Last updated: February 2026
This policy describes how AIACI (operated from the European Union) collects, uses, and protects information when you use aiaci.com and related services. We protect privacy and comply with the General Data Protection Regulation (GDPR) and applicable EU data protection law.
What Data We Collect
AIACI collects minimal data. No accounts, registration, or personal information is required. We collect only:
- IP addresses: Logged temporarily. Used solely for rate limits (20 messages per day on free web) and abuse prevention.
- Usage counts: Message count per IP per day for rate enforcement. Not linked to personal identity.
What We Do Not Collect
Explicit list of data we do not collect or store:
- Names, email addresses, or contact information
- User accounts or login credentials
- Conversation content or chat history on our servers
- Payment information (web version is free)
- Location data beyond what an IP address reveals
- Browsing history or cross-site activity tracking
Third-Party Services
AIACI uses these third-party services:
OpenAI API: Messages are sent to the OpenAI API (GPT-4o-mini) for processing. OpenAI generates and returns responses through our platform. We do not store message content or AI responses. OpenAI has separate data practices. See the OpenAI Privacy Policy.
Cloudflare: Cloudflare provides content delivery (CDN) and security, including DDoS protection. Cloudflare may process connection data (e.g., IP addresses) for security. Cloudflare has its own privacy policy.
Cookies
AIACI does not use tracking, advertising, or user-identifying analytics cookies. Cloudflare may set a necessary technical cookie (e.g., __cf_bm) for bot detection and security. No cookies for marketing, profiling, or cross-site tracking.
Data Retention
IP logs for rate limiting are deleted automatically after three days. We do not collect personal information or store conversation content. No long-term retention. Usage counts reset daily. Not preserved beyond the rate-limiting window.
Data Security
All connections use HTTPS with TLS encryption. Cloudflare adds network-level security: DDoS protection and Web Application Firewall (WAF). We follow industry-standard practices for the minimal data we handle.
GDPR Compliance
AIACI operates from the European Union. We comply with the General Data Protection Regulation (GDPR). Minimal data and no user accounts mean most provisions are satisfied by design:
- Lawful basis: IP addresses for rate limiting are processed under legitimate interest: abuse prevention and service availability.
- Data minimization: We collect only what is strictly necessary for the service.
- Right of access: You may request information about data associated with your use.
- Right to erasure: You may request deletion. With three-day retention, data is often already deleted.
- Right to object: You may object to processing by contacting us at the email below.
Children
AIACI is a general audience service. We do not knowingly collect data from anyone, including children. No personal information, accounts, or identifying details are collected. No age-specific collection. Parents and guardians should supervise minors online.
Our Data Handling Philosophy
Many platforms collect broadly and decide later. We chose the opposite. AIACI is built on minimal collection: the best protection is not collecting data. Each design choice asked: do we need this? Usually no. Names are not needed for AI responses. Email is not needed for chat. Browsing history is not needed for tools. Minimal collection removes risk categories: no personal databases to breach, no profiles to leak, no accounts to compromise. This is technical reality, not marketing.
How We Chose This Approach
Building without accounts was deliberate. We observed how other AI platforms handle data. Many require registration before one question. They collect email, build profiles, store conversations, use data for training or marketing. We asked if that was necessary for AI chat. We concluded it was not. Trade-offs exist: no cross-device sync on web, no personalized recommendations. We accepted them. Privacy outweighs convenience. Users wanting persistent history can use the iOS app. It stores data on-device, not on our servers.
What GDPR Means Practically
GDPR shapes how the service works. The regulation requires lawful basis, data minimization, and individual rights. For AIACI, compliance is straightforward. Our data footprint is minimal. IP addresses are processed under legitimate interest: abuse prevention and rate limits. Logs are deleted after three days. No tracking cookies, so no consent banners. No lengthy processing agreements. Right to erasure: IP logs are either expired or deleted on request. GDPR protects against data hoarding. Our approach leaves little to protect against.
Changes to This Policy
We may update this policy. Changes appear on this page with a new revision date. We do not collect email. We cannot notify users directly. Review this page periodically.
Contact
Questions about this policy or data protection rights:
Email: hello@aiaci.com
Service: AIACI (EU-based)
Return to AI Chat or learn more about AIACI and all available tools.