Privacy Policy
Last updated: 2026-06-18
This policy explains what Tipitaka.ai collects, how we use and protect it, and the control you have over your data. Our principle is to collect only the minimum needed to run the service — we do not sell data and we show no ads.
What we collect
Account: when you register or sign in with email or a third party (Google / Facebook), we store an account id, your login identifier (email, or the provider's account id), display name, and your chosen avatar; email accounts also store a hashed password (never plaintext). Guests: a device-level guest id is created automatically on first visit and contains no personal information. Your content: your conversations (questions and AI answers), bookmarks, message feedback (helpful / not helpful), notes and tags. Usage & anti-abuse: aggregate usage counts; your IP is used only for rate-limiting and abuse prevention and is discarded after a short cache window.
How we use it
To provide and improve the search-and-answer service, maintain your account and conversation history, keep the service secure and prevent abuse, and export or delete your data on request. We do not sell your data, show ads, or use your conversations to train our or third parties' models. We may include your display name in the context we send to the AI assistant so it can understand references to you and address you naturally; you can change your display name anytime in Settings.
Third-party services (sub-processors)
To run the service we share necessary data with: · Cloudflare — compute, database, cache, object storage, and email delivery. · Large-language-model providers — via Cloudflare AI Gateway we forward your question (and relevant retrieved canon text) to third-party models to generate answers, currently Anthropic, Google, and DeepSeek; these providers may process data outside your country or region. · Login providers — when you choose Google or Facebook sign-in, we receive your account id, email, and display name. We pass only what is needed to produce an answer.
Storage & retention
Conversations are kept until you delete them; you can delete individual conversations or close your whole account anytime in Settings → Data & Privacy. Closing your account cascade-deletes your account, conversations, bookmarks, and login methods. Operational audit logs are cleared automatically on a fixed schedule.
Your rights
You can export all your data (JSON), delete conversations, and close your account at any time inside the app. For other requests (access, correction, restriction) email us. See the Data Deletion page for exact steps.
Children
The service is intended for serious adults and is not directed to children under 13 (16 in the EU); we do not knowingly collect children's information.
Security
Data is encrypted in transit (HTTPS); passwords are stored as one-way scrypt hashes. No system is perfectly secure, so please safeguard your account and credentials.
Changes
We may update this policy; when we do we revise the "Last updated" date at the top and signal material changes appropriately.
The English version of this document is the authoritative one; translations into other languages are provided for convenience only, and the English version governs in case of any discrepancy.