NanoGPT Privacy Policy
Last Updated: October 6, 2026
NanoGPT LLC ("NanoGPT," "we," "us," or "our") values your privacy and is committed to taking reasonable steps to protect your personal information. We aim to limit the information we collect and store to what is reasonably needed to provide and operate our Services, as described in this Privacy Policy.
This Privacy Policy describes our practices regarding information we collect from or about you when you use our website, platform, services, and features, including all associated software applications (collectively, "Services").
You may request a copy of a prior Privacy Policy at support@nanogpt.com.
Scope
This Privacy Policy applies to personal information collected through:
- Our website and any webpages that link to this Privacy Policy;
- Our applications, features, and services (including APIs) that link to this Privacy Policy;
- Interactions with third-party sites or services where our Services are embedded and link to this Privacy Policy.
Capitalized terms not defined in this Privacy Policy have the meanings given in our Terms of Service.
NanoGPT determines how account, billing, security, support, and service-administration information is used. Where we process personal information on a business customer's behalf and instructions, our role and the customer's role depend on the processing involved and any applicable data-processing agreement. That customer may also provide a privacy notice. These arrangements do not remove our responsibilities under applicable law.
Personal information we collect
We collect personal information as described below when you use our Services, communicate with us, or create an account. NanoGPT does not train models on your Input or Output, sell your Content, or use your Content for advertising. NanoGPT no longer loads advertising pixels or sends advertising conversion events. See Your privacy choices and Your rights and requests below.
- Account Information: If you choose to create an account, we collect your email address, and may also store your name, profile image, a hashed version of your password, passkey (WebAuthn) credential handles, and two-factor authentication settings. This information is necessary to provide login, authentication, and account security features. You can also use our services without creating an account by using an anonymous session. We support multiple authentication methods, including email and password, Google OAuth, GitHub OAuth, and WebAuthn/passkeys. When you sign in via Google or GitHub, we receive limited profile information (such as your name, email, and profile image) from those providers in accordance with their privacy policies.
- Payment Information: When you make payments, we use third-party payment processors. For credit or debit card payments we use Stripe as our payment processor. We do not receive or store your full payment card details. Stripe collects and stores certain personal information related to your payment transactions. Account deletion includes an attempt to delete the associated Stripe customer records, but this does not erase every payment record: Stripe may retain transaction and other information for its independent purposes and legal obligations. Contact us about information we hold or control. You can also contact Stripe about its independent processing through its data deletion request page. For cryptocurrency or other payment methods, we may use processors such as BTCPay Server, Nanswap, or BoomFi; these providers may collect and process transaction details (such as wallet addresses, transaction identifiers, and amounts) under their own privacy policies. We receive limited transaction metadata to credit your account.
- Communication Information: If you communicate with us, we may collect your name, contact information, and the contents of your messages to the extent that you choose to share these details with us.
- Social Media Information: When you interact with our pages on third-party sites like X and Discord, we may collect information you choose to provide, such as your contact details.
Information Related to Your Use of the Services
We aim to minimize data collection and limit the use of IP addresses, as described below:
- Prompts and Conversations: By default, we do NOT store prompt or conversation content on our servers. If you enable optional features such as conversation sync or sharing, we store the necessary content (encrypted where applicable) so those features can work.
- Optional API Request Logging and Support Debugging: API-key owners may opt in to encrypted storage of new /v1/chat/completions request and response bodies in private object storage. Logs expire after a selected period of 1 to 30 days, become unavailable through the log-access tools, and are scheduled for deletion. The database retains the associated ownership, consent, request metadata, expiry, encryption reference, and opaque object key rather than the captured body. These private request logs are off by default and are available to the API-key owner. A separate, off-by-default setting allows authorized NanoGPT staff to inspect only logs captured while that support-access setting is enabled for debugging and support. This permission does not authorize model training or general product-improvement use. Turning support access off revokes further staff access through our support tools without clearing the logs from the owner's account. Support access is recorded in an audit log. Disabling request logging or clearing logs removes them from active access and initiates deletion of the stored payloads. Physical deletion may occur later as cleanup processes run or retry a failed storage operation.
- Responses API: Our OpenAI-compatible Responses API can store request and response data encrypted (AES-256-GCM) to support conversation threading, response retrieval, and background processing. Storage is off by default for ordinary requests; background processing requires storage. When storage is enabled, records expire after 7 days by default. Expired records become unavailable through the Responses API and are scheduled for deletion by our cleanup processes. Physical deletion may occur after expiration as those processes run. You can set the store parameter to false to disable local Responses API storage for a request. When storage is enabled, retention is configurable per request with retentionDays or retention_days from 0 to 365 days; setting retention to 0 disables retention for that request. User and team default retention settings are also available through API endpoints. See the Responses API retention documentation for the exact request fields and settings APIs. You may also provide your own encryption key (via the X-Encryption-Key header) for customer-managed encryption at rest. This key is provided with API requests and used server-side to encrypt/decrypt stored responses, and is not persisted by us.
