Policy // Privacy
Collect less. Explain the rest.
Last updated July 19, 2026
This policy explains how BrokenGPT processes information when you use the website, chat workspace, developer API, billing tools, and research features.
Data we process
- Account data: email, display name, authentication records, plan, and billing-provider identifiers.
- Web chat: conversation titles, message content, selected model, and timestamps.
- Web-chat agent tools: search queries, requested page URLs, tool timing/status, and retrieved web material used to produce an answer.
- Developer API: hashed key, prefix, model, token counts, latency, status, and request ID. Synchronous API prompt text is not persisted by the application; batch request bodies and results are stored while the batch is queued or available for retrieval.
- Documents and research: uploaded files, extracted chunks, citations, research constraints, source metadata, evidence snapshots, and generated reports you choose to retain.
- Workspaces: organization membership, role, invitations, service accounts, audit events, and workspace-attributed usage.
- Security data: session and sign-in records, request metadata used for rate limits, and abuse or incident records.
Why we process it
We process data to authenticate users, provide chat history and inference, enforce quotas, bill paid plans, secure the service, investigate abuse, comply with law, and improve reliability.
Providers and transfers
We use service providers for database hosting, privately routed open-source model inference, payments, email delivery, observability, and edge protection. When research tools are enabled, search queries and requested page URLs are sent to the configured search and page-retrieval services. Those services process request metadata and returned web content under their own terms; retrieved material may also appear in the assistant message stored with the conversation. The public developer API does not invoke research tools unless a documented API capability explicitly says otherwise.
Agent-tool cautions
Do not include secrets, sensitive personal data, private links, or access tokens in a web-search request. Retrieved pages are untrusted and may contain inaccurate content or prompt-injection instructions; the application treats them as evidence rather than authority, but no automated defense is perfect.
Retention and controls
You can export account data, delete your account, revoke API keys, remove conversations and documents, and configure conversation and document retention from the account console. Completed, failed, or cancelled batch bodies and results expire under the configured batch-retention period. Shared workspace material may remain under the workspace owner's retention settings after a member leaves. Some billing, security, fraud-prevention, backup, or legal records may be retained after deletion where required to operate the service or comply with law. Backup copies expire through the applicable backup lifecycle.
Contact
BrokenGPT is the service operator. Send privacy requests to privacy@brokengpt.com. General support is available at support@brokengpt.com.