Standard Mode
Message history is encrypted at rest with account keys and stored for up to 90 days. After 90 days, chats are automatically and permanently purged.
- • Model Training: DISABLED
- • Retention: 90 Days
- • Search & Files: Enabled
We separate protection inside SacredGPT from upstream provider policies. History is encrypted, routing denies training on requests, and Strict limits processing to routes declaring zero data retention.
01 — Three Retention Modes
Message history is encrypted at rest with account keys and stored for up to 90 days. After 90 days, chats are automatically and permanently purged.
The encrypted chat is retained for no more than 24 hours and then automatically deleted. It does not use saved account memory or instructions.
Maximum upstream protection: requests route only to providers declaring Zero Data Retention. Web search and external OCR are disabled. Local history remains encrypted for the chat's selected retention period.
02 — Encryption & Access Control
Messages and files use AES-256-GCM envelope encryption with a per-user data key. An API key is shown once and only its SHA-256 digest is stored. TLS and master-key protection depend on the production infrastructure configuration.
SacredGPT engineers and admins have zero routine access to readable user chats. Support team members can view a text snippet ONLY when explicitly attached by you to a support ticket.
Generation requires sending prompt plaintext to OpenRouter and the selected provider. SacredGPT denies collection for training and, in Strict, additionally requires a ZDR route. The actual provider appears in API request details; its published policy remains an external trust boundary.
You can request a data archive and delete the account. Active chats, keys, and personal data are deleted or anonymized; minimum financial records remain where accounting requires them. Backups expire on a separate retention cycle.
03 — FAQ
SacredGPT sends OpenRouter a data-collection denial for training. Processing still occurs at an external provider under its published policy; use Strict ZDR for the most sensitive requests.
The gateway filters models to routes whose providers declare Zero Data Retention. Web search plugins and third-party image recognition are disabled.
A background purge job runs every six hours and hard-deletes expired records from the active database. Backups expire on a separate schedule.