Privacy Policy
Last updated: September 2026
VonssyAI is a bring-your-own-key chat app. This policy explains what personal data we collect, why, and the choices you have. By using the service you agree to this policy.
Information we collect
Account data from your sign-in provider (Google or GitHub): name, email address, and profile photo. Profile data you enter: preferred name, date of birth, and avatar settings. Content you create: chat sessions, messages, message feedback, and AI provider configurations (label, API URL, model ID, and your encrypted API key). Operational data: token usage, latency, and abuse-prevention counters.
How we use information
To operate the service: authenticate you, store your chats and settings, and relay your messages to your configured AI endpoint. To personalize responses with your preferred name and birthday — only if you enable it in Settings → Profile. To protect the service: prevent abuse, debug errors, and enforce rate limits.
Sharing with third parties
Your messages are sent to the AI endpoint you configured — and only there. If you enable profile sharing, your preferred name and date of birth are sent along with them. Your AI provider processes that data under its own privacy policy. We do not sell personal data, use it for advertising, or share it with anyone else.
Storage and security
Data is stored in a Postgres database (Supabase). API keys are encrypted at rest with AES-256-GCM; the app only displays their last four characters. Traffic is encrypted with TLS and sessions use revocable database tokens. No system is perfectly secure. Protect your account credentials and never enter someone else's API key.
Retention and deletion
We keep your data while your account exists. Deleting your account permanently deletes your profile, chats, provider configurations, and usage logs. Export your history first from Settings → Data — deletion cannot be undone. Residual copies may persist in routine database backups for a limited time.
Your rights
Depending on your jurisdiction (including Indonesia's PDP Law), you may have the right to access, correct, export, and delete your personal data. Export and deletion are built into Settings → Data; profile corrections are in Settings → Profile.
Cookies and local storage
We use a session cookie to keep you signed in (Auth.js database session, 30 days). Theme, language, and reading-font preferences are stored in your browser's local storage. We use no advertising or cross-site trackers.
Children
The service is not directed at children under 13, and we do not knowingly collect their data. If you believe a child has provided data, delete the account and the data will be removed.
Changes and contact
We may update this policy; material changes will be noted here with a new revision date. Continued use after changes means acceptance. For privacy questions or requests, contact the site operator.