Privacy policy
The short version
- We don't have a user database. Your subscription lives at Stripe, and logging in checks that it is active.
- Your conversations are stored in your browser, not on our servers. We can't read them, and there is nothing for us to hand over.
- We set one cookie, and only when you log in. It is there to keep you logged in, and nothing else.
- The only measurement is a visit counter on the landing page (Plausible Community Edition) that runs on our own server. It sets no cookie, stores nothing on your device, and never keeps your IP address. There are no advertising pixels and no third-party scripts of any kind — the site's security policy forbids them from loading at all.
- Because none of our storage is used for tracking, there is no consent banner. The one choice worth making — whether your login survives closing the browser — is a checkbox on the login form.
1. Who is responsible
The controller for the processing described here is UniProject Manager Kft., Százados út 25-27. A. 3/5., 1087 Budapest, Hungary.
For anything in this notice, including the rights in section 6, write to cheaptalk@duck.com. We have not appointed a Data Protection Officer.
2. What we process, and why
Legal bases are cited from the GDPR: Art 6(1)(b) is processing necessary to perform our contract with you, Art 6(1)(a) is your consent, Art 6(1)(f) is our legitimate interest, and Art 6(1)(c) is a legal obligation.
| What | Why | Basis | How long we hold it |
|---|---|---|---|
| Your email address | It is your account. We check it against Stripe for an active subscription, send your login code to it, and it identifies your session. | Art 6(1)(b) | Held by Stripe for as long as you are a customer. On our own servers it exists only inside the signed session cookie your browser holds — there is no accounts table. |
| Six-digit login codes | To prove you own the address, so there is no password to steal. | Art 6(1)(b) | 15 minutes, in the server's memory only. Never written to disk. |
| Session identifiers of sessions you logged out of | So that "log out" ends the session on our side too, not just in the browser that asked. A signed token nobody tracks cannot be withdrawn. | Art 6(1)(f) — securing accounts on shared machines | Until the session would have expired anyway (at most 30 days). The stored value is a random identifier; your email is not part of it. |
| Payment details | To take the €9/month subscription. | Art 6(1)(b) | We never receive them. Checkout happens on Stripe's own pages; we only ever ask Stripe whether an address has an active subscription. |
| Your messages, the model's replies, and files you attach | To answer you. | Art 6(1)(b) | Not stored. They are held in memory for the length of the request, forwarded to the model, and dropped. Uploads are parsed in memory and never written to disk. They are not logged, and they are not used to train anything. |
| Voice recordings | To turn speech into text in the message box. | Art 6(1)(b) | Not stored. The audio is streamed into memory, transcribed, and discarded within the request. |
| Text you ask to have read out loud | When you press a reply's speaker button (or switch a conversation to read replies aloud), its text is turned into speech. | Art 6(1)(b) | Not stored. The text goes to the same Swiss provider that wrote it, the synthesized audio is returned to your browser and played there, and both are discarded within the request — nothing is written to disk or logged at either end. |
| Web-search queries and fetched page text | When a question needs current information, a search phrase is derived from it and pages are fetched to answer from. | Art 6(1)(b) | Not stored. The fetched text lives for one turn and is discarded; only the list of source links stays in the conversation in your browser. |
| Server logs | Keeping the service running and diagnosing it when it breaks. | Art 6(1)(f) | Our TLS front end keeps no access log at all — it records that it started, not who visited. The application records one line per request with the method, path and status code, but the address on that line is our own front end's, not yours: the app sits behind a proxy and never resolves the caller's address for logging. Your IP address is read once, in memory, to count requests against the login rate limits, and is not written anywhere, and is never stored nor logged. Nothing that passes through — messages, replies, uploads, voice — is logged. Logs rotate at 10 MB and three files per service, and the application's are discarded outright every time we deploy. |
| Search phrases, in one error case | Not deliberate: when a public search engine rate-limits our search service, it writes the failed request — which contains the search phrase — into its own diagnostic log. | Art 6(1)(f) | The phrase is a few keywords derived from your question, not the question, and nothing on that line ties it to you: no address, no email, no session. It rotates out with everything else. |
| Visit statistics for the landing page | To know how many people find the site and where they come from. Counted by Plausible Community Edition — analytics software running on our own server, so no analytics company receives anything. The chat app itself is not measured. | Art 6(1)(f) — knowing whether anyone visits | What is kept is the pageview: the page, the referrer, browser and operating-system family, device class, and the country derived from your IP address. The address itself and your full user agent are used only in memory, to derive a visitor number from a salt that is discarded every 24 hours — after a day nothing can connect two of your visits to each other, and nothing stored ever identified you in the first place. The aggregate counts are kept indefinitely. |
| Invoices and payment records | Tax and accounting. | Art 6(1)(c) | Held by Stripe for the statutory retention period in Hungary. |
We do not profile you, and nothing here makes an automated decision that produces a legal effect for you or similarly significantly affects you within the meaning of Art 22 GDPR. The models generate text; they decide nothing about you.
