# Pseudea privacy notice Effective date: 16 August 2026 ## What Pseudea stores You can open and explore Pseudea without creating an account or a guest record in the database. On an anonymous visit, Pseudea sets a short-lived secure browser cookie solely so that a first verified action can be associated consistently. When you first send a message or store a private file, Pseudea creates a pseudonymous guest identifier and secure guest session, then stores guest conversations, AI replies, character and Arena metadata, timestamps, and limited technical usage and security records. Guest use after that first action is pseudonymous rather than fully anonymous: the service does not ask for your name or email, but the stored guest identifier and limited abuse-prevention records distinguish one guest session from another. Guests and registered users can store private files and file metadata. If you create an account, Pseudea also stores your chosen username and account status. Creating an account from a guest session preserves that guest's conversations and files. When signing in to an existing account, you can choose whether to transfer the current guest conversations and files to it. No email address is requested. Passwords and recovery codes are never stored in readable form: passwords use a salted slow hash with a server-side secret, and recovery codes are stored only as one-way digests. Guest and account browser sessions use opaque secure cookies; the database stores only token digests. An unsaved-turn recovery copy may temporarily remain in your browser's local storage if a server save fails. It is used only to help prevent a message from being lost. ## Why it is used This data is used to provide guest or account access, preserve and resume conversation history, make stored files available to their guest or registered owner and to the AI when attached, maintain long-conversation checkpoints, enforce request and storage limits, diagnose failures and provider usage, protect the service from abuse, and administer the service. Pseudea does not enforce a local per-user or global spending allowance; availability of AI replies depends on a shared monthly pool governed by OpenRouter. Pseudea does not claim the right to train its own AI models on your private conversations or files. ## AI processing When you send a turn, the required conversation context and files attached to that turn are sent through OpenRouter to the selected model provider for inference. Files kept in your private Pseudea library are not sent merely because they are stored; they are sent when referenced in model context. OpenRouter states that it does not use API inputs or outputs for model training, but underlying model providers have their own retention and training practices. Do not submit information or third-party images/files you are not entitled to process. OpenRouter privacy information: https://openrouter.ai/privacy ## Hosting and file storage Cloudflare provides the site, Worker, database, security controls, and private object storage. Uploaded objects are kept in a non-public R2 bucket and are served only through authenticated Pseudea routes. Cloudflare documents automatic encryption of R2 objects and metadata at rest and TLS in transit. Cloudflare R2 data security: https://developers.cloudflare.com/r2/reference/data-security/ Cloudflare privacy policy: https://www.cloudflare.com/privacypolicy/ ## Administrator access Authorized Pseudea administrators can list guest identifiers, search registered usernames, and read guest or registered-user conversations, messages, file metadata, and uploaded file contents. For registered accounts they can also read account status. This is intended for service administration, safety, support, and investigation. Admin identities and sessions are separate from customer identities, content browsing is read-only, and transcript/file-content reads are recorded in an audit log. After password re-authentication and an exact confirmation phrase, an administrator can permanently flush all conversation histories. This removes conversations, messages, handoffs, and their linked usage records while preserving registered accounts and uploaded files. An administrator can also delete a selected guest or registered user and that identity's stored data through a separately confirmed, audited action. Administrators cannot retrieve passwords, password hashes, recovery-code digests, or live session tokens through the dashboard. ## Retention and your controls Once created by a first verified message or private-file action, guest identities, conversations, and private files do not expire because of inactivity. Registered conversations and private files also have no customer-controlled expiry. Data remains stored until an authorized administrator deletes the selected guest or registered identity, or performs the global history flush described above for conversation histories. Customers cannot delete guest identities, accounts, conversations, or stored files directly. To request deletion of your data, contact hello@pseudea.ooo and include the support reference shown in the guest Privacy & data panel when applicable. Only an authorized administrator can complete deletion through the dedicated admin dashboard. Access to guest history and files depends on the secure cookie in the same browser. Pseudea renews that guest session when the app opens successfully; it expires after one year without a successful return. Clearing site data, losing the device, or letting that session expire can make guest history and files inaccessible to you even though they remain stored. Create an account first if you need recoverable or cross-device access. You can: - export the canonical transcript of a conversation; - rename a conversation; - for a registered account, rename the username without losing ownership or history; - for a registered account, download a complete ZIP archive containing an account manifest, every canonical conversation and all currently stored file contents; credentials, recovery material and sessions are excluded; - as a guest or registered user, rename, download, or reuse a stored file; and - request deletion by emailing hello@pseudea.ooo. Administrator deletion may require a bounded infrastructure retry after a partial storage failure. Security, usage, and audit records may be retained where reasonably necessary for abuse prevention, accounting, legal obligations, or proof of authorized administrative access. ## Security and sensible use Pseudea applies access controls, private storage, transport encryption, rate limits, content-type validation, and one-way credential storage. No internet service can guarantee absolute security. Keep passwords and recovery codes private, and avoid submitting unnecessary sensitive data. This notice may be updated when the service or its providers change. The effective date above identifies the current version.