- Optional PII Redaction: If you enable PII redaction, we route the relevant request and response content through Grepture before forwarding to the selected model provider and before returning the response to you. This feature is for private information inside prompts, messages, context, and responses; we normally do not attach your NanoGPT account name, email, or other account metadata to model-provider requests. Redaction is designed to detect and mask supported PII categories, but may not identify every sensitive detail. Grepture receives the request and response content necessary to detect, mask, and restore supported PII categories, and may process operational metadata and traffic-log data as described in Grepture's Privacy Policy. Grepture's subprocessors are listed on its Subprocessors page, and further company information is available in Grepture's Impressum.
- Memory & Global Memory Sync: Memory is disabled by default. If enabled, Global Memory items are stored in your browser until you explicitly enable sync. Recoverable sync encrypts stored snapshots but NanoGPT infrastructure can decrypt them; it is not zero-knowledge. Passphrase mode encrypts snapshots in your browser before upload, and NanoGPT cannot read or recover those contents. You can view, edit, disable, delete, or clear memory. The default remote suggestion analyzer uses a TEE-backed provider route, but your browser sends the analyzed excerpts to NanoGPT in plaintext before NanoGPT forwards them; this is not browser-to-enclave Private Mode. A custom remote analyzer may not use a TEE. The optional local browser analyzer keeps analysis on the device, but saved memory may still be sent to the chat model when Memory is used. Saved items remain stored until you delete or clear them; disabled or expired items are excluded from active use but may remain stored. Capacity is configurable in Memory settings.
- Previously Imported Google Drive Files: Google Drive import has been retired. Files previously imported may remain in your local library, NanoGPT-managed object storage, or your configured Bring Your Own Storage bucket. No single maximum retention period applies to these stored copies. Removing an item from your local library or deleting your account does not necessarily delete the remote object immediately; content in your own bucket remains subject to the storage lifecycle you configure.
- AI Detection and Plagiarism Checks: If you use our AI detection or plagiarism checking features, we send the text you submit to Pangram so it can process the detection request and return a report. Pangram processes that text under its own privacy policy and terms.
- CAPTCHA Verification: When you attempt to claim free Nano, we use Cloudflare Turnstile to verify that you are a human. Cloudflare may process your IP address and browser information as part of this verification. This data is subject to Cloudflare's Privacy Policy.
- IP Addresses: Our hosting and security systems necessarily process your IP address when you connect. NanoGPT does not attach IP addresses to prompts, model-provider requests, usage records, support tickets, or bug reports. Our application uses raw IP addresses temporarily in rate-limit and abuse-prevention systems, where they are automatically deleted after the relevant security window expires. Retention varies by control, and we do not publish individual thresholds because doing so could weaken those protections. Password-reset abuse protection may also store a keyed one-way identifier derived from an IP address as a separate security record. We do not intentionally write raw IP addresses into application log messages. Vercel, our hosting provider, separately processes network information such as IP addresses under its Privacy Policy; because Vercel does not publish a single IP-specific retention period covering all infrastructure records, we do not claim a fixed duration for Vercel's independent processing.
- Usage Data: We do not attach IP addresses to model-usage records such as token counts, models, charges, and timestamps. Our hosting and security systems process IP addresses as described above.
Image, Audio, Video, and Potential Biometric Processing
Some models accept or generate images, audio, or video and may perform processing that is regulated as biometric processing in some jurisdictions. Depending on the model and feature, this may include voice cloning or voice conversion, speaker identification, voice-preserving translation, face cloning, face transformation, or analysis of facial or vocal characteristics. A Model Provider may extract or generate data such as voiceprints, voice models, face geometry, or faceprints to fulfill the request.
When you use these features, NanoGPT transmits the media and related instructions to the Model Provider selected for the request. The Model Provider's handling, retention, and use of that data is governed by its own terms and privacy practices. NanoGPT's own storage of submitted or generated media follows the feature-specific storage and retention practices described in this Privacy Policy, including optional storage, sharing, sync, and Responses API features.
NanoGPT does not itself sell submitted media or biometric data and does not use them to train models. Any separate rights or practices of a Model Provider are governed by that provider's terms and privacy policy.
If media contains another identifiable person, you must provide any legally required notice and obtain all rights, permissions, consents, and other lawful bases required to submit the media and use the selected feature. You must not submit another person's image, likeness, or voice for cloning, identification, or other biometric processing without that person's informed consent where consent is required by law.
We may collect limited product telemetry (for example, aggregate counts of how often certain interface features are used, such as quick-reply buttons) to evaluate feature usefulness and improve the service. For this telemetry, we use an in-house first-party system rather than third-party analytics tools for privacy reasons. This telemetry is aggregate-focused and does not include message content.
NanoGPT has retired advertising pixels, Google Tag Manager, and advertising conversion reporting. Our Advertising Policy explains this change.
For model-usage records, we store request metadata such as input and output token counts, the model used, charges, discounts, whether web search or memory was used for billing, and the request timestamp. These records power the Usage page. Account, payment, security, support, telemetry, and optional content-storage information is handled as described elsewhere in this Privacy Policy.
