StealthGPT

StealthGPT Privacy Policy

Effective 2026-09-03

Carrie McKeegan operates StealthGPT. Contact timmymckeegan@icloud.com about privacy, access, correction, or deletion.

Information and purpose

We process your email, chosen display name, and account identifier to provide your account; chats, images, saved memories, and preferences to provide and personalize the service; and usage, performance, error, and subscription records to enforce limits, verify paid access, prevent abuse, and diagnose failures. Search queries, requested webpage addresses, and tool results can be retained with the conversation that uses them.

AI processing is your choice

Before sending content to AI, we ask for explicit permission. Prompts, relevant conversation history, selected images, enabled memories, and custom instructions are sent through OpenRouter to the model provider selected for your tier. Current model providers are DeepSeek, Google, and Moonshot AI; OpenRouter may route requests through hosting providers. Web tools send relevant search queries directly to Exa and fetch requested public webpages. If image generation is enabled, its prompts and selected images are processed by OpenAI.

Processors receive the content needed to answer and safely process your request. Their retention and processing are governed by their applicable policies and service terms. We do not promise that third-party processing is anonymous, zero-retention, or excluded from training. Do not submit information you are not permitted to share. Withdraw AI permission in Settings to stop new AI requests; this cannot recall data already sent.

Hosting, billing, and speech

Supabase stores account data and private files. Vercel hosts the API. Superwall receives your account identifier and purchase-related information to manage subscriptions. Apple processes App Store payments; we do not receive payment-card details. Speech recognition may use Apple's speech service when on-device recognition is unavailable. Microphone, camera, and image access use iOS permission controls.

Documents you choose to upload to Library are stored privately in Supabase and validated by the API. Document text is not sent to an AI provider in this release. Images use the AI processing described above.

Superwall also processes device/vendor identifiers, device and app configuration, approximate location inferred from IP address, and app/paywall interaction events for subscription functionality and analytics. These records may be linked to your account or device. We do not use them for cross-app advertising tracking or sell them to data brokers. We do not request precise device location. Dictation audio is not stored by StealthGPT or uploaded to our API; the text you choose to send is processed as chat content.

App analytics and diagnostics

PostHog in the United States processes pseudonymous account and session identifiers, app and device versions, feature interactions, onboarding and sign-in outcomes, message and file counts and sizes, model usage and cost, performance timings, and error diagnostics to help us improve reliability. Message text, AI reply text, document contents, dictation audio, passwords, and authentication tokens are excluded from analytics. Session replays mask text and images; temporary-chat screens are excluded. You can disable usage analytics and masked replays in Settings. Operational server records used for billing, security, and account deletion remain necessary to provide the service. Account deletion also queues deletion of associated PostHog records and replays.

Retention and deletion

Regular chats, uploads, and saved preferences remain until deleted or the account is deleted. Temporary chats are not saved to conversation history and do not use saved memories or personalization. Temporary images become inaccessible after 24 hours and are removed by scheduled maintenance. Usage/security records may still be recorded for temporary chats; third-party retention is separate.

For Sign in with Apple, we store encrypted Apple authorization tokens server-side to revoke the app's authorization when your account is deleted. These tokens are not used for advertising and are removed with your authentication record. Older accounts without a stored authorization token can still be deleted; the app explains how to remove their Apple authorization in Apple Account settings.

Request account deletion in Settings → Account. Account access is disabled immediately. Our scheduled process removes your authentication record, application data, and private files, normally within 72 hours. Existing signed file links expire before final cleanup. A minimal identifier and deletion status remain to prevent stale-token access and safely retry cleanup. Existing downloads and third-party records, including Apple's required transaction records, are not erased by deleting our account. Contact us for processor-related privacy requests. Deletion does not cancel an Apple subscription; manage or cancel it through the App Store.

The app securely stores a deletion-status receipt on the requesting device. Reopen the app, or choose Check deletion status, to receive completion confirmation after account cleanup. This receipt works after sign-out and does not expose your email or account identifier.

Your choices

Delete chats and memories, manage permissions in iOS Settings, withdraw AI consent, or request account deletion. Contact us to exercise applicable data rights or raise concerns. Processing may occur outside your country. We do not use the app for targeted advertising. This service is not directed to children under 13.

Changes

We update this policy when processing changes and request renewed AI permission for material changes to that disclosure.