cannot erase previously downloaded content or keys. Keys are not automatically rotated. Encryption protects stored snapshots, not a compromised browser, modified client code, or plaintext processed during inference.
When you send a message, the conversation so far travels over TLS to our server, which forwards it to the inference infrastructure running the model and streams the answer back. Our server holds the text only in memory for the duration of the request.
Third parties
Inference infrastructure
The models run on third-party inference infrastructure selected for privacy: providers whose published policy is not to retain prompts or outputs, and not to use them for training. Like most infrastructure providers, they reserve the right to inspect traffic for operational and abuse-prevention purposes. Language models need the plain text of your conversation to generate an answer, so that text is processed on hardware we do not own. We send it without your account key, IP address or any identifier, but we cannot technically verify what a provider does with the requests it processes. Do not send information you could not accept an infrastructure provider theoretically seeing.
Model names shown in the service (for example Specter and Quill) are our service names for open-weight or provider models; we choose and may change the model behind each name.
Optional web search
Search is off by default for each reply. If you enable it, the model derives one or more queries from your question and bounded recent conversation context. These generated queries travel through our server to external search infrastructure. We do not forward your account key, IP address or raw conversation history to that search service, but generated queries may contain details from your messages. Do not enable search for sensitive content. Retrieved snippets and source URLs are sent to the inference provider as context for your answer.
The configured search route is selected for a published zero-data-retention policy. This is a provider policy, not end-to-end encryption, and we cannot independently verify its enforcement. We keep queries and results in server memory only for the request, without plaintext logs. Saved search snapshots follow the same browser storage, plaintext export and encrypted team-storage rules as messages; saved evidence can be sent again as context in later replies. Opening a source link visits an independent website under its own privacy policy.
Server hosting
Our own server also runs on rented infrastructure. The data listed above lives on it; we keep that list minimal precisely because infrastructure can be compromised or compelled.
Payments
We use no payment processor. When enabled, supported coins go through a BTCPay Server instance we run ourselves; it does not ask for your name, email or address, and we do not tell it which account an invoice belongs to. Enabled stablecoins (USDT, USDC) are sent straight to our own wallet: each payment request has a unique exact amount, and our server recognises your transfer by reading public blockchain data about our address from a blockchain node or API provider. That provider can see public sending addresses and amounts, but we do not send it your account identity. Only our own database links a payment to your account, for the period stated above. Available methods are shown at checkout.
Bitcoin, Lightning and stablecoin transfers are recorded on public ledgers: anyone can see that an address sent a given amount to ours. They are pseudonymous, not anonymous — especially if the sending wallet or exchange account is tied to your identity. Monero offers much stronger privacy and is what we recommend.
Cookies and local storage
We set one cookie: sid, an HttpOnly session cookie that expires after 30 days or when you log out. There are no tracking or advertising cookies. Personal chats and team keys are kept in IndexedDB. Invitation fragments are temporarily kept in sessionStorage across sign-in and removed after joining/unlocking. Your account key is stored in localStorage only if you tick "Remember account key on this device". Logging out does not erase local chats or team keys; use your browser's site-data controls to remove both.
Requests from authorities
We can provide only data we hold, as listed above. We have no stored plaintext conversation archive, team decryption keys or recorded IP history. Message content is nevertheless processed in memory during inference, as described above. We will not secretly add logging for a specific user.
Your controls
- Export or delete personal chats from Account. Make a private copy of shared history to export it, or delete a shared snapshot from Team chat.
- Revoke API keys at any time.
- Delete your account from the account page. This immediately removes the account, its sessions, API keys, usage totals and payment records from our database. Deleting an owner's account disbands its team and deletes shared snapshots; a non-owner's contributions remain with the team. A redeemed giveaway code is unlinked from the account, not restored for reuse. Backups and teammates' copies can remain as described above. Remaining prepaid time is forfeited.
Security
All traffic is encrypted with TLS. Secrets we must recognise (account keys, session tokens, API keys) are stored only as keyed hashes. Because we cannot recover your account key, keep it safe — anyone who has it can use your account.
Age
The service is only for adults (18+). We do not knowingly provide it to anyone younger.
Changes
We will update the date at the top of this page when the policy changes. Material changes that reduce your privacy will be announced on the website before they take effect.
Contact
https://t.me/Cyberdeck_support