Privacy Policy

TalkToAI Privacy Policy

Effective date: 14 June 2026. Last revised: 2 August 2026. This policy covers TalkToAI and connected ecosystem services including ZERO ONE Desktop, OpenZero, ZeroThink, ZMail, CallChat, ZSEC Shield, DNA Lab, Gateway, research workflows, in-house boards, subscriptions, uploads, support, and AI tools.

Controller contact: shaf@talktoai.org.

1. Information we collect

  • Contact and account information, such as names, email addresses, login identifiers, subscription status, support messages, and user preferences.
  • User content, including prompts, chat messages, research notes, uploaded files, DNA-related files, generated outputs, board posts, comments, feedback, and profile content.
  • Technical and security information, including IP address, device/browser details, logs, timestamps, referrers, errors, abuse-prevention signals, and rate-limit events.
  • Payment and subscription information, including plan type, payment references, cancellation events, and processor status messages. Full card details are handled by payment processors when applicable.
  • Crypto and token-related information voluntarily supplied or visible on-chain, such as public wallet addresses, transaction references, and user-provided payment confirmations.

2. How we use information

  • To provide websites, AI tools, research pages, subscriptions, uploads, boards, support, billing, reports, and connected services.
  • To secure the ecosystem, prevent abuse, detect attacks, protect intellectual property, maintain logs, and investigate misuse.
  • To debug, test, improve, and maintain features, including AI workflows, file analysis, DNA Lab, research tools, and content pages.
  • To process payments, subscriptions, cancellations, fraud checks, chargebacks, and support requests.
  • To comply with law, enforce terms, defend claims, preserve evidence, and respond to lawful requests.

3. Lawful bases

Depending on the context, we process information to perform a contract, take steps requested by a user, comply with legal obligations, protect legitimate interests such as security, fraud prevention, IP protection, service improvement, record keeping, and legal defence, or based on consent where required.

4. Sensitive files and AI content

Users should not submit confidential, regulated, employer-owned, third-party, medical, genetic, legal, financial, government, defence, classified, or highly sensitive material unless they have lawful authority and accept the risk of processing. DNA Lab and health-research outputs are informational research outputs only and are not medical advice, diagnosis, treatment, or clinical decision support.

5. Product disclosure: ZERO ONE Desktop and local ZSEC scans

Local desktop data and automatic startup

ZERO ONE Desktop stores user-chosen ZMail, ZeroThink, OpenZero, and CallChat service URLs, the configured OpenZero model, the CallChat media preference, and the launch-at-login preference in the operating system's application-data directory. The configured OpenZero endpoint can be a loopback address or an allowed public origin; model requests, prompts, and responses therefore are not always local. An OpenZero API token is stored only when secure operating-system encryption is available; the reviewed app refuses insecure Linux basic-text credential storage.

“Launch ZERO ONE when I sign in” is a user-controlled operating-system login item. When enabled, the operating system starts ZERO ONE automatically at sign-in. The setting can be turned off in the app, and the Clear desktop data control also disables it.

Automatic reachability checks

When ZERO ONE starts, and every 30 seconds while it remains open, it sends an HTTP GET reachability request to each configured ZMail, ZeroThink, OpenZero, and CallChat URL. The request follows HTTP redirects and has a bounded timeout. The configured service, and any followed redirect destination, receives the user's network IP address and the ZERO-ONE/<version> user agent as part of the connection. These probes do not attach the OpenZero API token, prompts, messages, mailbox content, or a diagnostics file.

User-initiated diagnostics export

Diagnostics export runs only when the user requests it and chooses a local save location. The JSON file contains its generation time, app version and platform, operating-system release, logical-core count, total RAM, origin-only service destinations, reachability state, HTTP status and latency, media and launch-at-login preferences, and a yes/no value showing whether an OpenZero token is configured.

The export excludes the computer hostname, API-token value, cookies, email, documents, notes, chat or call content, prompts, and model responses. Service destinations are reduced to origins: URL user information (userinfo), paths, queries, and fragments are not included. The saved file remains at the user-chosen location until the user moves, shares, or deletes it; uninstalling ZERO ONE or using Clear desktop data does not remove saved diagnostics files.

