BlackLab

Privacy notice

8 October 2026

Draft text, still to be checked by a lawyer.

This notice covers the BlackLab app at https://app.blacklab.chat, the API at https://api.blacklab.chat and the home page. It explains which personal data we handle, why, who else receives it and how long it is kept. Each statement is meant to match how the software works today.

1. Who is responsible

The controller is the seller: BlackLab.

Send privacy questions and requests to the contact given there.

2. In brief

3. Your messages

Standard models. A message goes from your browser to our API. The API keeps it in memory while the request runs, checks it (next paragraph) and forwards it through RedPill to the enclave that runs the model. The answer comes back the same way. Neither one is written to our database or our logs.

The safety check. For these models our API first runs a keyword check, then asks a safety model whether the request crosses one of the three hard limits listed in the terms (section 10). That safety model also runs in an enclave, through RedPill. It reads the latest part of the conversation, up to about 12,000 characters. When it refuses a request, it may also write you a short explanation. Nothing from the check is stored.

Encrypted models. These work when you are signed in and in Chat. Your browser gets the encryption key of RedPill's gateway enclave straight from RedPill, encrypts each message on your device and sends it to our API, which passes it on without being able to read it. The gateway enclave decrypts it for the model's enclave, and the reply travels back encrypted to your browser. Our API sees the model, the size of the request, the token counts and the time. The app checks that the key is bound to the enclave's report. It doesn't yet verify the chip maker's signature on that report.

Receipts. RedPill signs a receipt for every answer. The app can fetch it through our API, which hands it over without keeping a copy.

Without a wallet, the app saves your chats nowhere. They last until you close or reload the page.

4. What our server keeps

Our database holds the items below. None of them is the readable text of a chat.

Logs. Our API writes one line per request: the method, the path, the status code and the time it took. A path can contain an id, such as a chat's random id or a transaction hash. Logs contain no IP addresses, no query strings and nothing you or the model wrote. Error lines add a short technical reason.

IP addresses. Our API doesn't store your IP address. For requests that work without signing in, such as starting free messages, it keeps a keyed hash of the address in memory to limit how often they can be made, and forgets it after a minute or two without requests.

Backups. Copies of the database are encrypted before they leave the server.

5. Payments on the blockchain

6. Agent mode

In agent mode a model can call tools. Our server performs the ones that go online, so the services involved see our server, not you:

None of them is given your wallet address, your IP address or your chat. We don't keep the searches, pages or results. Agent mode doesn't use end-to-end encryption.

7. Who else receives data

We don't sell personal data, and we don't share it for advertising.

8. In your browser

9. Why we use this data

Messages can reveal sensitive things about you, such as your health. Our server only passes them on, but leave out details the model doesn't need.

10. Your rights and choices

11. Security

No system is perfectly secure. If a breach puts your data at risk, we will report it as the law requires and post a notice in the app.

12. Age

BlackLab is only for people aged 18 or over.

13. Changes to this notice

When this notice changes, so does the date at the top. If a change matters to you, the app will point it out.