Our platform uses your local browser storage to hold settings and conversation history. We also use a session cookie that contains a signed session identifier (and optional security flags, such as pending 2FA) so we can retrieve your session and balance from our servers. If you arrive via a referral or campaign link, we may set a referral/source cookie to attribute signups or payments. If you enable conversation sync, we store snapshots using your selected encryption mode in our cloud storage or your own configured storage. Passkey and passphrase modes encrypt snapshots in your browser before upload; access to those stored snapshots requires your encryption credentials or a supported recovery method. Convenience mode uses encryption managed by NanoGPT, and our infrastructure can decrypt those snapshots to restore your chats. These protections concern stored snapshots; content you use in model requests is still processed as described above. You can use the available controls to delete synced snapshots. If you share a conversation, we store a share snapshot, encrypted if you choose, for the retention period you select so the link can work.
How we use personal information
We use the personal information described in this Privacy Policy, including information you provide, information received from sign-in or payment providers, and information generated through your use of the Services, for the following purposes:
- To provide, operate, and troubleshoot the Services, including authentication and session management;
- To process your payments and update your account balance;
- To provide optional features you enable, such as sync, sharing, memory, request logging, and integrations;
- To communicate with you about our Services and events, including account, service, and security notices;
- To send new account holders up to four getting-started emails over about two weeks, which you can stop at any time with the unsubscribe link. We record clicks on links in these emails, and whether you use the Services afterwards, to decide whether to send the later emails and to measure whether they are useful. To choose which tips to send, we also use counts of which features you have used, such as how many images you have generated or whether you have used the API, never the content of your prompts or chats. We do not use tracking pixels or record email opens;
- To review, route, and respond to support requests, bug reports, and suggestions you submit;
- To understand feature usage and improve the Services using the limited first-party telemetry described above, which excludes message content;
- To help prevent fraud, unlawful activity, abuse, and misuse of the Services, and to support the security and integrity of our systems;
- To comply with legal obligations and protect our rights, privacy, safety, or property, and/or that of our affiliates, you, or other third parties.
Legal bases where required
Where data protection law requires a legal basis, we rely on performance of a contract for processing necessary to provide the Services you request, such as account access, payments, and processing your requests. We rely on legitimate interests for proportionate security, fraud prevention, service reliability, support, limited product telemetry, and getting-started emails to account holders, subject to balancing those interests against your rights. We rely on consent for optional ad-source measurement and other processing that requires consent, and on compliance with legal obligations where the law requires processing or retention. Enabling a feature does not by itself establish a lawful basis for every use of someone else's personal information.
Disclosure of personal information
We disclose personal information to the service providers and other recipients described throughout this Privacy Policy for the purposes explained here, including hosting, storage, payments, security, support, and the features you use. The following sections provide more detail:
- Service Providers: When you submit a prompt, it is passed directly to the relevant service provider (such as OpenAI, Anthropic, Sakana AI, or another LLM provider). While we do not store prompt or conversation content by default (unless you enable optional features like conversation sync or sharing), these service providers may store and process this information according to their own privacy policies. If you provide personal information within the prompts that you send, these service providers will have access to this personal information. We make reasonable efforts to minimize provider retention and support deletion through the settings each provider makes available to us. Providers operate their own infrastructure, and their handling of data remains subject to their own practices, policies, and legal obligations. For credit card processing, we use Stripe, which collects and processes payment information according to their own privacy policy.
- Aoru: When requests are routed through Aoru, it processes your prompts, conversation context, and outputs for inference, including automated prompt moderation. Aoru's privacy policy states that inputs and outputs are processed in memory, discarded when the request completes, and not used to train, fine-tune, or evaluate models. It retains content-free usage metadata and security/access logs for up to 60 days; billing and support records have separate retention periods. Its policy also permits sharing generated search queries with a search provider when Aoru's web search tool is invoked. NanoGPT relies on these provider statements and does not independently verify Aoru's internal processing or retention. See the Aoru privacy policy and Aoru terms of service.
- Astorias: Astorias publishes zero retention and no training for inference prompts and outputs, subject to legal, abuse, and security exceptions. Account, billing, and operational metadata may be retained. Astorias supports automatic prompt caching, and cross-request cache hits have been observed; its published request-only KV lifetime wording does not establish a cache retention period. Inference location has not been verified. See the Astorias privacy policy.
- Gonka24: Gonka24 is an independent broker that may process your prompts, conversation context, and outputs through the Gonka inference network and other providers. Its routes do not offer guaranteed zero data retention. Gonka24 retains data for operational, security, billing, and legal purposes without a fixed retention period. Its policy excludes training its own models on customer content by default, but third-party providers have separate policies. See the Gonka24 privacy policy and Gonka24 terms of service.
- LongCat (Meituan): When you select a model routed directly through LongCat, LongCat processes your prompts, conversation context, and outputs. This direct route is not classified as Zero Data Retention. LongCat's published terms permit use of inputs and outputs for service improvement, brand promotion, and marketing; restrictions on use for model training or improvement require a separate written arrangement. LongCat's privacy policy permits retention as reasonably necessary for its stated purposes. NanoGPT has not verified a separate no-retention or no-training arrangement for this route. See the LongCat privacy policy and LongCat platform terms.
