Privacy policy.
Effective 1 October 2026
DarkGPT is an early-access AI workspace. This page explains the data it needs, where your messages go, and the choices you have. The operator of darkgpt.surf is responsible for the account and chat data described here.
What we keep
- Account: email address, one-way password hash, email verification status, sessions, selected plan and Lucifer mode. We do not store your plain-text password.
- Workspace: conversation titles, project names, pin and archive settings, prompts, generated replies, timestamps, and names of attached files. You can delete individual chats from the conversation menu. Uploaded file bytes are stored in your private Library and can be downloaded or deleted there. Code and HTML uploads are treated as text and are never executed.
- Billing: Stripe processes card and wallet payment details. NOWPayments processes optional crypto invoices and payments. We store the chosen plan, provider reference IDs, payment status, crypto order and invoice IDs, and paid access expiry to activate access and prevent duplicate fulfillment. We do not receive or store full card numbers or crypto wallet private keys. The providers may process payment and account details under their own policies.
- Limits: message totals, token usage, credit reservations and billing-cycle balances to enforce credit budgets; guest and no-plan previews also have a rolling 24-hour question limit.
- Security: for each chat request we keep a 30-day audit record with UTC time, internal request ID, account or guest marker, hashed safety identifier, decision/category, model, and provider request ID when available. We do not include API keys, raw session tokens, prompts, or raw IP addresses in this audit table. We use a keyed hash of the IP address for the one-preview-per-IP limit and abuse controls. Our web server and Cloudflare may separately process IP addresses and request details to deliver and protect the site. Repeated unsafe requests may cause a temporary limit or suspension.
How AI requests work
When you send a message, our server first checks for clear unsafe requests locally. Other text prompts are checked with OpenAI moderation before generation. Requests that need a safety-focused response may receive a locally written educational answer instead of being sent for generation. For ordinary requests, we pass your message, limited recent chat history, and any attached files to OpenAI to generate an answer. A hashed account or guest-session identifier is sent with generation requests as a safety identifier. One guest preview per IP address is available in a rolling 24-hour period. The guest answer and its continuation token are stored for up to 24 hours so the answer can continue after sign-in. Clear unsafe prompts receive a locally written educational response; other guest prompts may be sent to OpenAI moderation and generation. Our server requests store: false; OpenAI may still keep abuse-monitoring data under its API policy. Read OpenAI's API data policy. Please do not submit secrets or material you cannot share.
Email and delivery
Resend sends verification and password-reset links to your email address. Cloudflare delivers the site. Stripe processes card and wallet subscriptions; NOWPayments processes optional crypto payments. Each provider processes data needed for its role. We do not sell account data or use chats for advertising.
Retention and your choices
Inactive chats and their messages are automatically deleted after 180 days without activity, or sooner if you delete them. Account and subscription records remain while your account exists or until an account-deletion request is handled, subject to records we must retain for payment, tax, dispute, or legal obligations. Session records expire after 30 days; verification/reset records are removed after expiry or replacement. Ordinary security audit records are deleted after 30 days and security action records after 90 days. Stripe checkout records are removed after 30 days; Stripe event IDs are retained for up to 400 days to prevent duplicate processing. Crypto order, invoice, payment and paid-access records remain while the account or an applicable payment record is required. Subscription and customer IDs remain while the account or an applicable payment record is required. A specific incident may be exported into a restricted evidence file for investigation; it is reviewed and removed when the case is closed. Provider logs and backups may follow their own retention schedules. For access, correction, export, or deletion requests, contact [email protected]. We may verify account control first, and keep limited records where law or security requires it.
Changes
We will update this page and its date when practices change. A new optional tracking purpose will require a new choice.
DarkGPT