Privacy
Privacy Policy
Your chats live in your browser—not in SayAll's database. SayAll does not store your conversation titles, prompts, or AI replies as server-side chat history.
Effective
1. Privacy starts in your browser
SayAll is built for conversations you do not want turned into a permanent server-side history. Eligible Guests can ask sensitive questions and explore lawful NSFW text without giving SayAll an email or creating a personal profile. Guest access reduces identity collection, but it is pseudonymous rather than completely anonymous.
Local storage does not mean local-only AI processing. When you choose Send, the message and relevant context are encrypted in transit to SayAll and the configured AI provider. SayAll keeps the live generation only in bounded process memory for delivery and short reconnection recovery; it is not written to SayAll's chat database. The AI provider's handling remains governed by its own terms and privacy policy.
- Conversation titles, prompts, replies, and drafts are saved only in this browser on this device.
- SayAll does not write chat content, conversation records, generation records, or AI usage details to its database under its default privacy configuration.
- There is no SayAll cloud chat history and no automatic cross-device chat sync.
- Clearing this browser's site data removes that local history copy and may sign you out.
- Only messages you choose to send leave the browser, and only so SayAll and its AI provider can generate and deliver a response.
2. Information we collect
SayAll processes the following categories of information to provide chat, accounts, Credits, security, analytics, payments, and support:
- Optional account information, such as an email address or external sign-in account, when you choose to register.
- A pseudonymous Guest or account identifier, session information, and security signals such as device-fingerprint and IP digests.
- Prompts and relevant conversation context while a sent message is being processed, plus the generated response while it is being delivered or briefly available for stream reconnection. SayAll does not turn this transient processing into database chat history.
- Limited transaction references needed to add purchased Credits and resolve a payment issue. Payment details are handled by the payment provider.
- The IP address and time when you open the Credit purchase dialog or create a purchase, and your account identifier if a session is present. SayAll stores these limited billing records privately for checkout troubleshooting and fraud prevention, not as chat history or advertising profiles.
- Limited product-interaction events, such as pages visited and whether a response, registration, or checkout step completed. These events do not include your prompt or response text. Registered accounts use a pseudonymous analytics identifier rather than an email address or raw account identifier.
- Limited technical diagnostics, such as an error, affected application version, route, timing, and request identifier, when needed to detect and fix service failures.
- Information you voluntarily send when you contact support.
3. What we do not use for analytics or advertising
Conversation processing, product analytics, and payment processing are separate data flows. The following limits apply to the current telemetry configuration:
- We configure product analytics and error monitoring not to receive prompt or response text.
- We do not use conversation topics to create advertising profiles.
- We do not sell personal information or chat content.
- We do not use third-party advertising trackers or cross-site behavioral tracking.
- We do not collect card, bank, or cryptocurrency-wallet credentials entered with a payment provider.
4. How conversations are handled
The conversation list, message history, titles, and drafts displayed by the chat interface are stored only in this browser's local database for the current user. They are not fetched from SayAll's servers or automatically synchronized to another browser or device. Someone with access to this browser profile or an unencrypted device may still be able to access local data.
Nothing is sent merely because you open SayAll, create an empty conversation, or type a draft. When you choose Send, the browser sends the message and relevant conversation context through SayAll's backend to the configured AI provider. SayAll does not insert the conversation, message, response, generation, or provider usage into its PostgreSQL chat tables. A bounded in-memory generation record may remain available for reconnection for up to approximately 15 minutes and disappears earlier when evicted or the process restarts.
Deleting a conversation or clearing SayAll site data removes the chat history from that browser. SayAll has no server-side chat-history copy to synchronize or restore. This does not delete separate account, session, security, Credit, transaction, support, analytics, or payment-provider records, and it does not control an AI provider's own retention.
Conversation content is kept separate from the manually defined product-analytics events. SayAll configures Google Analytics, PostHog, and Sentry telemetry not to include prompt or response text.
5. How information is used
We use the limited information we collect only to:
- Provide and secure the service.
- Generate and stream responses without creating server-side chat history.
- Authenticate an account when you choose to register.
- Maintain and apply Credit balances.
- Complete a payment and investigate payment errors or fraud.
- Understand aggregate acquisition and product funnels and improve onboarding, reliability, and performance.
- Respond to support requests and important service notices.
- Comply with a binding legal obligation.
7. Service providers and disclosure
SayAll uses infrastructure, AI-processing, authentication, support, email, analytics, error-monitoring, and payment providers where needed to deliver the service. The AI provider receives prompts and selected conversation context needed to generate a response. Provider handling is also governed by the applicable provider terms and privacy policy.
SayAll uses Google Analytics for acquisition reporting, PostHog for manually defined product events and funnels, and Sentry for errors and performance traces. Automatic product interaction capture and session replay are disabled. SayAll configures these services not to receive chat text, email addresses, raw account identifiers, payment credentials, request bodies, or URL query strings from the telemetry integrations.
Raw billing IP addresses are not included in SayAll's GA4 or PostHog event properties. This is separate from the network information those providers necessarily process when your browser connects to them.
Payment providers process payment information under their own privacy policies. SayAll may also disclose limited information when legally required, to protect people from an immediate threat, or as part of a transfer of the service subject to this policy.
8. Retention and deletion
SayAll does not retain conversation titles, prompts, responses, generation status, or AI usage details in its database under its default privacy configuration. Live generation state is held only in bounded process memory for response delivery and short reconnection recovery, normally for no longer than approximately 15 minutes after completion. Your browser retains the only SayAll chat-history copy until you delete it or clear site data.
Account, session, security, Credit, transaction, support, product-analytics, and diagnostic records are separate from chat history and are retained for operational, fraud-prevention, accounting, dispute, security, and legal purposes. For access or deletion requests involving those SayAll records, contact support@sayall.ai. Some records may need to remain where required by law or legitimate security and billing needs, and providers may apply their own retention rules.
Credit-dialog opening records are removed after 90 days by a periodic bounded cleanup, so a short processing delay may occur. A purchase's original IP is retained with its transaction record for billing audit and fraud prevention. These records are not exposed through the public account or purchase API.
9. Security
SayAll uses encryption in transit, access controls, credential protection, and other reasonable safeguards designed to protect information. No online service can promise perfect security, so you should avoid sharing highly sensitive information and keep your devices and credentials secure.
10. Your rights
Depending on where you live, you may have rights to access, correct, delete, restrict, or export personal information, object to certain processing, or complain to a data-protection authority. Contact support@sayall.ai to make a request. We may ask for enough information to verify that the request belongs to you.
11. Adults only
SayAll is for adults aged 18 or older. We do not knowingly offer the service to children or collect personal information from them. Contact us if you believe a minor has used SayAll.
12. Changes and contact
We may update this policy when SayAll or applicable law changes. The effective date at the top shows the latest revision. We will provide additional notice when required for a material change.
Questions and privacy requests can be sent to support@sayall.ai.