- Hyperfusion: When you select Hyperfusion, it processes your prompts, conversation context, and outputs on its own infrastructure in Dubai, United Arab Emirates. Hyperfusion has confirmed to NanoGPT that prompts and outputs are not recorded, monitored, or used for model training, and that inference for these UAE-hosted endpoints is handled in-house. Temporary inference caching may occur in memory; Hyperfusion states that this cache can be disabled by the provider. We do not represent that caching is disabled for every request. Hyperfusion retains request metadata, including time, size, and target model, for 30 days for billing and fraud investigation. Our zero data retention classification for Hyperfusion refers to its prompt and output retention commitment; it does not exclude temporary memory caching or retention of this metadata. These statements apply to the UAE-hosted endpoints offered through NanoGPT and are based on Hyperfusion's written confirmations to us. See Hyperfusion's website for its service information.
- Netra Runtime: When you select Netra Runtime, it processes your prompts, conversation context, and outputs. Netra has committed not to use this content for model training, but does not guarantee zero data retention. See the Netra Runtime privacy policy and Netra Runtime terms of use.
- Arnict: Arnict states that prompts and outputs routed through its service are processed for inference and are not archived or used for training. Arnict confirms that temporary inference caches are held only in GPU memory (VRAM) and expire 15 minutes after last use. Account, usage and billing metadata may be retained. See the Arnict privacy policy and Arnict terms of service.
- Kitani: When requests are routed through Kitani, your prompts, conversation context, and outputs are processed through its inference platform, which may use third-party capacity. NanoGPT requires zero data retention for Qwen 3.8 27B, GLM 5.3, Kimi K3, DeepSeek V4.1 Flash, GLM 5.3 Flash Uncensored, MiMo V2.6 Flash RL, and MiMo V2.6 Pro RL requests through Kitani, including applicable thinking variants. Kitani confirms that prompts and outputs for these routes are not retained or used for training. Requests fail when no qualified ZDR deployment is available. Kitani reports encrypted inference transport (TLS) for the reviewed DeepSeek V4.1 Flash, uncensored, and MiMo RL routes. These requirements apply to these reviewed models, not every Kitani deployment. Kitani retains usage and billing metadata. See the Kitani privacy policy and Kitani terms of service.
- SCX.ai: When you select SCX (Global) or SCX (EU only), SCX processes your request under its privacy policy. SCX confirms that API prompts and outputs are not retained or used for training. SCX (EU only) restricts inference, including SCX's own fallback inference, to the EU; the Global option may process requests in other regions. SCX retains operational metadata for billing, security, and reliability.
- Pareto Inference: Pareto defaults to zero data retention for its standard inference API: prompts and outputs are not kept in persistent storage after a request finishes, and model training requires separate opt-in. Temporary in-memory prompt caching may be used; operational, security, account, and billing metadata may be retained. Upstream fallback is restricted to providers OpenRouter designates as zero data retention. See the Pareto Inference zero data retention policy for scope and exceptions, the privacy policy, and the terms of service.
- Messaging & Notification Tools: To help our team respond quickly, bug reports and suggestions you submit through our website may be forwarded to internal messaging services (such as Discord) and may include the content you choose to provide.
- Important Note on Provider Data Policies: We send providers the content and related information needed to process your request, as described above. We do not intentionally attach your NanoGPT account identity or IP address to model-provider requests, but content you submit may itself identify you. Providers may collect or store that content under their own data retention practices. We make reasonable efforts to use available retention and deletion controls, but we rely on provider statements and cannot independently guarantee their retention, deletion, or security practices. This also applies to routes labeled Zero Data Retention: ZDR is a best-effort routing classification based on the provider's claim, not independent visibility into or verification of its servers and internal setup.
- Exercise caution and avoid submitting personal or sensitive information in your prompts, especially when using models from providers with indefinite data retention policies.
- Legal Requirements: We may share limited Personal Information if required by law or to protect our rights and the safety of our users.
Aggregated and De-identified Information
We may process information in aggregated or de-identified form so it cannot reasonably be used to identify you. We use this information to:
- Analyze and improve the performance and reliability of our Services;
- Understand usage trends and feature preferences;
- Publish or share high-level statistics about our Services.
Your privacy choices
- Advertising tracking: Advertising pixels and conversion reporting have been retired. See our Advertising Policy.
- Marketing and getting-started emails: Use the unsubscribe link in any of these emails or contact us to opt out. We may still send necessary account, payment, security, and legal notices.
- Sync, sharing, and memory: Use the relevant settings to disable future syncing or memory use, delete stored items, or revoke share links. Disabling a feature is separate from deleting content already stored. Link revocation does not recall copies saved by recipients.
- API request logging and staff access: These are separate opt-ins in API-key settings. Turning off staff access revokes further access through our support tools; turning off logging or clearing logs initiates payload deletion as described above.
- PII redaction: Manage redaction in chat, account, and API-key settings or through supported request overrides. Grepture receives the original content necessary for redaction. Turning redaction off means the selected model provider may receive unredacted content. Redaction may miss personal information and is not a guarantee of anonymity.
- Provider retention: Supported settings let you require a Zero Data Retention route. Coverage and restrictions depend on the endpoint and enabled features; ZDR does not mean no billing or security metadata is processed. Anonymized routing refers to withholding attached NanoGPT account identifiers, such as your user ID or email. Personal information you include in your prompt remains visible to the provider, and provider retention and training policies still apply. Changing a routing setting does not delete earlier requests.
Withdrawing consent does not affect the lawfulness of processing based on consent before withdrawal. It does not stop processing that has another lawful basis, such as necessary billing or security records. You can separately request deletion or exercise other applicable rights below. Optional settings do not waive those rights.
