Privacy Policy
This policy applies to the SacredGPT website, web chat, API, and related user services.
1. Scope and Contact Details
The SacredGPT project operates the website and user services. For questions about personal data, contact support@sacredgpt.pro, message @SacredGPT_Support_Bot, or open a request through the ticket system.
2. Data We Process
- • Account data: name, email, internal identifier, language, email and age verification status, legal consent records, and 2FA settings.
- • API data: key name and prefix, secret hash, permissions, budgets, allowed models, IP restrictions, and last-used timestamp. The full key secret is not stored after creation.
- • User content: prompts and responses, uploaded files, instructions, memory facts, feedback, search results, and public chat snapshots created by the user.
- • Usage and billing data: selected model, token counts, quota usage, subscription state, and payment identifier, amount, method, and status. SacredGPT does not receive bank card details.
- • Support requests, chat excerpts attached by the user, and selected contact methods.
- • Technical data: IP address or pseudonym, browser family, session details, security events, page route, and pseudonymous product analytics.
3. Purposes and Legal Bases
Data is used to register and secure accounts, process chat and API requests, retain user-selected settings, calculate charges and process payments, prevent abuse, operate support, analyze interface quality, and comply with applicable law.
Processing is based on performance of the user agreement, pre-contract steps requested by the user, consent, SacredGPT’s legitimate interests in service security and quality, and legal obligations. Data is not sold or used for third-party advertising mailings.
4. Processors and Data Transfers
To operate the service, necessary data may be shared with hosting, database, and encrypted object-storage providers; email delivery services; the Platega payment provider; OpenRouter and selected model providers; a search provider when web search is enabled; and Telegram when support is contacted through the bot.
The prompt, required conversation context, and selected files are sent to the model provider to generate a response. Some processors operate in other countries, so the relevant feature may involve cross-border transfer. Such transfer is limited to what the feature requires and relies on the user agreement and separate consent where required.
5. Use of Data by AI Models
SacredGPT does not use user prompts, files, or responses to train its own models. When routing through OpenRouter, the service sends data_collection: deny, while strict mode uses only routes marked as eligible for provider-side zero data retention (ZDR). A specific external provider’s technical processing rules may differ and apply to the request sent to that provider.
6. Retention Periods
- • Standard and strict chats: encrypted messages and related files are retained for up to 90 days.
- • Incognito chats: encrypted messages and files are automatically deleted after 24 hours.
- • Interactive browser: cookies, local storage, and history remain in an account-isolated profile until manually cleared, the account is deleted, or 90 days of inactivity pass. Browser sessions are unavailable in incognito and strict privacy modes.
- • API requests: content is not added to chat history; technical usage data required for billing, limits, and security is retained.
- • Support requests: are retained for up to 90 days by default.
- • Security events: a full IP address, when required, is encrypted and retained for up to 7 days; pseudonymized security events are retained for up to 180 days.
- • Analytics: pseudonymous events are retained for up to 395 days.
Settings, instructions, and memory facts are retained until deleted by the user or the account is deleted. Account, payment, and audit records may be kept longer when required for accounting, dispute resolution, fraud prevention, or legal compliance.
7. Data Security
Messages, extracted file text, instructions, and memory are encrypted with a user-specific key; uploaded files are stored encrypted. Full API key secrets are not retained, staff access is role-limited, and sensitive fields are removed from audit logs. No security method eliminates all risk, so users should enable 2FA and revoke compromised keys promptly.
8. Cookies
Technical cookies prefixed with sacredgpt are used for sign-in and session security; sessions last up to 30 days. The sacred_cookie_consent cookie stores the selected preference for one year. Only with permission, sacred_anon stores a random identifier for up to one year for pseudonymous product analytics. Consent can be changed through Cookie settings in the site footer. Advertising cookies are not used.
9. User Rights
You may request information about processing, obtain an export, request correction, blocking or deletion, restrict processing, and withdraw consent where processing relies on consent. Export and deletion controls are available in privacy settings; you may also contact support.
Before fulfilling a request, SacredGPT may verify account ownership. Records that must be retained by law or to protect the parties’ rights may be restricted, anonymized, or retained for the required period rather than deleted immediately.
10. Changes to This Policy
A new version is published on this permanent page with its revision date and applies upon publication unless stated otherwise. SacredGPT may request renewed consent for material changes.
Found a bug? Show us.
Tell us what happened and what you expected. The page address and browser details help us reproduce it faster.
