Privacy Policy
Last updated: 25 July 2026
At idapt, your privacy matters. We are a French company, and we protect your personal data in accordance with the General Data Protection Regulation (GDPR) and other applicable privacy laws. We make money from subscriptions and the usage credits you purchase; we never use your data to train AI models, and we do not sell it.
This Privacy Policy forms part of, and should be read together with, our Terms of Service. The identity of the publisher is set out in our Legal Notice. The full list of providers who process data on our behalf is on our Sub-processors page.
1. Who We Are
The data controller for your personal data is Logos Industries, a société par actions simplifiée incorporated in France and the company operating the idapt service (see the Legal Notice for full identification). For any privacy question, or to exercise your rights, contact us at [email protected].
2. What Data We Collect
We collect and process the following categories of personal data to provide and improve the Service:
- User Data: your conversations with AI, prompts, messages, chat history, and files you create or upload. This is necessary to provide AI assistance and maintain your history. To make your content searchable, we also create and store mathematical representations of it (embeddings) with our search provider.
- Account Data: your name (or pseudonym), email address, and payment details (processed securely by our payment provider, Stripe).
- Security Data: usage logs, IP addresses, device information, and user-agent strings, used for fraud prevention and security.
- Communication Data: emails and support interactions.
- Usage Data: analytics about how you use the Service, including AI model usage (token counts, costs, performance metrics) and feature usage.
3. How and Why We Use Your Data
We use your data to:
- Provide the Service: deliver AI functionality, maintain your history, and support your account (legal basis: performance of a contract);
- Improve the Service: troubleshooting, security monitoring, and new features (legal basis: legitimate interests);
- Communicate with you: account, billing, and product updates; you can opt out of non-essential messages (legal basis: legitimate interests / consent);
- Comply with the law: meet legal, tax, regulatory, and accounting obligations (legal basis: legal compliance).
What we never do with your data:
- No AI training: we do not use your User Data (conversations, prompts, files) to train AI models (neither our own nor anyone else's) and we do not permit our processors to do so on our behalf. AI providers receive your prompts through their business APIs solely to generate the responses you request.
- No selling: we do not sell your personal data, and we do not build advertising profiles from it. Where you accept marketing cookies, a pseudonymous identifier is shared with Google so we can measure which advert led to a sign-up. You can refuse this at any time from the cookie banner or your settings, and refusing changes nothing about the Service.
Where we rely on consent, for example to store analytics or advertising cookies on your device, you may withdraw it at any time.
Some measurement does not rely on consent, because it never touches your device: we record how our pages are used from the requests your browser already sends us, and we record what happens in your account while you use the Service. The basis for that is our legitimate interest in understanding and improving the Service. You can object to it at any time in Settings, Privacy.
4. How Long We Keep Your Data
We keep personal data only as long as necessary for the purpose collected or to meet legal obligations:
| Data | Retention |
|---|---|
| User Data (chats, messages, files, notes) | Kept while your account is open. When you delete an individual item it is held for 30 days, then permanently deleted. When you delete your account, your identifying details are removed immediately and the account can no longer be used. To have the content you created erased as well, ask us at [email protected] and we will do it within one month. |
| Account Data | Kept for the duration of registration, then up to 1 year after your account is closed for evidentiary and legal-compliance purposes. |
| Security Data | Up to 1 rolling year, then deleted automatically. |
| Payment & billing records | Retained for the period required by French tax and accounting law (generally 10 years). We keep these even after you delete your account, because the law requires it. |
| Communication Data | Up to 2 years from your last interaction, unless you ask for earlier deletion. |
If the law requires it, we may retain certain data beyond these periods, only to the extent necessary to comply.
5. When and With Whom We Share Your Data
We share personal data only with the providers needed to deliver the Service. Each is bound by contract to process data solely for the agreed purposes and in compliance with privacy law.
The table below summarises the main categories. The complete, current list, with the legal entity, country, and transfer safeguard for each provider, is on our Sub-processors page, which we keep up to date as the Service evolves.