3. Who else sees anything
These are all of them. There are no others, and no advertising or analytics partners at all.
- AI Router (Switzerland) — runs the models. Your messages reach them under a single API key shared by every cheaptalk subscriber, with no name or email attached, and the request comes from our server, so the IP address in their logs is ours rather than yours. They state that prompts are processed in memory and never stored, and that technical logs are kept 14 days.
- Stripe (Stripe Payments Europe, Ltd., Ireland) — subscriptions and payments. Stripe is, in effect, our user database.
- Plus Five Five, Inc. — Resend.com — delivers login codes. It sees your address and the code.
- Infomaniak Network SA, Geneva, Switzerland — runs the server. The web-search index we query runs on that same server, so search phrases do not go to a third-party search company under your name. The landing page's visit counter runs there too, so visit statistics never leave it either.
4. Transfers outside the EEA
Switzerland — both the models (AI Router) and the server itself (Infomaniak, Geneva). The European Commission has decided that Switzerland provides an adequate level of data protection (Decision 2000/518/EC of 26 July 2000, maintained following the Commission's January 2024 review), so no further transfer mechanism is needed.
The United States — Resend, which delivers login codes, is Plus Five Five, Inc. Those transfers rely on the Standard Contractual Clauses incorporated into its data processing agreement, and Resend is additionally certified under the EU–U.S. Data Privacy Framework. What crosses is your email address and a six-digit code.
Stripe we contract with through Stripe Payments Europe, Ltd. in Ireland, which is inside the EEA. Any onward transfer within Stripe's own group is governed by Stripe's data processing agreement rather than by us.
5. What is stored on your device
Article 5(3) of the ePrivacy Directive covers anything stored on or read from your device — not just cookies, but browser storage of every kind. It requires your consent unless the storage is strictly necessary for a service you explicitly asked for. Here is everything cheaptalk puts on your device, and which of those two it is.
| Name | Kind | What it is for | Lifetime | Consent |
|---|---|---|---|---|
ct_session |
Cookie, first-party. HttpOnly, SameSite=Lax, Secure. |
Keeps you logged in. It holds your email address, an expiry, the date your subscription is paid through, a random session id and a signature — nothing about what you do on the site. | Deleted when you close the browser — unless you tick "Keep me signed in", in which case 30 days. | Strictly necessary, so none needed — except for the 30-day version, which is what the checkbox on the login form is for. It is never pre-ticked, and not ticking it costs you nothing but a fresh login code. |
| Your conversations | IndexedDB | They are the product. They are stored here because they are not stored on our servers; the database is named after a hash of your email so that the list of databases on a shared computer doesn't reveal who has used it. | Until you delete them, or until the browser evicts them. Safari and every browser on iOS clear site data after 7 days without a visit — exporting is the only real backup. | Strictly necessary: this is the service you asked for, and without it there is nowhere for your chats to live. |
lang, theme, voiceLang, readSpeed, sidebarHidden, studyRailHidden, studyRailWidth, storageWarnedAt |
localStorage | Settings you chose: interface language, light or dark, dictation language, how fast replies are read out loud, whether the sidebar and the Study rail are folded away, and when you last dismissed the storage warning so it isn't shown again for a week. | Until you clear the site's data. | Set only when you change the setting, never read by us, never sent anywhere, and never linked to an identifier. This paragraph is the information that makes remembering them across sessions lawful. |
That is the entire list. The visit counter in section 2 is absent from it because it stores nothing on your device — no cookie, no localStorage, nothing to clear. Nothing here follows you, so there is nothing to put behind a consent banner and none to refuse. If you clear the cookie you are logged out; if you clear the rest you lose your conversations and your settings, and nothing else happens.
6. Your rights
Under the GDPR you can ask us to:
- tell you what we hold about you and give you a copy (Art 15);
- correct it (Art 16);
- erase it (Art 17);
- restrict what we do with it (Art 18);
- hand it over in a portable form (Art 20);
- stop processing based on legitimate interests (Art 21).
Where we rely on consent — which here means the "Keep me signed in" checkbox — you can withdraw it at any time, without giving a reason and without affecting what was lawful before. Logging out is the withdrawal: it deletes the cookie and ends the session on our side.
In practice the honest answer to an access request is short, because the only thing we hold that is tied to you is your email address at Stripe. Your conversations are on your device, where you can already read, export and delete them without asking us.
You can also complain to a supervisory authority where you live or work.
7. Do you have to give us anything
Only an email address, and only because it is how you pay and how you log in. There is nothing optional to withhold: we don't ask for a name, a phone number, or anything else.
8. Changes to this notice
If what we do changes, this page changes with it and the date at the top moves. Changes that affect you materially will be shown in the app rather than left here to be discovered.