This policy explains what llmwise collects, why, who else receives it, how long we keep it, and what you can do about it. We've tried to write it so you don't need a lawyer to read it.
1. Who we are
- llmwise (llmwise.ai) is operated by an individual based in the United States. "We", "us" and "our" mean llmwise. We decide how your personal data is used, so under privacy laws such as the GDPR we're the "controller".
- For anything about your privacy, email hello@llmwise.ai.
- You must be 18 or older to use llmwise.
2. The short version
- We store your account email, your chats, and what you put into llmwise, so you can come back to it. If you try a message without an account, we keep the message and answer for 7 days, then delete them in our daily cleanup, unless you choose to add them to your account after signing up in the same browser.
- Each message goes to the company whose AI model answers it. Your memory and your project's instructions and files go with it.
- We don't sell your data. We don't show ads. We don't train AI models on your content.
- One exception to how providers treat your data: every image model you can pick is marked with how it's made, and an image made with a model marked "via kie.ai" is made through kie.ai, which receives only that image's prompt, not your chat. Its terms let it use what it receives to operate and improve its services, and it keeps its task logs, which include the prompt, for 2 months (see 5.3). If you don't want that, choose a model that isn't marked "via kie.ai" when one is offered, or don't make images.
- Email: no newsletters, and never ads for other companies. We send sign-in links, notices about your account, a welcome email when you sign up, and a few reminders about your own account (see 4.4). Each reminder has an unsubscribe link that stops them all without signing in, and mail apps that show an Unsubscribe button do it in one click. Our emails never include anything from your chats.
- Purchases are sold through Link, Stripe's affiliate. We never see your full card details.
- We use non-essential first-party cookies to record how you found llmwise and which version of a feature you were shown in a test. We don't set them if you visit from the EU, the EEA, the UK or Switzerland (see section 8).
- We keep our own records of how llmwise is used: which features people use, where they came from, and the problems they hit, like a message that was refused or a reply that failed. They're short codes, never your messages, prompts, files or the answers, and they're deleted after 13 months (see 3.2).
- We may record how pages are used, like clicks, scrolling and the screens you open, with PostHog, to find what's confusing. Your chats, what you type, chat and project titles and your files are never in these recordings, and the words on your account's pages are masked. From the EU, the EEA, the UK or Switzerland we ask first. We never record a browser that sends Do Not Track or Global Privacy Control, and you can turn recordings off in Settings → Account (see sections 3.2 and 8).
- You can delete chats, memory, projects and more yourself. In Settings → Account you can download a copy of your data and delete your whole account. You can also email us to do either.
3. What we collect
3.1 What you give us
| What | Details |
|---|---|
| Account | Your email address. A name only if one is ever added to your account (sign-in doesn't ask for one). |
| Guest messages | If you try the free message without an account: your message, the AI answer, the model, the time and the token count and cost. A secret cookie lets only your browser return to that answer and, if you choose, add it to your account after you sign up. |
| Chats | Your chats and every message in them, including replies, tool results and any feedback you give on a reply (thumbs up or down, and, if you tap one, why: wrong, too slow, too long, refused or other). |
| Files | Files you attach to a chat, files your code runs create, and images you generate. |
| Documents | Documents, code, spreadsheets, slides and apps that llmwise writes for you. Exports (PDF, Word, PowerPoint, Excel, CSV) are made when you download them and aren't stored separately. |
| Memory | The short notes about you that you add in Settings → Memory, or that a model saves when you tell it something to remember. Each save shows in the chat with an Undo. |
| Projects | Project names and instructions, the files you add to a project, and the text we read from those files. |
| Personas and skills | Personas you save, and skills you upload. |
| MCP servers | The address of each MCP server you add, and any headers you give it. Headers are stored encrypted. |
| Connector choices | Which apps you've connected, and which connector actions you've allowed to run without asking. The connections themselves are held by Composio, not by us (see section 6). |
| Cancellation feedback | If you cancel a plan, the reason and comment you choose to give. Both are optional. |
| Feedback you send | What you write in "Send feedback" (the account menu), and the category you pick, if any. We save it with the page you were on (its address without anything after "?") and your plan, and read it as you wrote it. |
| Messages to us | What you send when you email us. |
3.2 What we collect as you use llmwise
| What | Details |
|---|---|
