Privacy notice
This notice covers the BlackLab app at https://app.blacklab.chat, the API at https://api.blacklab.chat and the home page. It explains which personal data we handle, why, who else receives it and how long it is kept. Each statement is meant to match how the software works today.
1. Who is responsible
The controller is the seller: BlackLab.
Send privacy questions and requests to the contact given there.
2. In brief
- We don't ask for a name, an email address or a phone number. Your account is a wallet address. A wallet address can be linked to a person, so we treat it as personal data.
- Our server forwards your messages to the model and doesn't save their text.
- With a model marked Encrypted, your browser encrypts every message, and our server relays only the encrypted form.
- Synced chats are encrypted in your browser with a key made from your wallet's signature. We receive only the encrypted copy.
- Payments are public transactions on BNB Chain.
- No ads, no analytics, no tracking.
3. Your messages
Standard models. A message goes from your browser to our API. The API keeps it in memory while the request runs, checks it (next paragraph) and forwards it through RedPill to the enclave that runs the model. The answer comes back the same way. Neither one is written to our database or our logs.
The safety check. For these models our API first runs a keyword check, then asks a safety model whether the request crosses one of the three hard limits listed in the terms (section 10). That safety model also runs in an enclave, through RedPill. It reads the latest part of the conversation, up to about 12,000 characters. When it refuses a request, it may also write you a short explanation. Nothing from the check is stored.
Encrypted models. These work when you are signed in and in Chat. Your browser gets the encryption key of RedPill's gateway enclave straight from RedPill, encrypts each message on your device and sends it to our API, which passes it on without being able to read it. The gateway enclave decrypts it for the model's enclave, and the reply travels back encrypted to your browser. Our API sees the model, the size of the request, the token counts and the time. The app checks that the key is bound to the enclave's report. It doesn't yet verify the chip maker's signature on that report.
Receipts. RedPill signs a receipt for every answer. The app can fetch it through our API, which hands it over without keeping a copy.
Without a wallet, the app saves your chats nowhere. They last until you close or reload the page.
4. What our server keeps
Our database holds the items below. None of them is the readable text of a chat.
- Account: your wallet address, when it first signed in, your credit balance and whether adult content is on. Kept while the account exists.
- Sign-in: for each session, a hash of its token, the account it belongs to and when it expires (7 days after sign-in). The one-time codes used to sign in are deleted once used, or after 10 minutes.
- API keys: a hash of each key, its first few characters, the label you gave it, and when it was made or revoked.
- Usage: one line per request with its type, the model, the token counts, the cost and the time. For a web search, the line says a search took place, not what was searched. You can see these lines under Account.
- Payments: the network, the transaction, the paying wallet, the amount, the status and any hold reason, when you made the request to start at once, which terms version you accepted, and the time of the sanctions screening. If our host passes us the country your connection comes from, as a two-letter code, that code is stored with the payment as well. Kept for the period bookkeeping law sets.
- Refunds: the wallet, the amount, the status and the payout transaction. Kept like payments.
- Free credit we gave you, if any, with a short note saying why.
- Synced chats, only if you turn syncing on: the encrypted copy, its random id, its size, a revision number and when it last changed. Deleted straight away when you burn a chat or stop syncing.
- Free messages without a wallet: a hash of your browser's token, the day it was made and how many messages it used today. No wallet address and no IP address. Deleted 30 days after the token was made.
- Free messages with a wallet: today's count for your account, removed the following day. The messages themselves appear in your usage at zero cost.
Logs. Our API writes one line per request: the method, the path, the status code and the time it took. A path can contain an id, such as a chat's random id or a transaction hash. Logs contain no IP addresses, no query strings and nothing you or the model wrote. Error lines add a short technical reason.
IP addresses. Our API doesn't store your IP address. For requests that work without signing in, such as starting free messages, it keeps a keyed hash of the address in memory to limit how often they can be made, and forgets it after a minute or two without requests.
Backups. Copies of the database are encrypted before they leave the server.
5. Payments on the blockchain
- A payment is a public transaction on BNB Chain. Anyone can see the sending wallet, our receiving wallet, the amount and the time. Nobody, us included, can remove it.