Your rights and requests
Depending on location, individuals may have certain statutory rights in relation to their Personal Information. For example, you may have the right to:
- Access your Personal Information and information relating to how it is processed.
- Delete your Personal Information from our records.
- Rectify or update your Personal Information.
- Transfer your Personal Information to a third party (right to data portability).
- Restrict how we process your Personal Information.
- Withdraw your consent where we rely on consent as the legal basis for processing at any time.
- Object to how we process your Personal Information.
- Opt out of sale, sharing, or targeted advertising, and limit certain uses or disclosures of sensitive personal information, where applicable law provides these rights.
- Exercise applicable rights concerning decisions based solely on automated processing that have legal or similarly significant effects.
- Lodge a complaint with your local data protection authority.
To exercise applicable privacy rights, contact support@nanogpt.com or use the relevant controls in the Services. You do not need to create an account or use particular wording. Describe your request and provide enough information for us to locate the relevant records, such as an account email or support identifier if you have one. You may also contact us if your personal information appears in content submitted by someone else.
Where needed and permitted by law, we may request proportionate information to verify your identity or an authorized agent's authority, using information already available to us where possible. Do not send passwords, API keys, sign-in tokens, recovery phrases, or unnecessary identity documents. Requests to opt out of sale, sharing, or targeted advertising do not require the same identity verification as requests for access or deletion; we may need enough information to apply the choice to the relevant records.
We respond within the time required by applicable law. Where the EU GDPR applies, we respond without undue delay and generally within one month; complex or numerous requests may allow up to two additional months, with notice and reasons within the initial month. Where the California Consumer Privacy Act applies, requests to know, delete, or correct generally have a 45-day response period, with a further 45 days where permitted and notified. Opt-outs and requests under other laws may have different deadlines. We charge no fee unless applicable law permits one and we explain it to you.
If we cannot fully comply, we will explain the applicable reason and any available appeal or complaint options. You may ask us to review a decision by contacting the same address; where the law provides an appeal right, we will handle it under that law. You may contact your data protection authority or other competent regulator without first contacting us or completing an appeal. We will not unlawfully discriminate against you for exercising your rights.
Where we process information on a business customer's behalf, we handle requests according to our role and applicable law, including assisting that customer where required. We handle requests concerning information we hold or control and, where required, notify, instruct, or assist relevant recipients and service providers. Providers that independently control information may also need to handle a separate request. Local-only content and content encrypted with credentials unavailable to us may require action by you; this does not remove rights concerning information we hold or control.
Children
Our Services are not directed to or intended for anyone under 18, and you must be at least 18 to use them. If we learn that we have collected personal information from someone under 18, we will take reasonable steps to delete it and prevent further use of the Services.
Security and Retention
We use commercially reasonable administrative, technical, and physical safeguards designed to help protect your Personal Information. For cloud storage of media and user-uploaded content, we use Amazon Web Services (AWS) S3. Data stored in AWS is subject to AWS's Privacy Notice. No method of transmission or storage is completely secure, and we cannot guarantee the absolute security of your information or that our safeguards will prevent every instance of unauthorized access, disclosure, alteration, or loss. These limitations do not affect our obligations or your rights under applicable law. We retain personal information for as long as reasonably necessary for the purposes described in this Privacy Policy, taking account of the type of information, the features and settings you use, and applicable legal requirements. Feature-specific expiration and deletion practices are described above. Account, payment, and security records may be needed for billing, accounting, fraud prevention, dispute resolution, or legal compliance after you stop using the Services; this does not extend the content-retention periods described above.
The safety and security of your information also depends on you. If you use a password to access any part of our Services, you are responsible for keeping it confidential and for not sharing it with anyone.
Deletion and retention limits
Account closure, disabling a feature, revoking access, and deleting stored content are different actions. Account deletion removes or de-identifies selected records and initiates cleanup, but is not a promise that every record, backup, or remote object disappears immediately. A record is not necessarily anonymous merely because a name or email has been removed. You can contact us for a privacy request covering information beyond the account-deletion controls.
- Local conversation history is held on your device. Optional cloud content follows its feature-specific settings, expiry, and deletion processes described above.
- Account, payment, usage, and security records are retained according to their continuing service, accounting, fraud-prevention, dispute, or legal purpose. Support messages and attachments may be retained to handle the request and related follow-up or disputes.
- Stored imports and media may require separate cleanup from local library or account deletion. Information in your own storage is also subject to your storage configuration and lifecycle.
- Deletion from active systems may precede physical removal from storage or backups. Cleanup failures can require retries. Any retention exception must have an applicable purpose and legal basis; a legal preservation obligation may limit deletion for the information it covers.
Processing locations
NanoGPT is a U.S. company, and our Services and providers may process information in the United States and other countries. Processing locations depend on the feature and provider route. An EU inference option does not by itself mean that account, billing, support, or every other processing stage remains in the EU. International transfers are subject to applicable legal requirements. Contact support@nanogpt.com for information about the relevant processing locations and applicable transfer safeguards. This policy does not represent that every provider offers the same regional or contractual protections.