| Usage records | For every AI call: the model, the tokens used, the cost, whether it came from a message or a tool, and the time. We use these to show what you have left, apply your plan's limits and run the business. |
| Plan and billing records | Your plan, its status, its billing period dates and the Stripe IDs that link your account to your purchases. We don't receive your full card details. |
| Sign-in sessions | Our sign-in provider, Neon Auth, keeps a record of each signed-in session. That record can include your IP address and browser type. |
| How you found us | Outside the EU, the EEA, the UK and Switzerland, a cookie records how you first arrived and the latest campaign or site that brought you back (see section 8). From the EU, the EEA, the UK and Switzerland there's no cookie: the sign-in page reads the same things from your visit and your sign-in link carries them. If you create an account, we save them with your account, with your device type (phone, tablet or computer, not your browser's details) and your country, as our host works it out from your IP address (we don't keep the address). |
| Product analytics | Short codes, with your account and your plan at the time: which features you use (Compare, image mode and which image model, research, web search, connectors, MCP tools, memory, projects, skills, file uploads, exports, the Tools menu, Create image), the problems you run into (a message refused and why, a reply that failed, came back empty or took more than 15 seconds to start, an image that wasn't made, a checkout that didn't open or expired unpaid, a payment that failed, a thumbs-down), how long your first reply took to start, and plan changes you make in the app. Never your messages, prompts, file names, tool inputs or the answers. We use them to see what people use and where llmwise gets in their way. |
| Visit counts | Before you have an account, we count visits to our public pages, the sign-in form being opened, and sign-in links sent or refused (and why), each with the page, the campaign tags in the link, the name of the site that sent you, your device type and your country. There's no identifier, cookie or IP address in them, so they can't be connected to you. |
| Steps toward a paid plan | When you see an offer to upgrade (the card at the end of the free trial, or the pricing page while you're on Free), and when you start or finish a checkout: which step, where in llmwise, the plan and the time. We use these to see how people move from trying llmwise to paying. |
| Lifecycle email records | Which welcome or reminder emails we send, which email links you click, when you unsubscribe, and your reminder preference. Links in these emails go through llmwise so we can record the email and the time of a click and understand whether reminders lead to a checkout. We do not put chat content in these records. |
| Feature tests | Outside the EU, the EEA, the UK and Switzerland: a random browser identifier, the test and version shown, and whether you used the guest message. If you sign up in that browser, we connect its test assignment to your account to compare sign-up and paid-plan conversion. We don't put message content or your IP address in these events. |
| Abuse-prevention counters | A keyed hash of your network address and a daily attempt count enforce the guest-message limit. We don't store the address itself in these counters or guest-message records. |
| Session recordings and product events | Through PostHog, when you haven't turned them off: how you move through llmwise's pages (clicks, scrolling, the screens you open, the size of your window), what kind of browser and device you use, and a few steps we record on purpose (opening the sign-in form, sending a sign-in link, signing up, sending a message, starting a comparison, an image being made, a message being refused, with the reason as a short code, and starting or finishing a checkout), each with its time. Recordings never include your chats, the composer, what you type, documents, chat or project titles or files: those parts of the page are left out, every field you type in is masked, and every word on your account's pages is masked. Page addresses lose everything after "?" except campaign tags, and chat and project IDs are replaced. Once you're signed in, this is linked to your account by its internal ID, never your email. We use it to find what's confusing or broken. From the EU, the EEA, the UK or Switzerland, nothing is recorded unless you choose Allow when we ask. |
| Technical data | Our host, Vercel, handles every request. It keeps technical logs and traces that can include your IP address. We set up our traces of AI calls not to record the text of your messages or the replies. See section 6 for page analytics and bot checks. |
3.3 What we get from others
- Link and Stripe tell us whether a payment went through, and about refunds and disputes, so we can update your plan.
- Composio tells us whether an app connection worked and lists your connections. It doesn't give us your passwords or sign-in tokens.
4. How we use your data
We use your data to:
- Run llmwise for you: sign you in, save your chats, send your messages to the model you pick, and run the tools you use. If you try a guest message, generate its answer, and add it to your account if you choose to after signing up.
- Apply your plan: show what you have left, apply limits, and process plan changes and top-ups.
- Keep llmwise safe: prevent abuse, fraud and automated traffic, and fix bugs and outages.
