AllGPT

allgpt.live

Privacy Policy & Data Security

সর্বশেষ আপডেট: September 5, 2026

Overview

AllGPT (allgpt.live) is a multi-model AI workspace operated for users who want to chat with frontier models from one account. This policy explains what we collect, why we collect it, how long we keep it, and the security measures we apply.

By creating an account or using AllGPT, you agree to this policy. If you do not agree, please do not use the service.

Information we collect

  • Account data: name, email address, and a hashed password when you register with email. We send a confirmation email to verify that you own the address. If you continue with Google, Google shares your name and verified email so we can create or link your account. We do not receive your Google password. You may also add a date of birth and location on your profile. A Bangladesh mobile number can be saved after we send a one-time SMS code.
  • Chat data: conversation titles, messages, attachment names, and extracted text from files you upload (.txt, .docx, .pdf). Original uploaded files and photos are not stored after the message is sent. Images the models generate for you are stored in that chat so you can reopen and download them. Voice recordings are used only to produce a transcript and are not stored on AllGPT. When you turn on web search, we store the source titles and URLs shown under that reply.
  • Billing data: prepaid credit balance, credit lots and expiry dates, top-up requests (wallet method, amount, transaction ID), usage records, and credit ledger entries when you pay with bKash or Nagad or use platform models.
  • API keys (optional): provider keys and custom endpoint details you choose to save in Settings. These are encrypted before storage.
  • Technical data: session cookies, a first-party visitor cookie used only for anonymous pageview analytics, rate-limit counters, and basic logs needed to operate and secure the service. We do not use third-party ad trackers.

How we use your information

  • Authenticate you and keep you signed in securely.
  • Store and display your conversations across devices on the same account.
  • Route chat requests to the AI provider or model you select.
  • Transcribe voice clips you record in the composer so the text can be edited before you send a message.
  • When you enable web search, look up public sources for that prompt and pass the titles, URLs, and snippets to the model you selected.
  • When you enable read pages, fetch the top public result pages and pass extracted text to the model. Full page HTML is not stored in the chat.
  • Deduct prepaid credits when you use platform keys, and record usage for your balance.
  • Apply credit expiry: unused free credits (starter, bonuses, grants) expire 3 months after they are received; unused credits from an approved top-up expire 1 year after they are added.
  • Verify manual wallet top-ups and prevent duplicate transaction IDs.
  • Protect the service from abuse (rate limits, fraud checks, error monitoring).

We do not sell your personal data. We do not use your chats to train our own models.

What we send to AI providers

When you send a message, the relevant parts of your conversation (including your prompt, prior messages in that thread, extracted text from attached documents, and images on that turn) are transmitted to the provider powering the model you picked — for example OpenAI, Google, Anthropic, xAI, Fal, or DeepSeek, or a custom API you configured. Image-generation prompts are sent to the image model you selected; later chat turns do not resend the generated pixels. Voice clips are sent to OpenAI speech-to-text (using your OpenAI key if you added one, otherwise the platform key) and are discarded after the transcript is returned. The transcript is only saved if you send it as a chat message.

If you turn on web search, we send your prompt (or a shortened search query) to a web search provider — DuckDuckGo by default, or Tavily, Brave, or Serper if those keys are configured on the server. The returned titles, URLs, and snippets are then sent to the AI model you picked so it can cite current sources. We cache identical search queries briefly to reduce repeat lookups.

If you turn on read pages (deep search), we also fetch the top public result pages, extract visible text, and send that excerpt to the selected model. We do not store the full page body in your chat — only the source titles and URLs. Private or local network addresses are not fetched.

If you add your own API key, requests go to that provider under your key and your agreement with them. If you use platform keys, we send requests on your behalf using our infrastructure.

Each provider has its own privacy terms. We recommend reviewing their policies for how they handle API data.

Data security

  • Passwords are stored using industry-standard one-way hashing — never as plain text.
  • API keys are encrypted at rest with AES-256-GCM. The encryption key is kept separate from the database.
  • Sessions use signed, httpOnly cookies so JavaScript on the page cannot read your session token.
  • Database (PostgreSQL) and cache (Redis) run on managed infrastructure with access restricted to the application.
  • Transport is over HTTPS in production (allgpt.live).

No online service can guarantee absolute security. We work to reduce risk, but you should also use a strong unique password and keep your account credentials private.

Data retention

  • Account & chats: kept while your account is active. You may delete individual conversations from the workspace.
  • Billing records: top-up and usage history are kept for account reconciliation, dispute handling, and fraud prevention.
  • Voice recordings: not stored. Audio is discarded after transcription.
  • Logs: short-lived operational logs may be retained for a limited period for debugging and security.

To request account deletion or export of data you control, contact us using the details below. Some billing records may be retained where required for legal or accounting purposes.

Cookies & local preferences

We use an essential session cookie to keep you signed in. Appearance preferences (theme, font, stream speed) may be stored in your browser's local storage and are not sent to our servers unless tied to a saved setting on your account.

Your choices

  • Use your own API keys instead of platform credits where supported.
  • Review and edit voice transcripts before you send them as a message.
  • Delete conversations you no longer need.
  • Sign out on shared devices.
  • Contact us to update or delete account information, subject to legal retention needs.

Children

AllGPT is not intended for users under 13. We do not knowingly collect data from children. If you believe a child has created an account, contact us and we will take appropriate steps.

Changes to this policy

We may update this page as the product or legal requirements change. The "Last updated" date at the top will reflect the latest version. Continued use after changes means you accept the revised policy.

Contact

Questions about privacy or data security: email [email protected] from the address linked to your account, including your registered email so we can verify you.