Privacy
What AIfrit keeps, and what you can do about it.
Plain language, no boilerplate. AIfrit is a product built on remembering things about you, so this page has to be specific — including where the honest answer is the weaker one.
Effective 5 September 2026 · AIfrit
Who we are
AIfrit Labs is the company behind AIfrit, and is the data controller for everything described here. You can reach us at hello@aifrit.com, or by post:
AIfrit Labs
33 Arch Street
Boston, MA 02110
United States
What we collect
Your account details. The email address you sign up with. If you sign in with Google, the account identity Google returns to us.
What you send AIfrit. Your messages, the images and documents you upload, and anything you ask it to look up.
What AIfrit works out from that. Facts it draws from your conversations — goals, decisions, context, preferences — each stored with a confidence level and the part of your life it belongs to.
Your calendar items and to-dos. Events, tasks, and reminders that you create or approve in the app — AIfrit can offer one, but it becomes an item only when you confirm it. Each is stored with its dates, times, and any alert settings you choose.
Your subscription status. Whether you are on a trial, active, or cancelled. Your card details are entered on Stripe's own payment form; we do not receive or store your card number.
What AIfrit remembers, and why
The memory is the product. Without it AIfrit is another chat window, so it keeps the things that make the next conversation better: what you're trying to do, what you're working around, what you already decided and why, and how you like to be spoken to.
Each of those is held as a separate fact, at a confidence level, filed under a part of your life. You can open the full list in the app or on the web and read it — all of it, confidence and all. You can read back any conversation you have had, in full.
If a memory is wrong, you correct it. Corrections never overwrite: the old version is marked as contradicted and kept beside the new one, so the record of what changed survives. If AIfrit can't tell that your correction contradicts what it held, it tells you rather than quietly doing nothing.
Some subjects are handled more carefully. Memories about faith or health are never given a bulk "show me everything about this" control — that restriction is enforced on our server, not in the app, so it holds no matter which version of the app you are running.
And memory is a setting. You can turn it off entirely, in Settings, at any time.
Who processes your data
AIfrit is not built alone. These are the companies we work with directly, and what each one receives.
OpenRouter — routes model requests to whichever company runs the model we asked for. Receives the content of the requests it carries.
DeepSeek — one DeepSeek model does most of AIfrit's thinking. It writes the replies you sit and wait for; it does the work that happens after the conversation has moved on, reading back over what you said and writing down what it decided to remember; and it looks at images you send, so AIfrit can answer questions about them. It receives what is sent for that work — your conversation content now goes straight to DeepSeek, and the images you send go straight to DeepSeek.
OpenAI — converts text into the numeric form AIfrit uses to find related memories. Receives, through OpenRouter, the text being indexed.
Google — image generation, and sign-in if you use it. Receives what you ask AIfrit to draw, and your Google account identity if you sign in that way.
Deepgram — speech, in both directions. When you dictate, the recording of your voice is sent to Deepgram to be turned into text. When you have a reply read aloud, the text of that reply is sent to Deepgram to be turned into audio. Deepgram, Inc. is a company in San Francisco. Every one of those requests carries a flag that excludes it from Deepgram's Model Improvement Partnership Program, and their documentation says data from opted-out requests "is retained only for the duration necessary to process the request". Beyond that we cannot tell you how long they hold it: their public privacy notice does not say, and points instead to the agreement a customer has with them.
Tavily — web search. Receives the search query when AIfrit looks something up for you.
Resend — sends the service email: your welcome message, password links, account notices. Receives your email address and the contents of those messages.
Stripe — payments. Receives your name, email address, and card details, and handles the card end to end; we never see the number.
Cloudflare — delivers this website and secures traffic to AIfrit. Sees your IP address and ordinary request information in the course of serving pages.
IONOS — hosting. AIfrit runs on a single server that IONOS owns and operates, in the United States. Everything the service stores sits on their machine: your conversations, your memories, the database behind them.
Backblaze B2 — offsite backup storage. Receives our backups, which are encrypted on our own server before they are sent, so Backblaze stores something it cannot read.
Where what you send is processed. DeepSeek is Hangzhou DeepSeek Artificial Intelligence Co., Ltd., a company in China. Its published privacy policy says it processes and stores data in the People's Republic of China, and its developer terms are governed by Chinese law. It publishes no separate commitment about where content sent by developers like us is held. So the honest thing to tell you is to assume what you send is processed in China. This changed recently, twice. Image understanding used to be done by Google, and this page said so until we corrected it. And your conversations used to be handled by whichever company the router picked, so we could not tell you which one or where; they now go to DeepSeek directly, which means we can tell you, and the answer is China. We also used to ask, on those requests, that they go only to companies that do not collect user data — that request went through the router, so it goes no longer.
One thing this list cannot tell you. OpenRouter is a router. The requests that still go through it — building your memory index, and generating an image — are handed to whichever company runs that model at that moment, from a pool of around thirty that host it. We do not currently pin that choice, so for those requests we cannot hand you the name of the company that handled them, or the country it was in. That is a gap in what we can tell you, not a loophole we wanted. Your conversations no longer go through it: they go to DeepSeek, in China.