Third-Party Services
Our Services may link to or integrate with third-party websites, applications, or services. Those services have their own privacy policies governing their independent processing of information, and we do not control those independent practices. Our collection and disclosure of information to these services is described in this Privacy Policy, and our responsibilities under applicable law continue to apply. Please review the applicable privacy policies of any third-party services you use.
- Web Search & Browsing Providers: Linkup Privacy Policy, Tavily Privacy Policy, Exa Privacy Policy, Kagi Privacy Policy, Brave Search Privacy Notice, Perplexity Privacy Policy, Valyu Privacy Policy.
- Audio & Media Generation: Some audio, image, and video generation features use third-party providers (such as FAL AI, Runware, WaveSpeed, and Replicate) to process prompts or media inputs and return outputs. Data shared with these providers is subject to their respective privacy policies: FAL AI Privacy Policy, Runware Privacy Policy, WaveSpeed Privacy Policy, Replicate Privacy Policy.
- Content Extraction & Transcripts: Firecrawl Privacy Policy, YouTube Transcript Privacy Policy.
- AI Detection & Plagiarism Checks: Pangram Privacy Policy.
- PII Redaction: Grepture Privacy Policy, Grepture Terms of Service, Grepture Subprocessors, and Grepture Impressum.
- Payment Providers: Stripe Privacy Policy, BTCPay Server Privacy Policy, Nanswap Privacy Policy, BoomFi Privacy Policy.
Changes to this Privacy Policy
We may update this Privacy Policy from time to time by posting the revised policy and updating the date on this page. Updates apply prospectively, subject to applicable notice and consent requirements. We will provide any notice and obtain any consent required by law before a change requiring that notice or consent takes effect. Posting an update does not itself authorize a new use of information that requires consent. You may request prior versions through our contact address below.
How to contact us
If you have any questions or concerns about this Privacy Policy, please contact our NanoGPT Support Team at support@nanogpt.com.
List of AI Model Providers Terms
AI Model Provider Terms: When using our Services, depending on which model is used, you agree to abide by the terms of the respective AI model providers:
- 01.AI: If you use 01.AI models, you agree to abide by the 01.AI terms.
- AionLabs: If you use AionLabs models, you agree to abide by the AionLabs terms.
- Alibaba: If you use Alibaba models, you agree to abide by the Alibaba Cloud terms.
- Amazon Bedrock: If you use Amazon Bedrock models, you agree to abide by the AWS Service terms.
- Ambient: If you use Ambient models, you agree to abide by the Ambient terms of service, Ambient privacy policy, and Ambient data handling policy.
- AtlasCloud: If you use AtlasCloud models, you agree to abide by the AtlasCloud privacy policy.
- Baseten: If you use Baseten models, you agree to abide by the Baseten terms of service and Baseten privacy policy.
- Baidu: If you use Baidu models, you agree to abide by the Baidu AI terms.
- Anthropic: If you use Anthropic models, you agree to abide by the Anthropic usage terms.
- Aoru: If your requests are routed through Aoru, your use is subject to the Aoru terms of service, including its acceptable-use restrictions, and Aoru privacy policy.
- Arcee AI: If you use Arcee AI models, you agree to abide by the Arcee AI privacy policy.
- Arli AI: If you use Arli AI models, you agree to abide by the Arli AI terms.
- Azure: If you use Azure models, you agree to abide by the Microsoft terms of use.
- Chutes: If you use Chutes models, you agree to abide by the Chutes terms.
- Cerebras: If you use Cerebras models, you agree to abide by the Cerebras privacy policy.
- Cloudflare: If you use Cloudflare models, you agree to abide by the Cloudflare terms of service and Cloudflare privacy policy.
- Celeris: If you use Celeris models, your request and response content is processed under the Celeris privacy policy and Celeris terms of service.
- Pokee: If you use Pokee-Isaac, your request and response content is processed under the Pokee privacy policy and Pokee terms of service. Pokee states that developer API prompts and outputs are not used for training. Its infrastructure provider retains an approximately 120-character preview of each message for 1 day and stores the encrypted raw request payload for up to 7 days before automatic deletion.
- Abliteration.ai: If you use an Abliteration.ai model, your request and response content is processed under the Abliteration.ai privacy policy, terms of service, and data-handling policy. Abliteration.ai states that API prompts and completions are processed transiently, are not stored, and are not used for training. NanoGPT relies on that provider statement.
- Cohere: If you use Cohere models, you agree to abide by the Cohere terms of use.
- CoreWeave: If you use CoreWeave-routed models, you agree to abide by the CoreWeave Terms of Service, Data Processing Agreement, and Privacy Policy.
- Crusoe: If you use Crusoe models, you agree to abide by the Crusoe terms of service and Crusoe privacy policy.
- Decart: If you use Decart models, you agree to abide by the Decart terms of service and Decart privacy policy.
- DeepInfra: If you use DeepInfra models, you agree to abide by the DeepInfra terms.
- DeepSeek: If you use DeepSeek models, you agree to abide by the DeepSeek terms of use.
- DekaLLM: If you use DekaLLM models, you agree to abide by the DekaLLM terms of service and DekaLLM privacy policy.