Remote service boundaries

ZMail, ZeroThink, OpenZero, and CallChat are remote-capable services displayed in separate persistent, isolated webview partitions. Requests, authentication, cookies, settings, and content used in those views are handled at the selected service boundary. The reviewed ZERO ONE Desktop preview does not merge their credentials or silently transfer content between those services. Server-side collection and retention can differ by service and must be read with the applicable service disclosure; this section does not claim that remote services collect no data.

Removing the reviewed Windows binary does not itself clear the operating-system application-data directory. ZERO ONE settings and persistent embedded-workspace cookies and storage can therefore remain after uninstall. Users who want to remove that local app data should use the in-app Clear desktop data control before uninstalling.

After confirmation, Clear desktop data removes ZERO ONE settings and the encrypted OpenZero token, clears embedded cookies, storage, caches, and authentication state for ZMail, ZeroThink, OpenZero, and CallChat, disables automatic startup, and restarts the app with defaults. It does not delete accounts, messages, files, or other data held by the connected services, and it does not delete diagnostics files previously saved by the user.

CallChat camera and microphone

Camera and microphone access is disabled by default. If the user enables CallChat media, access is restricted to the exact CallChat HTTPS origin and remains subject to operating-system permission controls.

Selected-folder ZSEC Shield scan

In the reviewed Windows x64 preview, the user must press the scan button and choose exactly one folder through the operating-system picker. The desktop invokes its bundled ZSEC Shield runtime with that selected path and bounded arguments. It does not start a background scan, automatic deletion, or automatic quarantine.

The reviewed desktop bridge does not upload file names, paths, hashes, samples, or reports. The app receives aggregate counts and a bounded scan outcome. Local command-line reports may contain paths, hashes, configured-rule matches, and operational errors. The separate command-line tool supports opt-in recoverable quarantine, but the desktop scan button does not request quarantine.

This selected-folder description is limited to the reviewed Windows x64 preview. It is not a claim about unverified platform packages, real-time protection, cloud reputation, telemetry, crash reporting, or sample submission.

Reporting

To report concerning AI output, use the AI output reporting page. Do not include passwords, API tokens, session cookies, private keys, recovery codes, unnecessary personal data, confidential files, or live malware samples.

Store-readiness boundary

This disclosure describes reviewed source behavior. It does not mean a Microsoft Store submission, publisher signing, exact final-binary verification, clean-machine testing, or review of every connected service's live privacy practice is complete.

6. Boards, comments, and public spaces

In-house boards, comments, feedback, profiles, shared links, and public areas may be visible to other users or administrators. Do not post private information, secrets, API keys, wallet seed phrases, passwords, personal data about other people, infringing content, unlawful content, or anything you do not have the right to publish.

7. Sharing and processors

We may use hosting providers, payment processors, email services, analytics/security tools, AI model providers, API providers, research/search tools, blockchain tools, quantum-cloud/research APIs, file-processing tools, and other technical suppliers. Information may also be disclosed where required by law, to protect rights and safety, to enforce terms, or as part of a business transfer.

8. Retention

Information is retained for as long as reasonably needed for service delivery, account management, security, billing, backups, audit trails, dispute handling, legal compliance, research provenance, IP protection, and claim defence. Abuse, security, payment, and legal records may be retained longer where necessary.

DNA-related files are sensitive. Raw DNA uploads should not be kept longer than needed for service delivery unless account support, security, billing, legal compliance, or dispute handling requires retention. Users can request deletion or review by emailing shaf@talktoai.org; identity or account verification may be required before action is taken.

9. User rights

Depending on your location and the data involved, you may have rights to access, correction, deletion, restriction, objection, portability, withdrawal of consent, and complaint to a regulator. Requests can be sent to shaf@talktoai.org. We may need to verify identity before acting.

10. Security

We use reasonable safeguards, but no website, AI service, upload system, blockchain payment, direct-key workflow, or third-party API can be guaranteed completely secure. Users are responsible for protecting their own accounts, files, API keys, wallets, devices, and passwords.

11. Updates

This policy may change as TalkToAI grows. Continued use after an update means acceptance of the updated policy where permitted by law.