1. Who this policy covers
This policy covers visitors, account holders, subscribers, guests using direct-key mode, people who submit prompts, files, feedback, board posts, support requests, research materials, DNA-related files, ZMath files, or payment-related information through ZeroThink or linked TalkToAI services.
2. Information collected
- Account details, such as name, email address, Google login identifiers, subscription status, account role, and support messages.
- Technical information, including IP address, user agent, device/browser information, security logs, rate-limit events, and timestamps.
- User content, including prompts, uploaded files, generated outputs, research notes, chat history, board posts, comments, feedback, and files selected for analysis.
- Payment-related records, including plan type, subscription status, payment references, cancellation events, and fraud-prevention signals. Full card data is handled by payment processors when applicable.
- Direct-key and ZeroKill information. A temporary API key is transmitted through the ZeroThink server only as needed to call the selected provider. ZeroKill keeps that temporary key in page memory for the current tab and request, and does not write it to persistent browser
localStorage, the account Vault, saved account memory, or chat history. A signed-in user may instead choose a provider key they previously saved in Neural Vault; that existing key is resolved server-side for the selected request, is not returned to the page, and is not copied into ZeroKill history. Direct mode also offers an optional tab-only sessionStorage choice.
- DNA Lab or health-research data when a user voluntarily uploads it. This may include sensitive personal data and should only be uploaded by someone with lawful authority to use that file.
3. How information is used
- To provide ZeroThink, QuantumZero, ZMath, DNA Lab, board, research, subscription, upload, export, and support functions.
- To secure the service, stop abuse, detect automated misuse, investigate suspicious activity, protect intellectual property, and preserve audit logs.
- To improve reliability, debug errors, test features, maintain model and tool performance, and understand which features are useful.
- To process subscriptions, cancellations, refunds where applicable, and payment disputes.
- To comply with legal obligations, enforce terms, respond to lawful requests, and defend against claims.
4. Lawful bases
Depending on the context, information may be processed to perform a contract with the user, to take steps requested by the user, for legitimate interests such as security, service improvement, fraud prevention, IP protection, record keeping, and claim defence, to comply with legal obligations, or with consent where consent is required.
5. AI, research, and sensitive files
Users should not submit confidential, regulated, medical, genetic, legal, financial, government, defence, employer-owned, third-party, or highly sensitive material unless they have permission and accept the processing risk. DNA and health-research outputs are informational research outputs only and are not medical advice, diagnosis, treatment, or clinical decision support.
No-login BYOK features are server relays, not direct browser-to-provider connections. ZeroThink receives the key and submitted claim, prompt, evidence, or file context long enough to make the provider request. The selected AI or search provider then processes that material under its own terms and privacy controls. ZeroKill and Direct mode do not add those requests to normal ZeroThink account history or memory.
5A. DNA Lab data flow and choices
- Explicit upload: DNA Lab processes a raw genotype file only after the signed-in user confirms the research-use and privacy notice. Upload only your own file, or a file you have clear authority to process.
- Default handling: the uploaded raw file is used to generate the requested report and is not kept as a normal library document. The temporary upload is discarded by the server after the request.
- Optional private save: if the user selects “save,” an eligible file is stored in that account's private, non-web DNA vault. It is classified as sensitive genotype data and is excluded from Zero Library search, retrieval-augmented generation, and ordinary AI context.
- Optional DNA Agent: a separate consent is required. The Agent receives a minimised derived summary, not the raw file, sample rows, filename, file hash, exact genotypes, or rsID list. The private DNA-Agent lane does not read or write normal chat history, saved memory, or Zero Library context. The minimised summary and the user's question are sent to the model provider identified in the interface, currently Groq.
- Sensitive health screen: selected sensitive findings are withheld by default and require a separate opt-in. Build, strand/orientation, callability, and quality gates may withhold personalised interpretation.
- No silent imputation: a missing or no-call marker is not treated as a negative result, and ZeroThink does not silently strand-flip, impute, or clinically confirm an uploaded result.
To ask about access, correction, deletion, restriction, or withdrawal of consent for DNA-related data, email shaf@talktoai.org from the account email. Backup and security-log handling is described below.
6. Sharing and processors
Information may be processed by hosting providers, payment providers, email providers, analytics/security tools, AI model providers, API providers, search providers, quantum-cloud or research API providers, and other technical suppliers used to deliver the service. DNA uploads are not sent to an AI provider merely to create a deterministic local report; the separately consented DNA Agent sends only the minimised derived context described above. Information may also be disclosed where required by law, to protect users or systems, to enforce terms, or as part of a business transfer.
7. In-house boards and public areas
Posts, comments, profile names, uploaded public materials, and board activity may be visible to other users or administrators. Users should not post private information, secrets, passwords, keys, personal data about others, unlawful material, or content they do not have the right to publish.
8. Retention
Records are kept only as long as reasonably needed for service delivery, security, account management, payment records, legal compliance, dispute handling, backups, research audit trails, and IP protection. Temporary ZeroKill and Direct-mode API keys are not intentionally persisted by those application endpoints and are used only within the request lifecycle, except for Direct mode's optional tab-only sessionStorage choice. A provider key deliberately saved by a signed-in user remains in Neural Vault until the user replaces or removes it through available account controls or a verified deletion request; ZeroKill does not create an additional stored copy. Short-lived rate-limit records may be retained to protect the public endpoint. An unsaved DNA upload is temporary for the analysis request. A DNA file saved by the user remains in the account-private vault until it is removed through an available account function or a verified deletion request, subject to limited backup retention and legal obligations. Security logs, abuse records, payment records, and claim-defence records may be retained for longer where necessary; application access logs are designed not to record uploaded file bodies.
9. User rights
Depending on location and the information involved, users may have rights to access, correction, deletion, restriction, objection, portability, withdrawal of consent, and complaint to a regulator. Requests can be sent to shaf@talktoai.org. Identity checks may be required before action is taken.
10. Security
Reasonable technical and organisational measures are used to protect the service, but no website, AI workflow, blockchain transaction, uploaded-file system, or API integration can be guaranteed completely secure. Users are responsible for keeping account access, API keys, wallets, and files safe.
11. Changes
This policy may be updated as the service changes. Continued use after an update means the user accepts the updated policy where permitted by law.