SacredGPT Trust Center

Privacy by Architecture, Not Promises.

We separate protection inside SacredGPT from upstream provider policies. History is encrypted, routing denies training on requests, and Strict limits processing to routes declaring zero data retention.

AES-256 Envelope EncryptionNo-Training RoutingStrict ZDR Routing

01 — Three Retention Modes

Complete Control Over Data Lifecycle

01. Standard Mode

Standard Mode

Message history is encrypted at rest with account keys and stored for up to 90 days. After 90 days, chats are automatically and permanently purged.

  • Model Training: DISABLED
  • Retention: 90 Days
  • Search & Files: Enabled
02. Incognito Mode

Incognito Mode

The encrypted chat is retained for no more than 24 hours and then automatically deleted. It does not use saved account memory or instructions.

  • Model Training: DISABLED
  • Retention: 24 Hours (Cache)
  • Saved to History: NO
03. Strict ZDR Mode

Strict Zero-Retention

Maximum upstream protection: requests route only to providers declaring Zero Data Retention. Web search and external OCR are disabled. Local history remains encrypted for the chat's selected retention period.

  • Model training: DENIED BY ROUTING POLICY
  • Upstream retention: declared ZDR
  • Web search & external OCR: DISABLED

02 — Encryption & Access Control

How Your Data is Protected

Encryption at Rest and in Transit

Messages and files use AES-256-GCM envelope encryption with a per-user data key. An API key is shown once and only its SHA-256 digest is stored. TLS and master-key protection depend on the production infrastructure configuration.

Zero Staff Access Policy

SacredGPT engineers and admins have zero routine access to readable user chats. Support team members can view a text snippet ONLY when explicitly attached by you to a support ticket.

Upstream Provider Boundaries

Generation requires sending prompt plaintext to OpenRouter and the selected provider. SacredGPT denies collection for training and, in Strict, additionally requires a ZDR route. The actual provider appears in API request details; its published policy remains an external trust boundary.

Self-Service Export and Deletion

You can request a data archive and delete the account. Active chats, keys, and personal data are deleted or anonymized; minimum financial records remain where accounting requires them. Backups expire on a separate retention cycle.

03 — FAQ

Security FAQ

Are my prompts used to train GPT or Claude?+

SacredGPT sends OpenRouter a data-collection denial for training. Processing still occurs at an external provider under its published policy; use Strict ZDR for the most sensitive requests.

What happens when Strict ZDR mode is enabled?+

The gateway filters models to routes whose providers declare Zero Data Retention. Web search plugins and third-party image recognition are disabled.

How is 90-day deletion enforced?+

A background purge job runs every six hours and hard-deletes expired records from the active database. Backups expire on a separate schedule.