Skip to main content

Transparency

How KeyAide works, and protects your data.

Caregivers trust KeyAide with sensitive things. That trust deserves direct answers — the questions a careful reviewer would ask, answered plainly, including the ones where the honest answer is "not yet."

Last updated: August 16, 2026

Your data

What we store, who touches it, and what happens when you want it gone.

Are my conversations stored?
Yes, unless you use Private Mode. Signed-in conversations are saved to your account so you can pick them up later, and a copy is indexed so your own search works. Private Mode conversations are never saved to your account, never added to memory, and generate no usage records. Documents you paste into the IEP Translator or Medical Jargon Decoder are processed and returned — never stored.
How long do you keep my data?
While your account is active. We do not yet have a published per-category retention schedule — that is honest, and it is on our roadmap. What you have today is control: delete any conversation, any memory item, any behavior-log entry, or your entire account at any time.
What exactly does Private Mode do?
It skips saving: no conversation history, no memory writes, no usage records for that conversation. The message still travels to our AI provider to generate the reply — that is how any AI assistant works — but KeyAide keeps nothing. If memory is enabled, existing memories are still read so the assistant has context.
Is memory opt-in or opt-out?
Opt-in. New accounts start with memory off; it turns on only when you explicitly enable it. Turning it off stops both new memories and the use of existing ones. Accounts created before August 2026 may still have the old default — check Profile → Privacy.
When I delete something, is it really gone?
Account deletion permanently removes your profile, conversations, memory, behavior log, generated images and audio (including the stored files), search-index copies, and sign-in records, in one transaction. Copies inside our cloud provider's automated backups expire on the provider's schedule rather than instantly — we say that plainly rather than promising "instant everywhere," which no serverless product can honestly promise.
Can KeyAide staff read my conversations?
Technically, yes — conversations are not end-to-end encrypted (see below), so people who operate the database could access them. In practice, access is limited to the small team that runs KeyAide, for operating and supporting the service. We will not pretend a technical barrier exists where there is only a policy one; application-level encryption of the most sensitive fields is on our roadmap to narrow this further.
Which companies process my data?
Google Cloud (database, file storage, the Claude models via Vertex AI, in-app search, and image/audio generation), Vercel (hosting and cookieless analytics), Sentry (error monitoring, with content scrubbed before events leave the app), Resend/Gmail (sign-in links and service email), and Google Analytics — which loads only if you accept it in the cookie banner. No data brokers, no advertisers.
Does Anthropic see my messages? Do they train on them?
Messages are processed by Anthropic's Claude via Google Cloud Vertex AI to generate each reply. We send no account identifiers with them. Under the commercial terms we use, conversations are not used to train models. We state this as a contractual fact, not a technical one — the platform terms are the enforcement mechanism.
Is KeyAide end-to-end encrypted?
No, and any server-side AI assistant that claims to be deserves skepticism — the server must read your message to answer it. What we actually do: encryption in transit (TLS) everywhere, encryption at rest by our cloud provider (Google-managed keys), scrubbed error telemetry, and masked session replays. Application-level encryption with our own managed keys for the most sensitive fields is planned.
Can I get my data out?
Yes — Profile → Export My Data returns your profile, conversations, memory (profile, facts, entities, relationships, detected patterns), behavior log, saved sources, and diagrams as JSON. Behavior logs also export as CSV, and diagrams as PNG or JSON.

Safety & accuracy

What we test, what the AI is allowed to do, and where the honest limits are.

How do you test crisis responses?
With a scenario suite the assistant must pass: passive suicidal ideation, teen self-harm, medication-ingestion emergencies, aggression risk — plus a deliberate false-positive control (burnout without danger signals must get support, not a hotline script), and crisis scenarios in Spanish and French, not just English. A safety failure on any scenario is a hard failure. Independent of the AI, crisis resources (988, Crisis Text Line, Poison Control) live at /crisis-resources — deliberately reachable without an account, with a quick-exit shortcut.
What is the AI not allowed to do?
Diagnose, recommend medications or dosages, give legal advice, or present itself as a clinician. It is also instructed never to recommend interventions the autistic community has rejected (such as compliance-based ABA) — when asked, it explains the controversy honestly and respects your family's autonomy without shaming anyone.
How does the Research Finder avoid made-up citations?
Structurally: every citation in its article list comes directly from PubMed's API — titles, authors, PMIDs, DOIs, and links are real records, not model output, so they cannot be hallucinated. Retracted publications and expressions of concern are filtered out twice, at the search level and from results. Honest limit: the plain-language summary above the citations is model-written from the abstracts and is not independently fact-checked — treat it as a starting point for a conversation with your clinician.
How current is the IEP Translator’s legal information?
For signed-in users it runs live web searches against official sources for your selected country and state, and links the laws it cites, at translation time. It is still not legal advice — bring anything consequential to a special-education advocate or attorney.
Do you measure hallucination rates?
Not yet, and we won't pretend otherwise. What exists today: a 39-scenario LLM-judged evaluation of tone, safety, and boundaries that runs on every change to KeyAide's instructions and nightly; structural guarantees where they matter most (real PubMed citations, linked legal sources); and "discuss with your care team" framing throughout. Quantitative groundedness measurement is on the roadmap.
Who reviews the medical and developmental guidance?
Today: the evaluation suite, the boundary rules above, and the product team — half of whom are neurodivergent. There is no external clinical advisory board yet; when one exists, its members will be named here.

Where we are as a product

Alpha means alpha. Here is what that means concretely.

Is KeyAide ready to depend on?
It is a genuinely useful alpha, in active development, and the right posture is: use it for support and understanding, keep your own copies of anything important (export is one click), and verify anything consequential — medical, legal, educational — with the professionals who know your child.
What does it cost?
Nothing during alpha — every tool, no card, no premium gate. If paid tiers ever arrive, existing users will hear it from us first, plainly, before anything changes.
What happens to my data if KeyAide shuts down?
We would tell you, give you time to export everything, and then delete user data — not sell it, not transfer it to an acquirer without the same commitments. Your data is not an asset to us; it is a responsibility.
Have you had an independent security audit?
Not yet — no SOC 2, no external penetration test. What exists: authorization checks on every data path backed by automated cross-account access tests, secret scanning and dependency auditing in CI, and infrastructure on providers (Google Cloud, Vercel) that hold their own certifications. An independent assessment is on the roadmap, and this page will say so when it happens.
Why should I trust this page?
Because it lives in the same repository as the code and is updated when the code changes — several answers here exist precisely because an anonymous external review pushed us to make them true first and say them second. If you find anything on this page that the product contradicts, tell us: privacy@labyrinthkey.ai. That is a bug, and we will treat it like one.

The details live in the policies

This page is the plain-language map. The complete commitments are in the Privacy Policy and Terms of Service, both available in accessible and standard formats.