effective october 1, 2026
Privacy, in plain language.
This policy explains how the Chat service at chat.belayet.app handles information. The short version: account identity lives on the service, password-account chat data is encrypted before sync, and model requests go directly from your browser to OpenRouter.
What is collected
If you create an account, we store your name, email address, self-declared date of birth, email-verification state, sessions, and basic security metadata such as IP address and user agent. The date of birth is used to enforce the 18+ requirement.
An account is required to use the app. Conversations, app settings, and your OpenRouter key are stored on our servers, and for email-and-password accounts every one of them is encrypted in your browser before it is sent — using a key derived from your password, which we never receive. Generated images and attachments are encrypted the same way and stored as opaque objects.
What is not encrypted is the shape of your usage, because the service has to sort and group it to show you a conversation list: how many conversations you have, how many messages are in each, their order, when each was last changed, and which are pinned. Conversation titles, message contents, system prompts, model choices, and settings are never visible to us. A complete copy of our database would show that you had a conversation, and nothing about what it was.
How model requests work
Model requests travel directly from your browser to OpenRouter using the key you provide. OpenRouter and the model provider selected for a request receive the prompt, relevant conversation context, and any attachment you send to that model. Models that can search the web may decide to, in which case OpenRouter sends the search query to its search provider. Those services apply their own privacy and retention terms. Our Worker does not proxy or log model prompts.
Why data is used
We use account data to authenticate you, enforce the adult-only gate, synchronize encrypted app data, prevent abuse, provide account deletion, and operate and secure the service. We do not sell personal information, run behavioral advertising, or use conversation content to train models.
Infrastructure and disclosure
Cloudflare provides hosting, D1 database storage, R2 object storage, realtime connection infrastructure, and network security. Information may also be disclosed when required by law or when necessary to protect the service and its users. End-to-end encrypted content cannot be decrypted by the service operator, but account identity and usage metadata are not end-to-end encrypted.
Retention and deletion
Account data is retained while your account exists. Choosing “delete account” removes the account, sessions, conversations, messages, settings, and stored files associated with it. Deleting a single conversation removes its messages and files immediately. Copies already sent to OpenRouter or a model provider are governed by those providers.
Your choices
You can remove your OpenRouter key, sign out, export individual conversations as Markdown or JSON, delete a conversation, or delete your account outright. Depending on where you live, you may also have rights to access, correct, or erase personal information and to object to or restrict certain processing.
Cookies, local storage, and age
Authentication uses secure, HTTP-only session cookies. Your conversations are not stored in this browser. What is kept here is a non-extractable encryption key by default, held so you do not have to re-enter your password on every visit; you can instead choose “lock on exit,” which keeps that key in memory only. A single preferences entry holds your appearance, sidebar geometry, and that device-security choice, and the browser cache may hold OpenRouter's public model list. Your OpenRouter key is not written to browser storage. The service is intended only for people who are at least 18 years old.