- Talk to you: send sign-in links, answer your emails, and tell you about important changes to your account, your plan, or our terms. We also send a welcome email when you sign up, and a few reminders about your own account: a few hours after your free trial is used up, about three days after you sign up, and when a checkout you started expires unpaid (at most one of those a week). Some reminders mention what Pro costs. We send reminders only to accounts created on or after October 7, 2026, and never to an account on a paid plan or that has ever subscribed to one. We don't send newsletters or ads for other companies, and these emails never include chat content. The welcome email and every reminder have an unsubscribe link that stops all reminders without signing in, and mail apps that show an Unsubscribe button do the same in one click. Unsubscribing doesn't stop sign-in links or notices about your account. Deleted accounts don't get these emails.
- Understand how llmwise is doing: count visits and page speed without identifying you, see which channels bring people to llmwise, see how people move from the free trial to a paid plan, see which features people use and where llmwise gets in their way, compare sign-ups and paid plans between feature-test versions, look at usage and costs, and read cancellation feedback and the feedback you send.
- Meet legal duties: comply with the law and respond to lawful requests.
We don't:
- sell your personal data, or share it for advertising;
- show ads, or use advertising cookies or trackers;
- train AI models on your content;
- make decisions about you by automated means that have legal or similarly significant effects. Plan limits, such as the fair-use limit, apply automatically in the way How pricing works describes.
We don't look at your chats to run llmwise. We look at them only if you ask us to help with something in them, to investigate abuse or a security problem, or if the law requires it.
5. Where your messages go
5.1 To the AI model that answers
When you send a message, we send it to the company that runs the model you picked, so the model can reply. Along with it we send:
- the earlier messages in the chat;
- any files attached to the chat;
- your memory (unless memory is off, in Settings → Memory or for that chat);
- your project's instructions and file text, if the chat is in a project. For a large project, only the parts of its files that best match your message are sent, or the start of each file when nothing matches.
Models reach us in one of two ways:
- Directly from the company that makes them. This is possible for Anthropic, OpenAI and Google.
- Through OpenRouter, a service that routes requests to AI models. OpenRouter is used when we don't call a provider directly, or when a direct call fails. It's the only route for xAI (Grok), DeepSeek, Moonshot (Kimi) and Z.ai (GLM) models. For some of these models, the endpoint that runs your request can belong to a hosting company, not the company that made the model.
The model provider handles your request under its own terms. We ask the model routers we use not to route your requests to providers that train on or retain your data for their own use. Every request we send through OpenRouter asks only for endpoints that, according to OpenRouter, don't store your prompts for their own use or train on them. OpenRouter doesn't store prompts or replies unless an account turns that on, and we haven't. The one exception is kie.ai, which makes images with the models marked "via kie.ai": it receives only an image's prompt, never your messages, and its terms let it use what it receives to operate and improve its services (5.3).
A guest message uses GPT-6 Luna. We send only your message, our instructions and a one-way hash made from your browser's random test identifier (llmwise_vid, section 8) to its AI provider, using the routes described above. The provider uses that hash to spot abuse, such as one person sending many messages; it can't be turned back into the identifier, and it contains nothing that names you. Guest messages have no files, memory, tools or web search.
5.2 To search and research services
- Web search. When the model searches the web, the search is run by the model's own provider (Anthropic, OpenAI or Google) or by Exa, through OpenRouter. Exa receives the search query the model writes, not your chat.
- Reading a link you share. The link goes through OpenRouter to a small OpenAI model, which asks Exa to fetch the page. They receive the link, not your chat.
- Research reports. A Standard report is written by DeepSeek V4 Pro through OpenRouter, searching with Exa. A Deep report is written by Perplexity through OpenRouter. Both receive only the research question the model writes and its focus, not your chat.
5.3 To tools you choose to use
-
Running code and backend apps (paid plans). Code you approve runs in Vercel Sandbox, on a fresh isolated machine that gets only the code and the files it needs. It can't reach the internet except to install packages. The machine is stopped when the run ends. A backend app runs the same way on its own machine and stops when you close it or its time runs out.
-
Images (paid plans). When you ask for an image, the model writes a prompt for it from your request, and the image model you picked (in the Tools menu, or GPT Image when you don't pick one) makes the image from that prompt. Only that prompt and the image's size are sent, never your chat, your files, your memory or your account details. The prompt can include details from your request, because the model writes it from what you asked.
- Every image model is marked with how it's made. A model shown with its maker alone (for example "OpenAI" for GPT Image) is made by that company directly, like the GPT models in 5.1. Which models are offered, and how, can change; the picker always says.