Infrastructure and business providers
| Provider | What they do | Where they process |
|---|---|---|
| Hetzner (Hetzner Online GmbH, through Hetzner US LLC) | Application hosting, the database, and caching | United States (Ashburn, Virginia) |
| Cloudflare | File and media storage (R2), database backups, content delivery, bot protection | United States |
| Amazon Web Services | Backup mirror, secrets management, serverless code execution | United States (us-east-1) |
| Turbopuffer | Search indexing over your content | United States |
| RunPod | GPU cloud computers | United States |
| Stripe | Payment processing | Ireland and United States |
| Brevo | Transactional and marketing email | France |
| PostHog | Product analytics and error tracking | Germany (PostHog Cloud EU) |
| Google Ads | Measuring which advert led to a sign-up, only with marketing consent | Ireland and United States |
| Brave Search | Answering web searches you or an agent run | United States |
| Bright Data | Fetching web pages when you or an agent open a link. The page content passes through their proxy | Israel |
| Apple, Google | Push notifications to your devices | Ireland and United States |
AI service providers
| Provider | What they do | Where they process |
|---|---|---|
| OpenRouter | AI model gateway (unified access to multiple providers) | United States |
| OpenAI, Anthropic, Google, xAI, Groq, Together, Fireworks, DeepInfra, Cohere, Runway, Luma, Replicate, MiniMax, DeepSeek and other model providers | AI processing and generation (text, image, video, and audio), accessed directly or via OpenRouter | United States, and other countries including China |
AI providers process your prompts solely to generate the responses you request. Their retention and training practices vary by provider, and we publish what we have verified for each one on the Sub-processors page and in your AI Routing settings. You can restrict routing to providers we have verified do not train on your data, bring your own provider API keys to run under your own contract with that provider, or run models on your own computer so that no third-party AI provider is involved.
Local models. When you run an open model on your own computer, your prompts and the model's replies are not sent to any third-party AI provider. They are relayed through our infrastructure to reach your device, and your conversation history remains stored by idapt like any other chat, with the same protections described in this Policy.
We may disclose data where required by law, a court order, or other legal process. Our approach to such requests, including our commitment to challenge overbroad ones and to notify you unless we are legally barred from doing so, is described on our Trust page. We do not sell your data.
6. Data Security
We protect your data against unauthorised access, loss, or alteration through:
- Encryption: data in transit is encrypted with TLS; data at rest is encrypted using managed encryption services;
- Access control: strict authentication and authorisation, enforced in the database itself through row-level security, so only authorised personnel can access data;
- Regular review: periodic review of systems and processes, with prompt application of security updates.
More detail, including who at idapt can access customer content and under what conditions, is on our Trust page.
7. Where Your Data Is Processed
The idapt application, its database, and your files are processed in the United States. Application servers and the database run in Ashburn, Virginia, operated for us by Hetzner Online GmbH (Germany) through its United States subsidiary Hetzner US LLC. Files, media, and database backups are stored on Cloudflare R2 in North America. A second backup copy, our secrets management, and serverless code execution run on Amazon Web Services in the us-east-1 region. Search indexing runs in the United States.
Transactional email (Brevo, France) and product analytics (PostHog Cloud EU, Frankfurt) are processed in the European Union.
| What | Where it is processed |
|---|---|
| Application, database, cache | United States (Ashburn, Virginia) |
| Files, media, backups | United States (Cloudflare R2, North America) |
| Backup mirror, secrets, code execution | United States (AWS us-east-1) |
| Search index | United States |
| GPU cloud computers | United States |
| France | |
| Product analytics | Germany |
| AI model providers | United States and other countries, per provider |
idapt is established in France, so your data is protected by the GDPR wherever in the world it is processed, and you keep every right described in Section 8.
For processing outside the European Economic Area we rely on the European Commission's Standard Contractual Clauses, supported by a documented assessment of the laws of the destination country, or on the recipient's certification under the EU-U.S. Data Privacy Framework. The safeguard that applies to each provider is shown on our Sub-processors page. You may obtain a copy of these safeguards by writing to [email protected].
