SearchQ
Legal

Privacy Policy

How SearchQ, Inc. collects, uses, shares, and protects personal information when you use the SearchQ AI chat service, plus your privacy choices under U.S. (including California) and international law.

Last updated: June 9, 2026

This Privacy Policy explains how SearchQ, Inc. ("SearchQ", "we", "us", or "our") collects, uses, shares, and protects personal information when you use our AI chat website, applications, browser extensions, mobile apps, APIs, and related services (collectively, the "Service"). It applies to the Service and is incorporated into our Terms of Service.

We do not use your chats to train AI models, and for every model that supports it we enforce Zero Data Retention so the AI provider does not store your prompts or responses. See Section 4 below for details.

1. Who is the Controller of Your Information

SearchQ, Inc., a Delaware corporation, is the controller (or, under U.S. state laws, the business) of personal information collected through the Service. You can reach us at [email protected].

2. Information We Collect

2.1 Information you provide

  • Account information. When you create an account, we collect your name, email address, profile image, and the authentication identifier from your chosen provider (Google, or an email one-time password). Anonymous guests do not provide account information.
  • Chat content. The prompts, messages, files, attachments, and other content you submit to the Service ("Inputs") and the responses the Service generates back to you ("Outputs").
  • Payment information. If you subscribe to a paid plan, our payment processor, Stripe, collects and processes your payment-card or other payment-method details directly. SearchQ does not store full card numbers on its servers; we store only a billing identifier and the subscription metadata returned by Stripe.
  • Support and feedback. Messages you send through the in-product Support and Feedback forms, including any contact details and the email address used to reply.

2.2 Information we collect automatically

  • Usage data. Records of your interactions with the Service, including which models you select, message counts, token counts, timestamps, conversation IDs, feature usage, and error events. Cost-accounting events are recorded per message.
  • Device and connection data. IP address, user-agent string, browser type, operating system, device identifiers, language, time zone, and the referring URL.
  • Cookies and similar technologies. We use a small number of strictly necessary cookies to keep you signed in, remember your sidebar state, and protect against CSRF. We may also use first-party analytics and product-telemetry cookies described in Section 11.
  • Logs. Standard server logs (request timestamps, paths, status codes) for security, debugging, and abuse detection.

2.3 Information from third parties

  • Single sign-on providers. If you sign in with Google, we receive the basic profile information you authorize that provider to share (typically name, email, and avatar URL).
  • Payment processor. Stripe sends us subscription status, plan, billing-period anchor, and invoice metadata, but not your full payment-method details.

3. How We Use Information

We use personal information to:

  • Provide and operate the Service — route your Inputs to the model provider you selected, return Outputs, store your conversation history, and enforce per-plan usage limits;
  • Authenticate you and protect your account;
  • Process payments, manage subscriptions, and prevent fraud;
  • Communicate with you about your account, security alerts, billing, and transactional matters (we do not send marketing email by default);
  • Respond to support requests and feedback;
  • Monitor, secure, and improve the Service, including diagnosing errors and analyzing aggregated usage patterns;
  • Comply with law and enforce our Terms.

We process this information based on the legal grounds of contractual necessity (to provide the Service you requested), our legitimate interests (security, abuse prevention, product analytics), your consent (where required), and our legal obligations.

4. AI Training and Zero Data Retention

We do not use your Inputs or Outputs to train, fine-tune, or evaluate our or any third party's foundation models. Your Inputs and Outputs are transmitted to the upstream model providers reached through OpenRouter (such as OpenAI, Anthropic, and Google) solely to generate a response, and are subject to those providers' own data-handling policies — most of which similarly prohibit training on API traffic by default. We do, however, use aggregated, de-identified usage metrics (such as model counts, token counts, and error rates) to operate, scale, and improve the Service.