- The models marked "via kie.ai" (today Nano Banana 2 and Nano Banana Pro by Google, Seedream by ByteDance, FLUX.2 by Black Forest Labs, Ideogram, Qwen-Image by Alibaba, and GPT Image by OpenAI whenever it isn't offered directly) are made through kie.ai. According to kie.ai's Terms of Use, the website is "jointly operated by NEXUSAI SERVICES LLC and INNOLEAP AI LLC", and its Privacy Policy says "NEXUSAI SERVICES LLC … operates the website kie.ai". kie.ai has the image made by the model's upstream provider, under kie.ai's own arrangements, which we don't control. What kie.ai says about what it receives, as of September 26, 2026:
- Its Terms of Use (effective August 1, 2025) say that for content submitted to it, "you grant us a worldwide, non-exclusive, royalty-free license to use, host, store, reproduce, modify, and display your content solely for the purpose of operating and improving our services". For llmwise, that content is the prompts we send it.
- Its developer guide says "Generated media files: stored for 14 days, then automatically deleted" and "Log records (text / metadata): stored for 2 months, then automatically deleted". Its task logs include each request's input, so a prompt is kept for up to 2 months.
- Its Privacy Policy is about its own account holders (for llmwise's images, that's us, not you): it collects their email address. It doesn't say more about content sent through its API.
We download each image as soon as it's made and keep it in our own storage, so your copy never depends on kie.ai. If you don't want a prompt to go to kie.ai, choose a model that isn't marked "via kie.ai" when one is offered, or don't make images.
-
Connectors (paid plans). When the model uses an app you've connected (like Gmail, Google Drive, Notion or Slack), the action runs through Composio and that app's own service. They receive the action's inputs. What comes back is shown in your chat and saved with it.
-
MCP servers (paid plans). When the model uses an MCP server you added, that server receives the inputs the model sends it, which can include parts of your chat. An MCP server you add is run by whoever operates it, under their own terms, not by us.
5.4 Using llmwise from ChatGPT
If you connect llmwise in ChatGPT, ChatGPT can see which models your llmwise account can use and ask them questions for you.
- What ChatGPT sends us. The question it writes and the models it picks. ChatGPT decides what goes into the question, so it can include parts of your ChatGPT conversation. We send the question to each model it picked, as in 5.1, and send each answer back to ChatGPT. ChatGPT, run by OpenAI, handles your conversation, the questions and the answers under OpenAI's own terms and privacy policy, not ours.
- What we keep. We don't save these questions or answers to your chats. Each one gets a usage record (3.2), like every message: the model, the tokens, the cost and the time, never the text. Each counts toward your account's messages.
- Signing in. Connecting is handled by WorkOS (section 6). You sign in with llmwise's usual email link and confirm the connection; we then give WorkOS your email address and your account's internal ID, and WorkOS gives ChatGPT the access it needs to ask llmwise for you.
- Disconnecting. You can disconnect llmwise in ChatGPT's settings at any time. Deleting your llmwise account also ends the connection.
5.5 Using llmwise from Claude
If you connect llmwise in Claude, Claude can see which models your llmwise account can use and ask them questions for you.
- What Claude sends us. The question it writes and the models it picks. Claude decides what goes into the question, so it can include parts of your Claude conversation, but nothing else from your Claude conversation reaches us: not the rest of the chat, your files, or what Claude remembers about you. We send the question to each model it picked, as in 5.1, and send each answer back to Claude. Claude, run by Anthropic, handles your conversation, the questions and the answers under Anthropic's own terms and privacy policy, not ours.
- What we keep. We don't save these questions or answers to your chats. Each one gets a usage record (3.2), like every message: the model, the tokens, the cost and the time, never the text. Each counts toward your account's messages.
- Signing in. Connecting is handled by WorkOS (section 6). You sign in with llmwise's usual email link and confirm the connection; we then give WorkOS your email address and your account's internal ID, and WorkOS gives Claude the access it needs to ask llmwise for you.
- Disconnecting. You can disconnect llmwise in Claude's settings, under Customize → Connectors, at any time. Deleting your llmwise account also ends the connection.