We do not sell your data, and we do not share it with advertisers or data brokers. The companies listed above are the ones we work with directly to run AIfrit — the models, the hosting, the payments, the email. Your data does not go to anyone who is not helping run AIfrit.
There is no analytics code and no advertising code in the AIfrit app or on this website.
One more thing worth naming. An earlier version of the web app loaded part of its display engine from an address Google operates, and this page said so. We have since rebuilt it: the app now serves its display engine and fonts from our own address. Two honest edges remain. If you sign in with Google, the sign-in page itself loads Google's sign-in code — that page is the one place Google's code runs, and it is built that way on purpose. And if a conversation contains writing our bundled fonts don't cover (some scripts, some emoji), the display engine can fetch a fallback font from a Google-operated address in that moment. The Android app does none of this.
Training
We do not train AI models on your data. AIfrit is not a model company. There is no AIfrit model, so nothing you tell AIfrit is used to build one, and that is not a policy we could quietly reverse without first building something we do not have.
What happens at the companies that run the models is a different matter, and this is where the honest answer is the weaker one. We used to send an instruction with the requests that carry your conversation, asking that they be handled only by companies that do not collect user data. We no longer send it: those requests now go straight to DeepSeek rather than through a router, and that instruction was something the router understood. The router also carried two settings on our account — one that kept our requests away from companies that store what we send, and one that kept them away from companies that train on it. Going straight to DeepSeek, those do not apply to your conversations either.
The requests that still go through the router are the ones that build your memory index and the ones that generate an image. Our account there is set to keep those away from companies that store what we send or train on it — that setting is the router's own judgement about those companies, not a promise from us. The requests that read an image you have sent do not go through it either. For those, what the company running that model does with the content is governed by that company's own terms and by nothing we send with the request. We have not measured what each of them does.
And an instruction is not a promise from us. Once your conversation reaches a model company we are relying on that company's terms. We cannot give you a period for how long any of them keeps what we send, because we have not found one published that covers this use. Deleting something from AIfrit removes it from AIfrit — see "Your choices" — and it does not reach back into a model company's systems.
Security
Everything travels over encrypted connections — between your device and AIfrit, and between AIfrit and every company that handles it.
Our backups are encrypted on our own server before they leave it, so the backup provider holds something it cannot read.
Who reads your conversations
Most of the reading of your conversations is done by software rather than by people — that is how AIfrit draws out the facts it keeps for you. What it learns can also be used to improve AIfrit for other members: a fix or an improvement that comes out of one person's use can end up helping everyone. We do not train AI models on your data. It does not go to advertisers or data brokers, and the companies it does reach are the ones listed above — what those companies may do with it afterwards is set out under Training.
People can read it too. Our staff can open stored conversations and memories when they are running, fixing, or supporting the service, and when they are working on those improvements. We keep that access to the people who need it.
How long we keep things
Raw image files: 30 days. An image you upload is deleted 30 days after it arrives. What survives is the written description AIfrit made of it — that's what the memory is built from. This is automatic: a job runs every night and removes them.
Conversations, messages, memories, and calendar items: until you ask us to delete them. There is no automatic expiry and no retention window, and we are not going to invent one to make this page read better.
Deleting a conversation in the app hides it. It disappears from your list and the record is kept; our staff can still read it. Archiving works the same way. Both can be undone.
Operational logs: capped, not permanent. Running the service produces ordinary logs of what the server did and when. Those logs can contain text drawn from your conversations, which is why they are capped rather than left to grow: they roll over at a fixed size, so what exists at any moment is on the order of the last couple of months of activity rather than a permanent record. Cloudflare separately sees your IP address and ordinary request information at the edge, as described above.
Your choices
See everything. Open your memory list in the app or in a browser. Every fact AIfrit holds about you is there, with its confidence.
Correct anything. Corrections never overwrite the original.
Turn memory off. In Settings, at any time, entirely.
Archive a conversation. It leaves your list, and you can restore it.
Ask us to delete. There is no self-serve delete — not for one memory, not for all of them, not for your account. Write to hello@aifrit.com, tell us what you want removed, and we will remove it within 30 days of your request.
Export. There isn't one. No export feature exists today, and we would rather say that than describe one that doesn't work.
If you cancel
Cancelling stops the next charge. You keep access until the end of the period you have already paid for, and it ends then. It does not delete anything.
Your conversations and memories stay where they are. That means they are intact if you come back — and it also means that if you want them gone, cancelling is not how you do it. Write to hello@aifrit.com and ask.
Children
You must be 18 or older to use AIfrit. It is a paid subscription that requires a payment card, and it is not designed or intended for children. AIfrit does not knowingly collect information from anyone under 18. If you believe someone under 18 has an account, write to hello@aifrit.com and we will close it and remove the data.
Changes to this notice
If we change this notice, the effective date at the top changes with it. If a change is significant — a new company handling your data, a change to what we keep or for how long — we will tell members by email rather than leaving it for you to notice.
Contact
hello@aifrit.com — for privacy questions, deletion requests, or anything on this page you think is wrong. If a sentence here doesn't match what the product actually does, that's a defect and we want to know.