Short form: chats are never training data.
EFFECTIVE 2026-01-01This is the actual privacy commitment. Not the marketing summary. If you spot anything here that contradicts what you see in-product, the in-product behavior is a bug — email us and we'll fix it.
What we collect.
Account email, hashed password, and — if you paid — the Stripe customer ID we get back after payment. That's it for the human-identifiable data. We do not ask for a phone number, address, birthday, or job title.
We store your chat history so you can find it again in the sidebar. It is server-side encrypted at rest.
What we don't do.
We do not use your chats to train Anthropic's public models, our own models (we have none), or any third party's models. This is not opt-out — it is off, by default, for everyone.
We do not sell, license, or share your chats with advertising networks, data brokers, or partner companies. There are no such partners.
Who processes your chats to answer them.
Anthropic. When you send a message, we forward it to Anthropic's API on your behalf, they stream a response back, we stream it to you, and both sides retain what they need to serve you and satisfy their own security & abuse policies. Anthropic's data-handling terms for API customers apply and are linked below.
Payment data.
Stripe handles it end-to-end. We never see your card number, CVC, or bank routing details. We see a customer ID and a subscription status. Stripe's data policy applies to your card details.
Cookies.
We set one session cookie so you stay logged in. There is no analytics cookie, no marketing pixel, no A/B test cookie, no third-party script. If we ever add analytics, it will be a self-hosted, IP-anonymized tool and we'll say so here.
Deleting your data.
Cancel your subscription and email us — or hit Settings → Delete account. The account and its chat history enter a 30-day soft-delete window (recoverable by emailing us within that window), then are hard-deleted from our primary database and any residual logs. Backups roll off within 30 days after that.
Anthropic's retention window on API traffic runs separately from ours; check their published policy for that timeline. Stripe retains payment records per its own compliance schedule (typically 7 years for tax audit purposes) — payment records include the amount charged and the customer identifier, not chat content.
Workspaces (teams).
A workspace is a shared billing + membership boundary. When you create or join a workspace, three things change and nothing else:
- Workspace admins can see the list of members, the billing history for the workspace's Stripe subscription, and the count of chats/messages per workspace (for the impact report). They cannot read the content of anyone's chats.
- An admin can publish "workspace knowledge" (shared text notes) and "workspace instructions" (voice / house-style rules for the AI). Both are visible to every member of the workspace and are injected into the AI system prompt for chats sent inside the workspace.
- Chats you send inside a workspace are tagged with the workspace ID for the admin's impact-report tally. The content of those chats is still readable only by you. Not the admin, not other members, not us beyond the operational access described in section 03.
Copy anchor we use everywhere: Team resources are shared. Team conversations are yours. This is enforced at the database layer (row-level security), not by policy.
Contact.
Email privacy@ladle.chat. We reply in person, not from an automated queue. This address is also our Data Protection Officer contact for GDPR / UK-GDPR purposes — messages get to the same human, and DPO responses are handled with the same in-person response.