Help
Privacy, security and your data
What llmwise stores, where your messages go, how to delete chats and your account, and the safeguards around tools and code. The Privacy Policy has the full details.
What llmwise stores
Your account email.
Your chats and the messages in them.
Files you attach, files your code runs create, images you make and documents you export.
Your personas and skills, and the MCP servers you connect (their address, and any headers you add, stored encrypted with AES-256-GCM).
Which apps you've connected, and the connector actions you've let run without asking. The app sign-ins themselves are held by Composio, not by us.
Your memory: the short notes about you that you add in Settings → Memory, or that a model saves when you tell it something to remember.
Your projects: their names and instructions, the files you add to them, and the text read from those files.
Usage records: which model you used and how many messages you sent, to apply your plan's limits.
A few steps toward a paid plan: when you saw an offer to upgrade, and when you started or finished a checkout (just the step, where in the app and the plan), to see how people go from trying llmwise to paying.
Where your messages go
A message, and any file attached to it, goes to the provider of the model that answers it. In llmwise, a message to Claude, GPT, or Gemini goes to the model's maker, or through OpenRouter when llmwise can't reach the maker directly. DeepSeek, Grok, Kimi, GLM, and Mistral models are served only through OpenRouter, by endpoints that don't store or train on prompts.
Your memory, and the instructions and file text of the project a chat is in, go with each message to the same provider. A chat you share never shows them, though a reply's own words are part of it.
Every company involved, and what each receives, is listed in the Privacy Policy.
Your controls
Delete a chat
From a chat's menu in the sidebar, or by typing /delete in it. Deleting a chat removes it and its messages, the files attached in it and the files made in it (unless another chat uses the same file), and stops any backend app it started.
Delete every chat
From the account menu, or by typing /purge: every chat goes at once.
Sharing
Chats are private unless you share them. From a chat's menu, Share → Public lets other people with its link open it; Share → Private turns that off again.
Memory and projects
Turn memory off in Settings → Memory, or for one chat in its options, and delete a memory or all of them there. Delete a project's files, or the whole project, from its page: its files go, its chats stay.
Download your data
In Settings → Account, download a ZIP of your chats, memory, projects, personas, skills and usage.
Delete your account
In Settings → Account → Delete account: your plan is canceled, your apps are disconnected, and everything in your account is deleted. Or email hello@llmwise.ai and we'll do it for you.
Safeguards
No passwords
You sign in with a link we email you, which works for 15 minutes. There's no password to leak or reuse.
Tools ask first
Running code, backend apps, research reports and MCP tools ask for your approval before they run, unless you set them to Always allow.
Connectors ask first
On a paid plan, apps you connect (Gmail, Drive, Notion, Slack and more) can be read and used in a chat. Reading needs no approval. Anything that writes asks first, and sending, deleting, payments and sharing always ask. That can't be switched off for sending, deleting, payments or sharing.
We never hold your app sign-ins
App sign-in runs through Composio, our connector partner (SOC 2 Type II and ISO 27001; trust.composio.dev), which holds the sign-in tokens: llmwise never sees your app passwords or stores the tokens. Disconnect any app in Settings → Connectors.
Code runs in a sandbox
Code you approve runs in a fresh, isolated machine that gets only the code and the files it needs, and is stopped when the run ends. A backend app's preview address is shown only to you.
Searches get the query, not the chat
Search and research services outside the model's own provider get only the query the model writes, or the link to read, never your chat.
Payments
Payments go through Stripe, which never shares your card details with us.
Questions
Who sees my messages?
llmwise stores them so you can come back to your chats, and each one goes to the provider of the model that answers it. Models served through OpenRouter only use endpoints that don't store or train on prompts; for the others, the provider's own terms apply, as the Privacy Policy explains. An image made with a model marked “via kie.ai” sends kie.ai only that image's prompt, never your chat; kie.ai's terms let it use it to operate and improve its services, and it keeps its logs 2 months.
What does an MCP server I connect receive?
When the model uses one of its tools, the server gets the inputs the model sends it, which can include parts of your conversation. A server you add is run by whoever operates it, under their own terms, so connect only ones you trust.
Claude, GPT, Gemini, DeepSeek, Grok, Kimi, GLM, and Mistral, in one chat.
See what a message costs before you send it. Free is 5 messages to try; sign in with an email link, no password or card.