What we store, who touches it, and what happens when you want it gone.
- Are my conversations stored?
- Yes, unless you use Private Mode. Signed-in conversations are saved to your account so you can pick them up later, and a copy is indexed so your own search works. Private Mode conversations are never saved to your account, never added to memory, and generate no usage records. Documents you paste into the IEP Translator or Medical Jargon Decoder are processed and returned — never stored.
- How long do you keep my data?
- While your account is active. We do not yet have a published per-category retention schedule — that is honest, and it is on our roadmap. What you have today is control: delete any conversation, any memory item, any behavior-log entry, or your entire account at any time.
- What exactly does Private Mode do?
- It skips saving: no conversation history, no memory writes, no usage records for that conversation. The message still travels to our AI provider to generate the reply — that is how any AI assistant works — but KeyAide keeps nothing. If memory is enabled, existing memories are still read so the assistant has context.
- Is memory opt-in or opt-out?
- Opt-in. New accounts start with memory off; it turns on only when you explicitly enable it. Turning it off stops both new memories and the use of existing ones. Accounts created before August 2026 may still have the old default — check Profile → Privacy.
- When I delete something, is it really gone?
- Account deletion permanently removes your profile, conversations, memory, behavior log, generated images and audio (including the stored files), search-index copies, and sign-in records, in one transaction. Copies inside our cloud provider's automated backups expire on the provider's schedule rather than instantly — we say that plainly rather than promising "instant everywhere," which no serverless product can honestly promise.
- Can KeyAide staff read my conversations?
- Technically, yes — conversations are not end-to-end encrypted (see below), so people who operate the database could access them. In practice, access is limited to the small team that runs KeyAide, for operating and supporting the service. We will not pretend a technical barrier exists where there is only a policy one; application-level encryption of the most sensitive fields is on our roadmap to narrow this further.
- Which companies process my data?
- Google Cloud (database, file storage, the Claude models via Vertex AI, in-app search, and image/audio generation), Vercel (hosting and cookieless analytics), Sentry (error monitoring, with content scrubbed before events leave the app), Resend/Gmail (sign-in links and service email), and Google Analytics — which loads only if you accept it in the cookie banner. No data brokers, no advertisers.
- Does Anthropic see my messages? Do they train on them?
- Messages are processed by Anthropic's Claude via Google Cloud Vertex AI to generate each reply. We send no account identifiers with them. Under the commercial terms we use, conversations are not used to train models. We state this as a contractual fact, not a technical one — the platform terms are the enforcement mechanism.
- Is KeyAide end-to-end encrypted?
- No, and any server-side AI assistant that claims to be deserves skepticism — the server must read your message to answer it. What we actually do: encryption in transit (TLS) everywhere, encryption at rest by our cloud provider (Google-managed keys), scrubbed error telemetry, and masked session replays. Application-level encryption with our own managed keys for the most sensitive fields is planned.
- Can I get my data out?
- Yes — Profile → Export My Data returns your profile, conversations, memory (profile, facts, entities, relationships, detected patterns), behavior log, saved sources, and diagrams as JSON. Behavior logs also export as CSV, and diagrams as PNG or JSON.