Privacy at idapt
Your data is never our product.
idapt makes money from subscriptions and usage credits, never from your data. We don't train AI on it, we don't sell it, and you choose who processes your prompts.
The legal version lives in our Privacy Policy.
Four levels of privacy: you pick
Everyone gets the first level. Each next level tightens who can see your prompts, all the way down to nobody but your own computer.
1. The default, for everyone
idapt never trains AI models on your content and never sells your data. Prompts reach AI providers through their business APIs solely to generate your responses. Your data is encrypted in transit and at rest, and idapt is a French company, so the GDPR governs it wherever it runs.
2. Choose your providers
Every provider's data policy is labeled below and in the product. Block any provider, or require no training in AI Routing, and idapt only routes to providers that meet it. The floor covers every modality, images and video and speech included. Providers whose policy we could not verify are excluded, never assumed safe.
3. Bring your own keys
Connect your own provider API keys and requests run under your own contract and account terms with that provider. Keys are encrypted before storage and only ever used server-side.
4. Maximum privacy: local models
Run open models on your own computer. The model runs on your hardware: no third-party AI provider ever sees your prompts or replies.
Every provider, labeled
This is the same table our router enforces: turn on a privacy floor and only qualifying rows remain routable. Models running on your own computer always qualify.
Each row is read by hand from that provider's own published terms. Hover a claim to see the sentence it came from and the date we read it, and follow the provider name to check it yourself. A nightly job re-reads every source and flags any page whose wording has moved. Providers we have not been able to source are not listed: that is a statement about our reading, not about them.
| Provider | Trains on your data | Retention |
|---|---|---|
| No | None | |
| No | None | |
| No | Not published | |
C Cerebras | No | Not published |
| No | Not published | |
| No | Unspecified | |
| No | Not published | |
| No | Unspecified | |
G Google Ai Studio | No | Unspecified |
| No | Unspecified | |
| No | 30 days | |
N Nebius | No | Unspecified |
| No | 30 days | |
| No | None | |
| No | Not published | |
| No | Not published | |
| No | 30 days | |
| Not published | 30 days | |
A AtlasCloud | Not published | Not published |
C Chutes | Not published | None |
| Not published | Not published | |
| Yes | Unspecified | |
| Yes | Unspecified |
Best-effort labels sourced from providers and OpenRouter (as of 2026-07-24); provider names link to their published policies; verify with the provider for compliance needs. Providers not listed are treated as unknown and excluded whenever a privacy floor is on. See the provider directory for details.
Local models, exactly as they run
Your computer runs the model → idapt syncs and stores your workspace → no third-party AI provider is involved.
When you run an open model on your own computer, no AI provider ever sees your data. To be fully transparent: your workspace still lives in idapt; prompts and replies pass through our servers to reach your device, and your chat history is stored in your account so it syncs across devices. We are the only party that handles it, we encrypt it, and we never use it for training or sell it. If you need data that never touches any server, that's not this, and we'd rather tell you that than overclaim.
What we store, and for how long
- Chats, messages, and files : kept while your account is open. Deleted data is retained at most 30 days for abuse detection, then permanently removed.
- Account data: kept up to 1 year after your account closes; billing records as long as tax law requires.
- Security logs: up to 1 rolling year, then deleted automatically.
Full retention tables, sub-processors, and your GDPR rights are in the Privacy Policy.
You stay in control
- Opt out of analytics anytime in Settings → Privacy (necessary cookies only).
- Turn agent memory off per chat, delete any conversation or file, and export chats.
- Delete your whole account in Settings → Privacy: irreversible, GDPR-grade.
- Exercise any GDPR right by emailing [email protected].