6. Companies that process data for us
We use these companies to run llmwise. They process your data to provide their service to us.
| Company | What it does for llmwise | What it receives |
|---|---|---|
| OpenRouter | Routes messages to AI models. Runs web search, link reading and research reports. | Your messages and everything sent with them (5.1), search queries, links you share, research questions. |
| Anthropic (Claude) | AI models. Web search for Claude. | Your messages and what's sent with them, when a Claude model answers. |
| OpenAI (GPT) | AI models. Images with GPT Image, when it's offered directly (not marked "via kie.ai"). The small model that reads links. | Your messages and what's sent with them, when a GPT model answers. The prompts of images made with GPT Image directly. Links you share. |
| kie.ai (operated by NEXUSAI SERVICES LLC and INNOLEAP AI LLC, according to its terms) | Makes images with the image models marked "via kie.ai" (5.3). | Only the prompt and size of each image made with one of those models. Under its terms it may use them to operate and improve its services, and keeps generated images 14 days and task logs, which include the prompt, 2 months. |
| Google (Gemini) | AI models, with Google's own search. | Your messages and what's sent with them, when a Gemini model answers. |
| xAI (Grok), DeepSeek, Moonshot (Kimi), Z.ai (GLM), Mistral, and the companies that host their models | AI models, reached only through OpenRouter. | Your messages and what's sent with them, when their models answer. |
| Exa | Web search and fetching pages. | Search queries and links. |
| Perplexity | Deep research reports, through OpenRouter. | The research question and its focus. |
| Vercel | Hosts llmwise and runs its servers. Keeps technical logs and traces. Counts visits and a few actions, like pressing Start free (Web Analytics), and measures page speed (Speed Insights). Checks that chat messages come from a real browser (BotID, with its partner Kasada). Runs code and apps (Vercel Sandbox). | Every request to llmwise, including your IP address. Browser signals when you send a chat message. Code and files for runs you approve. |
| Neon | Our database, our sign-in system (Neon Auth), and file storage. | Everything we store (section 3), including your email and sign-in sessions. |
| Resend | Sends sign-in emails for Neon Auth and lifecycle emails for llmwise. | Your email address and the email's text and links. Lifecycle emails may include your remaining trial count, but never chat content. |
| Stripe and Link | Payments. Sold through Link, LLC, Stripe's affiliate, is the merchant of record for purchases (see our Terms). | Your email, a user ID that links you to your llmwise account, and the payment and billing details you give at checkout. Link handles them under Link's Privacy Policy. |
| Composio | Runs connectors: app sign-ins, stored connections, and actions. | Your connections and their sign-in tokens (stored encrypted on its side), and each action's inputs and results. It knows you by a random ID, not your email. |
| WorkOS | Signs ChatGPT and Claude in to llmwise when you connect llmwise in them (5.4 and 5.5). | Your email address, your account's internal ID, and a record of the connection. |
| A hosted Redis service | A short-lived cache that lets a reply keep streaming if your connection drops. | Parts of a reply while it's streaming. Entries expire within a day. |
| PostHog | Session recordings and product events (3.2), stored in its US region. | How you move through llmwise's pages, with the chat surfaces left out and every typed field and every word on your account's pages masked, the steps listed in 3.2, your browser and device type, your IP address as part of each request, and your account's internal ID once you're signed in. Never your email or your chats. |
Other people can also see some data, but only when you choose:
- People you share a chat with. If you make a chat public, anyone with its link can read it. They can't see your memory, your project's instructions or files, or your attachments.
- Apps and MCP servers you connect, as described in 5.3.
- ChatGPT, if you connect llmwise there: it sees the models your account can use and the answers to the questions it sends (5.4).
- Claude, if you connect llmwise there: it sees the models your account can use and the answers to the questions it sends (5.5).
We may also disclose data if the law requires it, or to protect people's safety or llmwise from abuse. If llmwise is ever transferred to someone else, your data would go with it, and we'll tell you before that happens.
7. Where your data is stored
- We're based in the United States. Our database and file storage are with Neon, on Amazon Web Services in the US. Vercel runs our servers in the US. PostHog stores session recordings and product events in its US region.
- The AI providers, OpenRouter and the other companies in section 6 may process data in the US and in other countries.
- If you're in the EU, the UK or another country with transfer rules, your data is transferred to the US and other countries where these companies work. Where the law requires it, these transfers rely on safeguards such as the European Commission's standard contractual clauses in these companies' data processing terms. kie.ai (5.3) publishes no data processing terms, so there's no such safeguard for an image prompt you send through it; if that matters to you, choose an image model that isn't marked "via kie.ai" when one is offered, or don't make images.