Zero Data Retention (ZDR). For every model that supports it, we route your Inputs and Outputs only to upstream endpoints that operate under Zero Data Retention: the provider processes your request to generate a response and does not store your Inputs or Outputs afterward, and cannot use them for training. We enforce this on a per-request basis through OpenRouter's ZDR routing. A small number of models do not offer a ZDR endpoint (for example, certain xAI (Grok) models); those models remain available, but route to providers that may retain your Inputs and Outputs under the provider's own policy. If you want a conversation restricted to ZDR-capable models only, use Incognito Mode, described below. If our ZDR routing information is temporarily unavailable, we fail safe by enforcing ZDR on all models.

Incognito Mode

Incognito Mode lets you have a conversation that is not retained. When you start a chat in Incognito Mode:

  • ZDR-only models. The chat is restricted to models with a Zero Data Retention endpoint, and every request is routed under ZDR as described above.
  • No chat history. The conversation is not saved to your chat history and does not appear in history search.
  • No tracing. We do not send the conversation to our AI-observability provider (Langfuse, see Section 5); no observability trace of the conversation is recorded.
  • Deleted when you close the tab. Closing the tab marks the chat for deletion within about a minute, and a daily cleanup permanently removes it — an incognito chat is retained for at most approximately twenty-four (24) hours after it is created.
  • Web search. If the model uses web search to answer your question, the search queries it generates are still processed by our web-search provider (see Section 5) in order to produce the answer.
  • Billing records. We retain de-identified billing records (token counts and cost — never conversation content) for the accounting purposes described in Section 6.

5. How We Share Information

We do not sell your personal information, and we do not "share" your personal information for cross-context behavioral advertising as those terms are defined under California law. We disclose personal information only in these limited circumstances:

  • Service providers (sub-processors). We engage trusted vendors to operate the Service. The current categories and identities include:

    • OpenRouter and the model providers it routes to (OpenAI, Anthropic, Google, and others) — model inference;
    • Stripe — payment processing and subscription management;
    • Langfuse (Langfuse Cloud, US region) — AI observability and tracing;
    • Tavily and similar web-search providers — when you enable web-search tools;
    • Vercel and Railway — application hosting and deployment;
    • Resend or similar — transactional email delivery;
    • Datafast and similar — product analytics.

    These vendors are contractually obligated to use personal information only to provide their services to us.

  • Legal compliance. We may disclose information if we believe in good faith that disclosure is necessary to comply with a law, regulation, legal process, or governmental request; to enforce our Terms; or to protect the rights, property, or safety of SearchQ, our users, or the public.

  • Corporate transactions. If SearchQ is involved in a merger, acquisition, financing, reorganization, or sale of assets, personal information may be transferred as part of that transaction, subject to standard confidentiality protections and notice to you where required.

  • With your consent. For any other purpose disclosed to you and to which you consent.

6. Data Retention

We keep personal information only as long as we need it for the purposes described in this Policy:

  • Account data and chat content for signed-in users: kept for the life of your account and deleted (or de-identified) when you close your account, subject to limited backups described below.
  • Anonymous (signed-out) sessions: automatically deleted approximately 30 days after the underlying session expires.
  • Incognito Mode chats: marked for deletion within about a minute of closing the tab and permanently removed by a daily cleanup — at most approximately 24 hours after the chat is created (see Section 4). De-identified billing records are retained as described below.
  • Cost-accounting and billing records: retained in de-identified form for as long as required for tax, accounting, audit, and dispute-resolution purposes — generally up to seven (7) years.
  • Support correspondence: retained for up to two (2) years after the issue is resolved.
  • Backups and logs: routine backups may persist for up to thirty (30) days after deletion from production systems.
  • Model-provider inference: For the AI models routed under Zero Data Retention (see Section 4), the upstream provider does not retain your Inputs or Outputs after generating a response. For the limited set of non-ZDR models, retention by the upstream provider is governed by that provider's own policy.

You can delete your account at any time from Settings → General → Delete account, which removes your account data, chat content, and per-user usage records from production systems. De-identified, aggregated records and the limited audit records described above may persist.

7. Security

We use technical and organizational measures designed to protect personal information, including TLS in transit, encryption at rest where supported by our infrastructure, principle-of-least-privilege access controls, audit logging, and standard application-security practices. No method of transmission or storage is perfectly secure, and we cannot guarantee absolute security. Please use a strong, unique password for any third-party account you connect to the Service, and notify us at [email protected] if you suspect your account has been compromised.

