RGPD / GDPR
Privacy policy
2026-09 · The Spanish version governs where both exist.
The short version
We cannot read your chats. Conversation content is encrypted on your device before it is stored or synced, and our servers keep only ciphertext they cannot open. We keep no plaintext logs of prompts or replies. There is nothing to sell, subpoena or leak.
Controller and contact
Demimonde is created and operated by a single individual: [LEGAL NAME], NIF [NIF], [STREET, POSTCODE CITY], Spain (trade name: Demimonde). Data protection contact: [email protected]. No data protection officer has been appointed; the applicable law does not require one for this processing, and your message reaches the operator directly.
You may lodge a complaint at any time with the Spanish Data Protection Agency (AEPD, aepd.es) or with the supervisory authority of your habitual residence.
What we process
Account metadata: a random user identifier, plan tier, account status, country code where jurisdiction blocking applies, and timestamps.
Credentials: salted argon2id hashes of your master key and recovery codes (the keys themselves are never stored), TOTP secrets kept encrypted, and public keys for passkeys.
Session and device metadata: a device label derived from your browser's user agent, session timestamps and expiry.
Billing records: ledger entries, payments, subscriptions and invoices, including the tax data the law requires.
Usage metadata: model name, input/output token counts, latency, status code and route (web or API). No prompt text, no reply text, no embeddings of content.
Encrypted sync blobs: ciphertext produced on your device with a key we never receive.
Network data: your IP address, used transiently to prevent abuse. At most a salted hash is retained, for no longer than 24 hours.
Optional email address, only if you choose to add one.
Purposes and lawful bases
Performance of the contract (Art. 6(1)(b) GDPR): creating and operating your account, storing your encrypted sync blobs, metering usage, billing you and delivering the service you asked for.
Legal obligation (Art. 6(1)(c) GDPR): issuing invoices, keeping accounting and tax records, and answering lawful requests from authorities.
Legitimate interests (Art. 6(1)(f) GDPR): preventing abuse, fraud and attacks; rate limiting; enforcing The Floor; keeping the service secure and available. We use request counts and hashed identifiers, never conversation content.
Consent (Art. 6(1)(a) GDPR): storing an optional email address and using it for receipts or security notices, any marketing message, and any analytics beyond aggregate, cookieless page views. You may withdraw consent at any time without affecting the lawfulness of prior processing.
What we never do
We do not store, index, scan or read your conversation content in plaintext on our servers. We do not use your content to train models or build advertising profiles. We do not sell, rent or share personal data for advertising. There is no tracking pixel, no third-party analytics script and no fingerprinting.
Recipients and processors
We share data only where necessary, and only with providers acting as processors under our instructions: hosting and application compute (Vercel), a managed database (Neon), container compute for the API gateway, inference compute, payment processing (Stripe), and a transactional email provider if you add an email address. When a crypto payment option is offered, a specialised crypto payment processor handles it.
The gateway and inference providers necessarily process the prompt in memory to generate a response. They receive no stored history, no identity and no billing data, and the operator's systems retain no copy of the content.
A self-hosted analytics service, if enabled, records aggregate page views and referrers without cookies or identifiers, and is never joined to accounts. We do not sell personal data.
International transfers
Some processors operate outside the EEA. Where personal data is transferred, the transfer relies on an adequacy decision of the European Commission, on the EU-US Data Privacy Framework where the recipient is certified, or on the Standard Contractual Clauses together with supplementary measures. You can request a copy of the applicable safeguards at the contact address above.
Retention
Session metadata: 30 days after the session expires.
Usage events: 24 months, for accounting and capacity planning.
Billing records and invoices: the statutory period (up to 6 years under Spanish commercial law and 4 years for tax).
Hashed network identifiers used for abuse prevention: at most 24 hours.
Encrypted sync blobs: until you delete them, trigger a panic wipe, or erase your account. Backup copies, where they exist, are purged within 30 days.
Optional email: until you remove it or erase your account.
Security
The service uses TLS in transit, argon2id for credential hashing, XChaCha20-Poly1305 for sync blobs, constant-time comparisons for secrets and least-privilege access. The architecture is designed so that even a breach exposes as little as possible: no plaintext conversations exist server-side to steal.
Your rights
You have the rights of access, rectification, erasure, restriction of processing, portability and objection, and the right to withdraw consent. Export and erasure are self-service in Settings and take effect immediately; you may also write to [email protected].
We answer within one month. Because accounts are anonymous, tell us your user ID if you can; if you cannot, we may be unable to identify you, which is the direct consequence of not holding identity data.
If you believe we have not handled your request correctly you may complain to the AEPD (aepd.es).
Children
The service is reserved for people aged 18 or over. Accounts are anonymous by design and carry no identity documents; if we learn that an account belongs to a minor, it is terminated and its data erased.
Automated decisions and profiling
We do not carry out profiling and there is no automated decision-making with legal effects. Rate limiting and abuse prevention operate on request counts, never on who you are or what your conversations contain.
Where the data comes from
Personal data comes from you and your device. Providing it is necessary to perform the contract: without an account identifier there is no account to use. The email address is entirely optional. Country codes may be derived from network geolocation solely to enforce jurisdiction blocks.
Personal data breaches
If a breach affecting personal data occurs, we notify the AEPD within 72 hours and, where the risk is high, the affected users without undue delay, in line with Article 34 GDPR.
Changes to this policy
Changes are published on this page with a new date. Material changes are announced on the site. The Spanish version governs where the two differ.