- Our server reads the network through a node provider. It asks about payments to our wallet and, when you open the top-up screen, about your wallet's USDT balance. The provider sees our server asking, not your device.
- We screen each paying wallet against the US Treasury's (OFAC) list of sanctioned addresses, plus any addresses we add by hand. The list is downloaded daily and the check runs on our own server, so your address isn't sent to anyone for it.
- Your wallet app reaches the network through its own provider, under its own privacy terms.
6. Agent mode
In agent mode a model can call tools. Our server performs the ones that go online, so the services involved see our server, not you:
- Web search (Brave Search) receives the search words, up to 400 characters.
- Reading a page: the website gets a request for that address from our server.
- Wikipedia search: Wikipedia receives the search words, through the same page reader.
- Market data (GeckoTerminal and DexScreener) receives the network, or the token name, symbol or contract address asked about.
None of them is given your wallet address, your IP address or your chat. We don't keep the searches, pages or results. Agent mode doesn't use end-to-end encryption.
7. Who else receives data
- RedPill receives every model request and safety check from our server: readable for standard models, encrypted for Encrypted ones. It runs the models in enclaves operated by companies such as Phala, Chutes, NEAR AI and Tinfoil. When you use an Encrypted model, your browser also asks RedPill directly for the enclave's key. That request carries your IP address, but no cookie and no message.
- Railway runs our API and its database. Vercel serves the app and the home page. Like any host, both handle the IP addresses of incoming connections to deliver traffic.
- Brave, Wikipedia, websites, GeckoTerminal and DexScreener, in agent mode only, as section 6 describes.
- A BNB Chain node provider, as section 5 describes.
- Authorities, when the law obliges us to hand data over.
We don't sell personal data, and we don't share it for advertising.
8. In your browser
- One cookie. Signing in sets one session cookie from our API that page scripts can't read. It ends when you sign out, or after 7 days. It only keeps you signed in, so we don't ask for consent to it.
- Local storage: a few settings (Chat or Agent, your preferred model, the wallet you used last, where your chats are kept), the free-message token, and the transaction of a payment still awaiting confirmation. Some of these settings are labelled with your wallet address.
- IndexedDB: your chats, encrypted, and the keys that open them. The keys are stored so that the app can use them but no script can copy them out.
- On sign-out the app deletes the synced-chat key and its local copies of synced chats. If you chose to keep chats on this device only, they stay on this device in encrypted form until you burn them or delete this site's storage in the browser.
- The app and home page load no ads, analytics or trackers, and no scripts or fonts from other sites. The app connects only to our own servers and to RedPill.
9. Why we use this data
- To provide what you asked for (the contract): your account, sign-in, chats, usage, credits, payments and refunds.
- To meet legal duties: bookkeeping and tax records of payments, sanctions screening, and the consumer-law record of your request to start at once.
- Our legitimate interest in a safe, working service: logs, rate limits, the safety check on requests, and stopping misuse of free messages.
Messages can reveal sensitive things about you, such as your health. Our server only passes them on, but leave out details the model doesn't need.
10. Your rights and choices
- In the app you can burn one chat or all of them, stop syncing (which deletes the copies on our server), revoke API keys and switch adult content off. These take effect in our database at once.
- You can ask for a copy of the data we hold on your wallet, and ask us to correct it, delete it, limit its use, or give it to you in a machine-readable format. You can also object to uses based on our legitimate interest.
- Write to the contact in section 1. We know you only by your wallet, so we will ask you to show you control it, for example by signing a message with it.
- Payment records that bookkeeping law makes us keep can't be deleted early. No one can delete a transaction from the blockchain.
- You may also lodge a complaint with a data protection supervisory authority, in particular where you live or work.
11. Security
- All connections use HTTPS.
- Session tokens and API keys are stored only as SHA-256 hashes.
- Synced chats are encrypted with AES-256-GCM in your browser.
- Our server holds no key that can send funds. Refunds are paid from a separate wallet.
No system is perfectly secure. If a breach puts your data at risk, we will report it as the law requires and post a notice in the app.
12. Age
BlackLab is only for people aged 18 or over.
13. Changes to this notice
When this notice changes, so does the date at the top. If a change matters to you, the app will point it out.