Privacy Policy
last updated 2026-09-28
What we collect
Account data: your email, optional display name and username, and OAuth provider ids when you sign in with Google or Discord. Email, name and IP addresses are encrypted at rest.
Usage data: per-request metadata needed for billing and reliability, such as model id, token counts, cost, latency and success. Payment records are kept for the transactions you make.
Account-security data: session dates, an encrypted sign-in IP and keyed IP hash, browser/OS details, a hashed first-party device marker, and bounded display and language settings supplied by your browser. These signals help detect new logins, prevent repeat free-trial signups and investigate disputes. We do not collect local network addresses through WebRTC.
API requests and saved chats
API request prompts and model outputs pass through to the model provider and are not persisted as conversation history. Dashboard Chat saves conversations and their instructions to your account so you can continue on another device. Saved chat content is encrypted at rest; you can export or delete conversations in the dashboard. This is server-side encryption, not end-to-end encryption. To make repeated prompts faster and cheaper, GPT-family models currently run with a 24-hour prompt cache. That cache lives on the upstream provider's inference servers, never on ours, and holds inference cache state under the upstream provider's policies. It expires automatically within 24 hours. We do not sell personal data, run ads, or use third-party analytics trackers.
Where your data goes
To serve a request, its content is transmitted to the upstream model provider that serves the model you chose; their processing is governed by their own terms. When web search is enabled in Chat, search queries are also sent to the search provider and source excerpts are included with the model request. Browser code previews run locally in an isolated environment. Payments already made by card are processed by Polar, while new top-ups use OxaPay (crypto); we never see full card numbers.
Cookies and sessions
We use a first-party session cookie (up to one day), short-lived OAuth and 2FA challenge cookies, and a first-party random device marker for abuse prevention. We do not use cross-site advertising cookies.
Retention and deletion
Account data is kept while your account exists. Expired and revoked session records are removed after 180 days; usage and payment records remain for billing history. A keyed email or device restriction may remain after a disputed account is deleted so that a chargeback ban cannot be cleared by re-registering. Deleting a saved conversation removes its content from active storage; backups expire under the operator's retention policy. To request account deletion, reach us on Discord at zenllm.org/invite/discord.
Contact
Privacy questions: join our Discord at zenllm.org/invite/discord.