Privacy & service providers
Effective August 12, 2026 · Web disclosure version r0-web-disclosure-2026-08-11
What My AI stores
Your account, conversations, projects, text sources, context snapshots, receipts, and artifacts are stored in the application’s Supabase project. Access is restricted by authenticated ownership rules. Project source originals use private storage.
Operational audit and analytics records contain identifiers, counts, safe reason codes, and states. They do not contain raw prompts, generated search queries, retrieved excerpts, project-source content, or model answers.
Optional Web evidence
Web search is optional and separately controlled with Auto, On, or Off. For a Web-enabled request, My AI sends only the current prompt as the submitted Web request through OpenRouter to Exa. OpenRouter or Exa may internally derive a search query; My AI does not store that provider-internal query unless it is authoritatively returned. The current retrieval contract does not return or store one. Project instructions, uploaded sources, conversation history, previous answers, and internal system prompts are not sent to Web retrieval.
OpenRouter’s inference zero-data-retention controls do not cover Web tools. Provider policies govern their processing, so avoid putting sensitive or personal information in a Web-enabled request. You can select Off for any request.
My AI stores the private submitted Web request (the current prompt), canonical source URLs and titles, bounded retrieved excerpts, timestamps, hashes, and cost/usage evidence so cited answers can be replayed, received, and exported. Public receipts omit the submitted request and excerpts. Account or project deletion removes access immediately and schedules the applicable private data for purge.
Citation validation proves only that the quoted span occurs in the stored retrieved excerpt. It is not independent fact-checking or live-page verification. Source links open external websites with their own privacy practices.
Read OpenRouter’s current zero-data-retention documentation and Web-search tool documentation.
Service providers
| Provider | Purpose | Policy |
|---|---|---|
| Lovable | Application hosting and deployment | Privacy policy |
| Supabase | Authentication, database, and private file storage | Privacy policy |
| Google Gemini | Answer-model inference when a Gemini model is selected | Privacy policy |
| OpenRouter | Alternative-model inference and the optional Web-search gateway | Privacy policy |
| Exa | Web search for Web-enabled requests only | Privacy policy |
Your choices
You can keep Web Off, export available account or project data, remove project sources, or request account deletion from Settings. Historical cited answers remain readable when new Web retrieval is disabled.