8. Cookies and browser storage
We don't use advertising cookies or third-party trackers. Here's everything llmwise stores in your browser:
| Name | What it's for | How long | Needed to run llmwise? |
|---|---|---|---|
| Neon Auth sign-in cookies | Keep you signed in. | Your sign-in session | Yes |
connector_nonce |
Links an app you're connecting back to the browser that started it, so a forwarded sign-in link can't connect someone else's account. | 15 minutes | Yes (security) |
chat-model |
Remembers the model you last picked. Adding a guest answer to your account picks Claude Sonnet 5, the model its "second opinion" offer names. | 1 year | It's a preference you set |
sidebar_state |
Remembers whether the sidebar is open. | 7 days | It's a preference you set |
llmwise_src |
Records how you first found llmwise: the campaign tag in the link (if any), the site that sent you (just its name, like news.ycombinator.com), the first page you landed on, and when. A later visit from a campaign link or another site is kept as your latest one, the first staying as it was. If you sign up, we save these with your account. Not set for visits from the EU, the EEA, the UK or Switzerland. | 90 days from your first visit | No |
llmwise_vid |
A random identifier, signed by us so it can't be made up, that keeps your feature-test version stable and connects test exposure to a later sign-up in the same browser. Not set for visits from the EU, the EEA, the UK or Switzerland. | 90 days | No |
llmwise_guest |
A secret reference to the one guest message you requested, so you can return to its answer or add it to your account. Set only when you send the message; it contains no message text. | 7 days, or cleared when you add the answer to your account | Yes, if you request a guest message |
| Browser storage (not cookies) | Your theme and font choices, your web search setting, and an unsent draft of your message. They stay in your browser and aren't sent to us. | Until you clear them | They're preferences you set |
| PostHog's browser storage (not a cookie) | A random identifier for your browser and the current session, so a recording and its events stay together. Only once PostHog loads: never with Do Not Track or Global Privacy Control, never after you turn recordings off, and from the EU, the EEA, the UK or Switzerland only after you choose Allow. | Until you clear it, or sign out (signing out starts a new identifier) | No |
llmwise_recordings_consent, llmwise_recordings_off (browser storage, not cookies) |
Your answer when we ask whether we may record (EU, EEA, UK and Switzerland), and whether you turned recordings off in Settings → Account, so we don't ask again or record anyway. They stay in your browser. | Until you clear them | They keep your choice |
Where we don't set llmwise_src. We don't set it when you visit from a country in the European Union or the European Economic Area, from the United Kingdom, or from Switzerland. We go by the country our host, Vercel, works out from your IP address for each visit, and we don't store that country. From anywhere else, we set it on your first visit to one of our public pages, unless your browser already has it. If you open your sign-in link in another browser, the link carries this record and we set the cookie there too, except on a visit from one of the countries above. A cookie set earlier stays until it expires or you clear it. Without the cookie (for example, from one of the countries above), the sign-in page reads the campaign tags, the site that sent you and the page you first opened from your visit itself, without storing anything in your browser, and your sign-in link carries them, so the account you create records them. If none of that is there, your account's record of how you found llmwise is left empty.
Visit counts. We also count visits to our public pages, and the sign-in form being opened, ourselves: without a cookie, browser storage or any identifier, and without keeping your IP address (see 3.2).
The same regional restriction applies to llmwise_vid: visitors in the countries above see the normal sign-up flow, without an experiment identifier or test-exposure event. A guest-message cookie is separate: it is needed to deliver the message a visitor explicitly requests.
We also use these, and none of them set cookies:
- Vercel Web Analytics counts page views, and a few actions — pressing Start free, opening the sign-up form, sending a sign-in link, seeing or clicking an upgrade offer — without third-party cookies and without your email or anything else that identifies you. It tells visitors apart using a hash of the request, which it discards after 24 hours.
- Vercel Speed Insights measures how fast pages load. Vercel says it doesn't tie that data to a visitor or an IP address.
- Vercel BotID runs a check in your browser when you send a chat message, to tell people from bots.
Session recordings (PostHog). PostHog's code is served from llmwise itself and loads only after a page has finished loading. It doesn't load at all if your browser sends Do Not Track or Global Privacy Control, or after you turn recordings off in Settings → Account (which applies to that browser). From the EU, the EEA, the UK or Switzerland, we go by the country our host works out for each visit, show a short question first, and load nothing unless you choose Allow; choosing No thanks is kept, and you can turn recordings off later in Settings → Account. PostHog uses browser storage, not cookies.
When you pay, Stripe's and Link's checkout pages use their own cookies, under their own policies.