8. Your Rights
Under the GDPR (and equivalent laws elsewhere) you have the rights of: access, rectification, erasure, restriction of processing, objection, data portability, and withdrawal of consent.
How to exercise them:
- Delete your account. Settings → Privacy → Delete account signs you out everywhere and removes your name, email address and profile picture straight away. Your account can no longer be used.
- Everything else, including erasure of the content you created, an export of your whole account, access, rectification, restriction and objection: write to [email protected]. We respond within one month, as the GDPR requires, and we do not charge for it.
- Individual resources export from their own screens at any time: a conversation to Markdown, plain text, JSON or PDF, a Notes box to a ZIP of Markdown files, a table to CSV, a folder of files to a ZIP, and a repository over standard
git clone.
We are building a single control that exports your whole account and a form for the other requests. Until they ship, the email route above is the way to exercise those rights, and it is the route we monitor.
If you believe we have not handled your data properly, you may lodge a complaint with your local Data Protection Authority; in France, the Commission Nationale de l'Informatique et des Libertés (CNIL).
9. Cookies and Tracking
We use cookies and similar technologies to operate the Service. You choose what to allow when you first visit, and you can change your choice at any time from Settings → Privacy or the cookie banner.
Essential (always on)
These are required for the Service to work and cannot be disabled.
| Cookie | Purpose | Duration |
|---|---|---|
better-auth.session_token | Keeps you signed in | 90 days |
__Secure-idapt_app_key | Signs you in to apps published on idapt subdomains | 1 day |
idapt_locale | Remembers your language | 1 year |
cookie-consent | Stores your cookie choices so we stop asking | 1 year |
idapt-device-id | Tells devices apart to stop abuse of the free tier | 1 year |
__cf_bm (Cloudflare) | Tells humans from bots on sign-up and sign-in | 30 minutes |
Analytics
We always measure how the site is used in aggregate, without storing anything on your device and without identifying you. That measurement needs no cookie and no consent, and it happens whatever you choose below.
What your analytics choice controls is linking: whether we may remember your visits on this device and connect them to your account, so we can see how features are used over time rather than only day by day.
| Cookie | Purpose | Duration |
|---|---|---|
ph_*_posthog (PostHog) | Links your visits to your account so we can see how features are used over time | 13 months |
Marketing (only with your consent)
| Cookie | Purpose | Duration |
|---|---|---|
_gcl_au (Google Ads) | Measures which advert led to a sign-up. We do not use it to build an advertising profile. | 90 days |
We do not use advertising cookies to profile you, and we do not share your content with advertisers.
10. Guest Users
You may use the Service as a guest before creating an account. Guest conversations are stored on our servers under a temporary guest account, with the same privacy protections and security as registered accounts. Guest accounts have limited capabilities. If you later create an account, your guest data is migrated to it.
11. Children
idapt is not directed to children. You must be at least 15 years old (or the age of digital consent in your country, if higher) to use the Service, as set out in our Terms of Service. We do not knowingly collect personal data from children below that age. If you believe a child has provided us with personal data, contact us at [email protected] and we will delete it.
12. If You Are in the United States
We do not sell or share your personal information as those terms are defined under United States state privacy laws, and we do not process it for cross-context behavioural advertising. Depending on your state, you may have the right to know what personal information we hold, to request its deletion or correction, to obtain a portable copy, and not to be discriminated against for exercising those rights. Use the same routes as everyone else: the export and deletion controls in Settings → Privacy, or [email protected]. We do not require an account to make a request, and we do not charge for one.
13. Changes to This Privacy Policy
We may update this Privacy Policy to reflect changes in our practices, the Service, or the law. We will notify you of significant changes by email or in-app notice. Please review this page periodically.
14. Contact Us
For any question or request regarding this Privacy Policy, contact us at [email protected]. Full publisher identification is in our Legal Notice.