1. Who this policy covers
This Privacy Policy applies to the HerGPT website and chat service at hergpt.org. “HerGPT,” “we,” and “us” refer to HerGPT as the operator of this service.
This document describes how HerGPT works today. We will update it when the service or our data practices change.
2. Data we handle
- Account and authentication data. Our authentication service handles the email address, account identifier, authentication records, essential session cookies, and the password flow used to sign in. HerGPT does not store your plaintext password in its application database.
- Conversation data. We store conversation titles, your accepted messages, completed assistant replies, and timestamps so your history can be reloaded. A title may be derived from the first part of your first message. If a generation fails or is stopped, the accepted user message can remain while an incomplete assistant reply is not saved.
- Generation and reliability data. We store identifiers, model ID, status, finish reason, token counts when available, latency, bounded error codes, and timestamps. A separate content-free usage record stores account ID, generation ID, model ID, and start time, but no prompt or reply text.
- Modeled impact data. For eligible completed replies, we use limited generation metadata to create a private, versioned modeled comparison. The private event links to the content-free usage record and contains no prompt or reply text. The private shared-cycle record stores aggregate research totals without an account ID. Those totals are not currently shown as public progress.
- Deletion-request data. A whole-account request stores a random receipt, the account ID derived from the signed-in session while the request is open, its status, and operational timestamps. It stores no email address, reason, free text, message content, or identity document. The account reference becomes null after hard deletion.
- Giving-program launch preference. If you choose an in-app launch notice, we store your account ID, a server-owned consent-version label, and the opt-in time. We do not store an email address or notification channel in this preference. An earlier launch-interest choice remains visible for its original purpose until you remove it or explicitly update it to the in-app notice.
- Platform request data. Our hosting, authentication, model, and network providers may process technical request data such as IP address, device/browser details, security signals, and service logs under their own service terms.
3. Why we use it
We use this data to create and secure accounts, save conversations, produce AI replies, restore history, enforce account limits, diagnose failures, protect the service, fulfill account-deletion requests, and remember an optional preference for a future in-app giving-program announcement.
HerGPT does not use advertising or behavioral analytics. It does not currently process payments or user donations.
HerGPT is evaluating a provisional research model—not a direct measurement—for a future comparison with frontier chat apps. The public preview stays in calibration and does not currently show personal energy- savings progress. Private research records do not expose prompts, private totals, thresholds, formulas, or individual usage details. Actual energy use may vary.
No public Community progress, donation, fund, or company-funded support activity is active. Any later program requires separate evidence, funding policy, authorized-recipient, cadence, reconciliation, and legal review. You are not charged for this research or for the planned program.
4. How AI message processing works
HerGPT is an AI system, not a person. To generate a reply, our server sends HerGPT's system instructions, your current message, and a bounded recent window of the conversation to an AI inference service. The current bound is up to 20 recent messages and about 16,000 message characters.
The application does not deliberately add your email address, account ID, conversation ID, or conversation title to the model request. However, anything you type in a message can be included. Do not enter sensitive, confidential, medical, financial, legal, or identifying information that you do not want processed by a third-party AI service.
HerGPT uses a third-party AI inference service to generate replies. That service may maintain operational logs and follows its own data-retention practices. We do not promise that copies controlled by that service follow the same lifecycle as data in HerGPT's application database.
5. Service providers
HerGPT currently relies on:
- Account and database infrastructure for authentication and saved product data;
- Cloud hosting infrastructure for the website and server execution;
- AI inference infrastructure for generating replies; and
- Network and security infrastructure for DNS, traffic delivery, and protection.
These providers process data needed to supply their part of the service and can maintain their own operational logs and retention practices.
6. Retention and deletion
HerGPT currently has no automatic expiry for saved messages or generation metadata. You can delete an individual conversation from the chat menu. That removes the conversation, its messages, and its generation records from the active HerGPT database. The content-free usage record and any linked private modeled-impact event remain until the whole account is deleted so account limits and the private method record cannot be reset by deleting a conversation.
To request deletion of the whole account and HerGPT-controlled data, sign in and use the request control on the Account & data page. The request is recorded in a private queue and completed manually by the team. It is not an instant delete, and no email notification is sent. While the account remains active, you can return to that page to see the request status.
Completion hard-deletes the authentication account and verifies that active HerGPT conversations, messages, generation records, and usage events are gone. Private modeled-impact events linked to those usage events and a saved giving-program launch preference are also deleted with the account. The company community-cycle aggregate, including shared progress already recorded, remains as a non-user-linked company record; it does not contain an account ID or let us reconstruct your individual activity. You can withdraw the launch preference at any time on the Account & data page without deleting your account. The minimal completion receipt, status, and timestamps remain with the account identifier set to null; that record currently has no automatic expiry. An already-issued access token may remain technically valid until it expires, and a model response already in flight may finish its bounded processing window. Prompts retained by third-party services, platform logs, support records, and backups follow separate service or operational retention lifecycles.
7. Security and your choices
HerGPT uses authenticated API requests, owner-scoped database rules, and server-only privileged credentials. No internet service can guarantee perfect security. Keep your password private, sign out on shared devices, avoid sensitive message content, and delete conversations you no longer want.
Use the signed-in Account & data page to submit a deletion request. HerGPT does not currently use email for deletion intake or status updates.
8. Changes to this policy
We may update this page as the service or legal requirements change. Material updates will be posted here with a revised effective date. The effective date shown on this page applies to the version you are reading.