Smack PCP Privacy Policy
DRAFT — placeholder until reviewed terms are published
This draft describes the current guest implementation. It is not a reviewed privacy notice. Provider retention, operator contact details and launch-region rights disclosures must be reviewed before public launch.
On your device
- A signed, HTTP-only guest cookie identifies your guest session. The cookie has a 180-day expiry; the server treats a guest as expired after 30 idle days.
- Guest messages and chat history are kept in this tab's session storage, survive reloads and normally disappear when the tab closes. Browser session restoration can restore them. There is no account sync.
- Display and sound settings remain in local storage. Legacy local chat data, if present, is neither read nor imported by this version.
On the Smack server
- A monthly-rotating IP pseudonym is used for abuse controls. Smack does not store the raw IP address in its database or application logs.
- Guest identity and consent records, including the accepted version and age, terms and tone confirmations.
- Per-conversation safety state, safety epoch and turn count, without a user transcript.
- Smack's delivered replies and request outcomes for 7 days for duplicate-request protection. Request metadata includes identifiers and a payload hash, not the original guest message or history.
- A usage and cost ledger kept for 13 months for accounting. Unresolved accounting holds may retain supporting records until resolved.
Guest messages and chat history are not stored on the server. They are processed in memory to generate replies and perform safety checks. Delivered Smack replies are the exception described above, retained for duplicate-request protection rather than as a chat-history service.
Guests and conversations expire after 30 idle days; rate and quota counters have a 35-day retention window. The bounded purge process removes eligible records and associated consent and safety data. These windows depend on the operator running that process; automated scheduling remains release work.
Model providers
When the live provider is enabled, messages and the recent conversation context needed for a reply are sent to xAI. Optional moderation sends text to OpenAI if enabled. Local mock mode does not send messages to either provider. These providers have their own data handling and retention terms; this draft makes no zero-retention promise.
Logs and control
Application logs record operational metadata such as response status, latency, policy decisions and cost, not message content or raw IP addresses. Hosting and model providers may process network information independently. You can clear site data in your browser to remove local history, settings and the guest cookie; this does not delete the server's retained accounting records.