- Darkbloom: If a model request is routed through Darkbloom, its request and response content is processed under the Darkbloom privacy policy and terms of service. Darkbloom says ordinary coordinator logs are designed not to contain prompt content and does not claim general-purpose training rights, but its policy permits operational retention and exceptions for support, abuse review, legal compliance, and disputes. Its terms state that end-to-end encryption between consumer and provider is not currently guaranteed.
- DigitalOcean: If you use DigitalOcean models, you agree to abide by the DigitalOcean Privacy Policy and DigitalOcean Terms of Service.
- Modal: If you use Modal models, you agree to abide by the Modal privacy policy and Modal terms of service.
- Doubao: If you use Doubao models, you agree to abide by the Doubao terms.
- FAL: If you use FAL models, you agree to abide by the FAL terms of service.
- Featherless: If you use Featherless models, you agree to abide by the Featherless terms.
- RouteCortex: If a model request is routed through RouteCortex, its request and response content is processed under the RouteCortex privacy policy and terms of service. RouteCortex states that prompts and completions are processed in memory and are not logged.
- Fireworks: If you use Fireworks models, you agree to abide by the Fireworks terms of service.
- Friendli: If you use Friendli models, you agree to abide by the Friendli terms of service and Friendli privacy policy.
- Gemini: If you use Gemini models, you agree to abide by the Gemini usage terms.
- Hyperfusion: If you select Hyperfusion, your use is subject to the applicable model licenses and Hyperfusion's service terms. The Hyperfusion entry in the information-sharing section above explains its commitments for NanoGPT requests, including UAE processing, prompt/output handling, temporary memory caching, and 30-day request-metadata retention. See Hyperfusion's website for its service information.
- Gonka24: If you select Gonka24, your use is subject to the Gonka24 terms of service and Gonka24 privacy policy.
- Gerra: If you use Gerra models, you agree to abide by the Gerra privacy policy.
- Greenference: Model requests may be processed by Greenference under its terms and data policy.
- ZenMux: If a model is routed through ZenMux, your request and response content is processed under the ZenMux privacy policy and ZenMux terms of service. ZenMux does not currently publish a model-API zero-retention or training guarantee, so avoid including sensitive information.
- GMICloud: If you use GMICloud models, you agree to abide by the GMICloud terms and conditions.
- Gondola / Venice: If a model request is routed through Gondola, its request and response content may be processed by Gondola and its Venice upstream under the Gondola privacy policy, Gondola terms of service, Venice privacy policy, and Venice terms of service.
- Google Vertex: If you use Google Vertex AI models, you agree to abide by the Google Cloud terms.
- Google AI Studio: If you use Google AI Studio models, you agree to abide by the Google Cloud terms.
- Groq: If you use Groq models, you agree to abide by the Groq terms of use.
- H Company: If you use H Company models, you agree to abide by the H Company privacy policy.
- Hyperbolic: If you use Hyperbolic models, you agree to abide by the Hyperbolic privacy policy.
- Infermatic: If you use Infermatic models, you agree to abide by the Infermatic privacy policy.
- Inflection: If you use Inflection models, you agree to abide by the Inflection developer terms.
- Inceptron: If you use Inceptron models, you agree to abide by the Inceptron privacy policy and Inceptron terms of service.
- IONOS: Requests to models hosted by IONOS CLOUD are processed on its infrastructure in Germany. According to its AI Model Hub data handling policy, prompts and outputs are not logged or retained, used for training, or shared with model developers. IONOS records billing and operational metadata, including timestamps, model names, and token counts.
- Io Net: If you use Io Net models, you agree to abide by the io.net terms and io.net privacy policy.
- Lucidity (Synth): Prompts and conversation context submitted to Synth 2.5 Flash Preview or Synth 2.5 Pro Preview are sent to Lucidity for inference. Lucidity has directly confirmed zero data retention for Synth API requests made through NanoGPT: prompts and outputs are not retained or used for training. See the Lucidity privacy policy and Lucidity terms of service.
- LLM Tech: If you select LLM Tech, your request and response content is processed under the LLM Tech privacy policy and terms of service. LLM Tech states that model content is processed in volatile memory with zero content retention and is not used for training. Its current EU path uses a Hetzner edge in Nuremberg, Germany, and a dedicated GPU rented from Seeweb S.r.l. in Italy. LLM Tech describes the GPU site as temporary and has committed to advance notice before another EU move.
- Mancer: If you use Mancer models, you agree to abide by the Mancer terms of service and Mancer privacy policy.
- Mara: If you use Mara models, you agree to abide by the Mara AI policies.
- Minimax: If you use Minimax models, you agree to abide by the Minimax terms of service.
- Mistral: If you use Mistral models, you agree to abide by the Mistral terms of use.
- Mixlayer: If you use Mixlayer models, you agree to abide by the Mixlayer terms of service and Mixlayer privacy policy.
- ModelRun: If you use ModelRun models, you agree to abide by the ModelRun terms of service and ModelRun privacy policy.
- Moonshot AI: If you use Moonshot AI models, you agree to abide by the Moonshot AI privacy policy.
- Morph: If you use Morph models, you agree to abide by the Morph terms of service and Morph privacy policy.
- MegaNova: If you use MegaNova models, you agree to abide by the MegaNova privacy policy.
- NCompass: If you use NCompass models, you agree to abide by the NCompass terms of service and NCompass privacy policy.