9. How long we keep data
| Data | How long |
|---|---|
| Account and settings | While your account exists. |
| Guest messages and answers | Available for 7 days. Messages nobody adds to an account are removed in the daily cleanup after that period. If you add one to your account before then, the guest copy is deleted and the prompt and answer become a private chat, kept until you delete that chat or account. |
| Anonymous feature-test identifiers and events | The browser identifier lasts 90 days. Events without an account are removed in the daily cleanup after 90 days. The test assignment linked to a sign-up stays while that account exists. Daily totals for guest usage, cost and refusals contain no browser identifier or message content. |
| Guest network-limit counters | Removed by the daily cleanup once their counting window is more than 2 days old. They contain a keyed network hash, not the address itself. |
| Chats and messages | Until you delete them, or your account. |
| Files you attach, code-run outputs and generated images | Until you delete the chat they're in, or your account. Deleting a chat deletes them, unless another of your chats or documents uses the same file. A file that none of your chats or documents mentions any more (its message was edited, or it was never sent), or that we couldn't delete when you deleted its chat, is removed by a daily cleanup, a day or more later. |
| Documents llmwise writes for you, and research reports | Until you delete your account. They aren't deleted with a chat, except a generated image, which goes with its file. |
| Memory, projects, personas, skills, MCP servers | Until you delete them, or your account. |
| Usage records, and our records of your plan and purchases | Until you delete your account. |
| Payment records that Link and Stripe keep | As the law and Link require, which can be up to 7 years, even after your account is deleted. |
| Cancellation feedback | 24 months, or until you delete your account if that's sooner. |
| How you found us | The cookie lasts 90 days. The copy saved with your account stays while your account exists. |
| Product analytics, visit counts and the feedback you send | 13 months, then removed by our daily cleanup; your account's analytics and feedback go sooner if you delete your account. |
| Steps toward a paid plan | While your account exists. |
| Lifecycle email records and reminder preference | While your account exists. |
| Session recordings (PostHog) | 30 days. |
| Product events sent to PostHog (3.2) | Up to 12 months. |
| Sign-in sessions | Until the session ends or expires, or you delete your account. |
| A deleted account's note | When you delete your account, we keep a note that it was deleted for about a week, so the deletion can finish and your old sign-in stays closed. It holds no email and nothing you wrote. |
| Server logs and traces | As long as our host, Vercel, keeps them. |
| The reply cache | Up to a day. |
| Database history | When we delete data, it can stay in our database's recovery history for a short time (today, about 6 hours) before it's gone for good. |
Companies in section 6 keep data under their own terms. For example, an AI provider may keep a request for a limited time for safety and abuse monitoring, kie.ai keeps the images it makes for 14 days and its task logs, which include each image's prompt, for 2 months (5.3), and Link keeps payment records as the law requires.
10. Your choices and controls
You can do these yourself, today:
- Delete a chat from its menu in the sidebar, or by typing
/deletein it. This removes the chat and its messages, the files attached in it and the files and images made in it, and stops any backend app it started. A file that another of your chats or documents still uses is kept. A file left behind by a message you edited goes in a daily cleanup. Documents and research reports aren't deleted with a chat (see section 9). - Delete every chat from the account menu, or by typing
/purge. Their files go with them, in the same way. - Share or unshare a chat. Share → Public makes it readable by anyone with the link. Share → Private turns that off.
- Memory. In Settings → Memory, see, edit and delete each memory, delete all of them, or turn memory off. You can also turn it off for one chat in that chat's options.
- Projects. Delete a project's files, or the whole project, from its page. Deleting a project deletes its files and keeps its chats.
- Personas, skills and MCP servers. Delete them in Settings.
- Connectors. In Settings → Connectors, disconnect an app. This removes the connection at Composio. You can also remove any action you've allowed to run without asking.
- Payments. In Settings → Billing, see invoices, change your payment method, and cancel your plan.
- Email reminders. Use the unsubscribe link in the welcome email or any reminder, or your mail app's Unsubscribe button, to stop all reminders without signing in. You'll still get sign-in links and notices about your account.
- Session recordings. Turn them off in Settings → Account → Session recordings (for that browser). Do Not Track or Global Privacy Control in your browser also turns them off. From the EU, the EEA, the UK or Switzerland they're off unless you choose Allow.
- Download a document that llmwise wrote as PDF, Word, PowerPoint, Excel or CSV.
