Privacy Policy
Effective
What we collect, why, who else sees it, and how to get it deleted. We do not sell personal information and we do not use your questions to train AI models.
1. What we collect
Account information
When you sign in with Google or with an email link, we receive and store your email address, your display name and profile photo URL if your provider supplies them, and the account identifier Firebase Authentication assigns you. We require a verified email address. We never see or store your Google password.
Your questions and answers
We store the questions you ask, the answers generated for them, the citations attached to each answer, and the conversation titles, so your history is there when you come back. You can rename, pin, or permanently delete any conversation from the sidebar.
Question log
Separately from your conversation history, every question is recorded with your account identifier, which topics it matched, how much evidence was found, and whether the corpus could answer it at all. This log is how we learn what the corpus is missing and decide what to research next. It is not shown to anyone but us, and it is never published or sold.
Usage and billing
We store your plan, subscription status, how many questions you have used in the current monthly window, and the Stripe customer and subscription identifiers that let us match a payment to your account. Card details go directly to Stripe and never reach our servers.
Free-plan record
The free plan is one per person. To enforce that, we store a keyed hash of your email address: a scrambled fingerprint made with a secret key, from which the address can't be read back. Before hashing, we remove the parts that make aliases of one mailbox, such as “+tag” and, for Gmail, dots. If you delete your account, we keep that fingerprint and the number of free questions you used, and nothing else, for 12 months. Our basis is our legitimate interest in preventing abuse of the free plan.
Technical data
- A session cookie named
__session, set when you sign in. It is HTTP-only, expires after five days, and exists only to keep you signed in. It is not used for advertising or cross-site tracking. - Rate-limit counters. To stop abuse we count requests per account and per IP address in short windows. IP addresses are hashed before they are stored, so we hold no raw IP addresses.
- Server logs, which record request and answer metadata such as timing, token counts, and errors.
- Your theme preference, stored in your own browser and never sent to us.
2. How we use it
- To run the service: sign you in, answer your questions, and keep your history.
- To meter free and paid usage and to process your subscription.
- To protect the service from abuse, fraud, and runaway cost.
- To improve the corpus and the product, by studying which questions we could not answer well.
- To contact you about your account, billing, or material changes to these documents.
We do not use your content to train AI models, we do not sell or share personal information, and we do not run advertising or third-party analytics on the site.
3. Who else processes your data
We use a small number of service providers, each acting on our instructions:
- Google Cloud and Firebase (United States) host the site, authenticate sign-ins, and store your account, conversations, and usage.
- Anthropic (United States) generates answers. Your question, recent conversation context, and the retrieved evidence are sent to its API. Anthropic does not train its models on data submitted through the API.
- Stripe (United States) handles checkout, subscriptions, payment methods, and tax calculation, and is the controller of the payment data you give it.
- Google reCAPTCHA Enterprise, through Firebase App Check, verifies that requests come from the real app. Google collects hardware, software, and interaction data for this purpose, subject to Google’s Privacy Policy and Terms of Service.
We may also disclose data if the law requires it, or to protect our rights or the safety of others.
4. Where your data is held
The service runs in the United States and your data is stored and processed there. If you use it from another country, you are sending your data to the United States.
5. How long we keep it
- Conversations: until you delete them, or until your account is deleted. Deleting a conversation removes it and its messages permanently, with no undo.
- Account and billing records: for as long as your account exists, and afterwards only as long as tax and accounting law requires.
- Question log entries: kept as corpus research. When you delete your account, or on request, your account identifier is stripped from them so they no longer identify you.
- Free-plan record after account deletion: 12 months, then it is deleted. Signing up again within that time continues the same free allowance and removes the record.
- Rate-limit counters: minutes to hours, then they expire.
6. Your choices and rights
You can see and delete your conversations in the app at any time. For anything else, write to lastpicked@proton.me from your account email and we will act within 30 days.
California residents have the right under the CCPA and CPRA to know what personal information we collect, to get a copy of it, to correct it, to have it deleted, and not to be discriminated against for exercising those rights. We do not sell or share personal information as those terms are defined, and we do not use it for cross-context behavioural advertising, so there is no opt-out to offer. If you are in the EEA or UK, you have equivalent rights of access, correction, erasure, restriction, portability, and objection; our basis for processing is performing our contract with you and our legitimate interest in keeping the service safe and improving it.
You can delete your account yourself from the account menu in the app. That deletes your conversations and account record, strips your account identifier from the question log, cancels any subscription immediately, and deletes your sign-in. Two things remain: billing records with Stripe, for as long as tax and accounting law requires, and the free-plan record described above, for 12 months. You can also ask us at the address above and we will confirm when it is done.
7. Security
Access to your data is enforced on the server: database rules deny direct client writes and let you read only your own records, sessions are verified server-side on every request, and requests are checked by App Check. No system is perfectly secure, but we keep the number of places your data lives deliberately small.
8. Children
The service is not for anyone under 18. We do not knowingly collect data from children. If you believe a child has given us data, write to us and we will delete it.
9. Changes
We may update this policy. The effective date at the top always shows the current version, and we will announce material changes by email or in the app before they take effect.
10. Contact
Privacy questions and deletion requests: lastpicked@proton.me. See also our Terms of Service.