- Nebius: If you use Nebius models, you agree to abide by the Nebius terms of service and Nebius privacy policy.
- NextBit: If you use NextBit models, you agree to abide by the NextBit terms of service and NextBit privacy policy.
- Neuralwatt: If you use Neuralwatt models, you agree to abide by the Neuralwatt terms of service and Neuralwatt privacy policy.
- NovitaAI: If you use NovitaAI models, you agree to abide by the NovitaAI terms of service.
- Meta: If you use Meta Llama models, you agree to abide by the Meta privacy policy.
- OpenAI: If you use OpenAI models, you agree to abide by the OpenAI usage terms.
- Pangram: If you use Pangram AI detection or plagiarism checking, you agree to abide by the Pangram privacy policy and Pangram terms of service.
- Perplexity: If you use Perplexity models, you agree to abide by the Perplexity usage terms.
- Phala: If you use Phala models, you agree to abide by the Phala Cloud privacy policy and Phala Cloud terms.
- Poe: If you use Poe models, you agree to abide by the Poe terms of service and Poe privacy policy.
- PolyChat: If you use PolyChat models, you agree to abide by the PolyChat privacy policy.
- Poolside: If you use Poolside models, you agree to abide by the Poolside privacy policy.
- Replicate: If you use Replicate models, you agree to abide by the Replicate terms.
- SambaNova: If you use SambaNova models, you agree to abide by the SambaNova terms and conditions.
- Sakana AI (Fugu): If you use Sakana AI or Fugu models, you agree to abide by the Fugu Privacy Policy, Sakana Fugu Terms of Service, and Sakana Fugu Usage Policy.
- Sail Research: If you use Sail Research models, you agree to abide by the Sail Research Data Processing Addendum.
- StepFun: If you use StepFun models, you agree to abide by the StepFun privacy policy, StepFun terms of service, and StepFun data processing agreement.
- SiliconFlow: If you use SiliconFlow models, you agree to abide by the SiliconFlow privacy policy.
- StreamLake: If you use StreamLake models, you agree to abide by the StreamLake privacy policy and StreamLake user service agreement.
- TensorX: If you use TensorX models, you agree to abide by the TensorX terms and TensorX privacy policy.
- Together: If you use Together models, you agree to abide by the Together terms of service.
- Uomi: If you use Uomi models, you agree to abide by the Uomi terms of service and Uomi privacy policy.
- Venice: If you use Venice models, you agree to abide by the Venice terms of service and Venice privacy policy.
- Relace: If your model request is routed through Relace, its request and response content may be processed by Relace under the Relace privacy policy and Relace terms of use.
- Reka: If your model request is routed through Reka, its request and response content may be processed by Reka under the Reka privacy policy and Reka terms of use.
- PrimeIntellect: If your request is routed through PrimeIntellect, its content may be processed under the Prime Intellect terms of service and privacy policy. Inference-specific retention, training guarantees, and processing locations have not been verified.
- Tenstorrent: The console terms linked by OpenRouter permit logging inputs and outputs and using them for training and optimization. Separate retention and training guarantees for OpenRouter inference have not been verified. See the Tenstorrent privacy policy; do not assume zero retention or exclusion from training.
- Wafer: If you use Wafer-routed models, you agree to abide by the Wafer privacy policy, Wafer terms of service, and Wafer's Zero Data Retention commitments where applicable.
- Weights & Biases: If you use Weights & Biases models, you agree to abide by the Weights & Biases terms of service and Weights & Biases privacy policy.
- SpaceXAI: If you use SpaceXAI models, you agree to abide by the SpaceXAI Privacy Policy and SpaceXAI Terms of Service.
- Xiaomi: If you use Xiaomi models, you agree to abide by the Xiaomi privacy policy.
- Z.AI: If you use Z.AI models, you agree to abide by the Z.AI terms of service and Z.AI privacy policy.
- Akash: If you use Akash models, you agree to abide by the Akash privacy policy.
- Fetch AI: If you use Fetch AI models, you agree to abide by the Fetch AI privacy policy.
- Inception: If you use Inception models, you agree to abide by the Inception privacy policy.
- OpenRouter: If you use OpenRouter models, you agree to abide by the OpenRouter privacy policy.
- Parasail: If you use Parasail models, you agree to abide by the Parasail privacy policy.
- Pareto Inference: If you use Pareto Inference models, you agree to abide by the Pareto Inference terms of service and Pareto Inference privacy policy.
- Astorias: If you use Astorias models, you agree to abide by the Astorias terms of service and Astorias privacy policy.
- Redpill: If you use Redpill models, you agree to abide by the Redpill privacy policy.
- Tinfoil: If you use Tinfoil models, you agree to abide by the Tinfoil privacy policy.
- YouTube Transcript: If you use YouTube Transcript, you agree to abide by the YouTube Transcript privacy policy.
- Firecrawl: If you use Firecrawl, you agree to abide by the Firecrawl privacy policy.
- Runware: If you use Runware models, you agree to abide by the Runware privacy policy.
- WaveSpeed: If you use WaveSpeed models, you agree to abide by the WaveSpeed privacy policy.
- Zai: If you use Zai models, you agree to abide by the Zai privacy policy.