8. Children's Privacy

The Service is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child under 13 has provided us personal information, please contact [email protected] and we will delete it promptly. If you are between 13 and the age of majority in your jurisdiction, you may use the Service only with the involvement and consent of a parent or legal guardian who has agreed to our Terms.

9. International Data Transfers

SearchQ is based in the United States, and the Service and our service providers operate primarily in the United States. If you access the Service from outside the U.S., you understand that your personal information will be transferred to, stored, and processed in the United States and other countries that may not provide the same level of data protection as your country. Where required (for example, for personal information transferred from the EEA, UK, or Switzerland), we rely on appropriate transfer mechanisms such as the European Commission's Standard Contractual Clauses.

10. Your Privacy Rights

Depending on where you live, you may have the following rights regarding your personal information:

10.1 All users

  • Access and download the personal information we hold about you;
  • Correct inaccurate information (you can update most account fields in Settings);
  • Delete your account and associated personal information from Settings → General → Delete account;
  • Export your chat history (available in Settings where supported).

10.2 California residents (CCPA / CPRA)

In addition to the rights above, California residents have the right to:

  • Know what personal information we have collected, used, disclosed, and (if applicable) sold or shared about them, including the categories, sources, purposes, and recipients;
  • Delete personal information, subject to certain exceptions;
  • Correct inaccurate personal information;
  • Limit the use of sensitive personal information to what is necessary to provide the Service (we do not use sensitive personal information for any secondary purpose);
  • Opt out of "sale" or "sharing"we do not sell or share personal information as those terms are defined under the CCPA;
  • Non-discrimination — we will not deny service, charge different prices, or provide a different level of service because you exercise your privacy rights.

To exercise these rights, email [email protected] or use the in-product controls. We will verify your request using information already on file (such as control of the account email) before fulfilling it. You may use an authorized agent; we may require proof of authorization.

10.3 EEA, UK, and Switzerland (GDPR / UK GDPR)

If you are in the EEA, UK, or Switzerland, you also have the right to access, rectify, erase, restrict or object to the processing of your personal information, and to data portability. Where we rely on consent, you may withdraw that consent at any time without affecting prior lawful processing. You also have the right to lodge a complaint with your local supervisory authority.

10.4 Other U.S. states

Residents of Virginia, Colorado, Connecticut, Utah, Texas, and other U.S. states with comprehensive privacy laws have similar rights of access, correction, deletion, and opt-out, exercisable through the methods above.

11. Cookies and Similar Technologies

We use the following categories of cookies and similar technologies:

  • Strictly necessary — required for the Service to function, including session cookies (Better Auth), sidebar-state preference, CSRF protection, and the anonymous-guest identifier;
  • Preferences — remember your theme, locale, and other display settings;
  • Analytics and product telemetry — first-party metrics that help us understand aggregated usage and improve the Service (see Datafast in Section 5).

We do not use cookies for cross-site behavioral advertising. You can configure your browser to block or delete cookies, but doing so may affect parts of the Service.

12. Do Not Track and Global Privacy Control

The Service does not respond to "Do Not Track" browser signals, because there is no industry consensus on how to interpret them. We do honor recognized opt-out preference signals such as the Global Privacy Control (GPC) as an opt-out of "sale" or "sharing" of personal information for California residents (which, again, we do not engage in by default).

13. Third-Party Links and Integrations

The Service may link to or integrate with third-party websites and services (for example, Stripe's checkout, or web pages returned by web-search tools). Those third parties have their own privacy policies, which we encourage you to review. We are not responsible for the privacy practices of third parties.

14. Changes to this Policy

We may update this Policy from time to time. If we make material changes, we will provide notice (for example, by email or in-product). The "Last updated" date at the top reflects the most recent update. Your continued use of the Service after a change takes effect constitutes acceptance of the updated Policy.

15. Contact Us

If you have any questions about this Privacy Policy or our privacy practices, or wish to exercise any of the rights described above, contact:

SearchQ, Inc.

Email: [email protected]