| Data | Why | Retention |
|---|---|---|
| Account email + password hash | Authentication, account recovery | While the account is active |
| Chat sessions and messages | Conversation continuity across sessions | While the account is active, until you delete them |
| Token-usage ledger (model, token counts, charge) | Billing accuracy and dispute resolution | 7 years (financial record) |
| Request logs (IP, timestamp, request id) | Abuse prevention, rate limiting, debugging | 30 days |
| Anonymous session identifiers | Quota enforcement for signed-out use | 24 hours |
We do not collect financial account numbers, holdings, or brokerage credentials. Do not paste account numbers, credentials, or identity documents into the chat.
To answer a question, the content of that question (and relevant retrieved sources) is sent to the model provider serving your request. Providers are listed on each answer. Where a request is served by our own locally hosted model, content does not leave our infrastructure. Where a request is served by an external provider, that provider processes the content under its own terms. Other processors we rely on are our hosting provider, our CDN, and our payment processor.
You control your history:
The token-usage ledger is retained after deletion in de-identified form only, because it is a financial record. It contains no chat content.
Traffic is encrypted in transit (TLS). Passwords are stored using a slow password-hashing function, never plaintext or a bare hash. Secrets are held outside the code repository with restricted file permissions. Access to production data is limited to the operator.
We use a session cookie to keep you signed in and, for signed-out visitors, a short-lived identifier to enforce anonymous quotas. We do not run third-party advertising trackers.
Depending on where you live, you may have the right to access, correct, export, or delete your personal data, and to object to certain processing. Requests: [email protected]. We respond within 30 days.
Material changes to this policy will be posted here with a new date. Continuing to use Ngans after a change means you accept the updated policy.