- Download your data in Settings → Account → Download your data. You get a ZIP file with your chats (the text of every message, and the names of their files, with links that open them while you're signed in), the documents llmwise wrote for you, your research reports, your memory, your projects (their instructions and the list of their files), your personas and skills, your MCP servers (their names and addresses, not the headers you saved), your tool and connector settings and the apps you've connected, a summary of your usage, and your account details. It's made when you ask for it and isn't stored. You can download it 3 times a day. Files themselves (attachments, images, project and skill files) aren't in it.
- Delete your account in Settings → Account → Delete account, after typing DELETE or your email to confirm. It cancels your plan, disconnects your apps at Composio, and deletes your sign-in and everything in your account: chats, files, documents, research reports, memory, projects, personas, skills, MCP servers, usage records, product analytics, the feedback you sent and settings. Then it signs you out. If a step can't finish when you confirm (for example, if Stripe can't be reached to cancel your plan), we tell you what's still pending, and our daily cleanup retries it until it's done. Link and Stripe keep their payment records (see section 9).
You can also email hello@llmwise.ai from the email address you sign in with, and we'll do these for you:
- Delete your account and everything in it.
- Get a copy of your data, including anything the download doesn't hold.
- Change your email address.
11. Your rights
- Depending on where you live, you may have the right to:
- see the personal data we hold about you;
- correct it;
- delete it;
- get a copy of it in a format you can reuse;
- object to how we use it, or ask us to limit it; and
- withdraw consent you've given.
- If you live in the EU or the UK, you have the rights your local data protection law gives you. You can also complain to your local data protection authority.
- If you live in a US state with a privacy law, you have the rights that law gives you. We don't sell your personal data or share it for targeted advertising.
- You can download a copy of your data and delete your account yourself, in Settings → Account (section 10). To use any of these rights, you can also email hello@llmwise.ai. We'll reply within the time the law gives us, usually a month. We may need to confirm that the request comes from you, for example by asking you to write from your account's email address. We won't treat you differently for using your rights.
11.1 Our legal reasons for using your data (EU and UK)
If you live in the EU or the UK, the law asks us to say why we're allowed to use your data:
| Why | What it covers |
|---|---|
| To provide the service you signed up for (contract) | Your account, chats, files, memory and projects. Answering a guest message you request. Sending messages to AI providers and tools. Payments, plan limits and top-ups. Sign-in emails. |
| Our legitimate interests | Keeping llmwise secure and preventing abuse (bot checks, rate limits, logs). Counting visits and page speed. Looking at usage and costs. Seeing how people move from the free trial to a paid plan. Seeing which features people use and where llmwise gets in their way (product analytics, visit counts: 3.2). Reading cancellation feedback and the feedback you send. Learning which channels bring people to llmwise, where we set the llmwise_src cookie (section 8). Session recordings and product events outside the EU, the EEA, the UK and Switzerland, to find what's confusing or broken (3.2). Comparing sign-up and paid-plan conversion for feature tests where we set llmwise_vid (section 8). Sending the welcome email and reminders about your own account (4.4), which you can stop at any time. |
| Legal obligations | Keeping records the law requires, and answering lawful requests. |
| Your consent | Session recordings and the product events sent to PostHog (3.2) if you're in the EU, the EEA, the UK or Switzerland: we ask first, and you can withdraw consent in Settings → Account. Anything else we ask your permission for. You can withdraw consent at any time. |
12. Security
- No passwords. You sign in with a link we email you, which works for 15 minutes.
- Private files. Files are kept in a private storage bucket. Only you can open your own uploads.
- Secrets stay secret. MCP server headers are encrypted before we store them. Connector sign-in tokens are held, encrypted, by Composio, not by us.
- Tools ask first. Code runs, backend apps, research reports, MCP tools and connector actions that change something ask for your approval before they run, unless you've chosen "Always allow". "Always allow" is never offered for actions that send, delete, move money or share. These also ask first: opening a link that didn't come from you; MCP tools that send, delete, pay or share; and changes to your memory after the model has read outside content (the web, files or tools).
- Code is isolated. Code runs in a sandbox that's stopped when the run ends.
- Payments. Your card details go to Stripe and Link, never to us.
No system is perfectly secure. If we learn of a breach that affects your data, we'll tell you and the authorities as the law requires.
13. Children
llmwise is for people 18 and older. We don't knowingly collect data from anyone younger. If you think someone under 18 has an account, email hello@llmwise.ai and we'll delete it.
14. Changes to this policy
When we change this policy, we update this page and the "Last updated" date. For important changes, we'll tell you in advance, by email or in the app.
15. Contact
Email hello@llmwise.ai.