Controller
ZL Partnership LLC, reachable at hello@dusken.ai.
The design in one paragraph
Conversations are processed transiently to generate a reply and are not intentionally retained by us afterward. Chat history is stored only as encrypted data under a key you hold; we cannot read it. This posture is internally tested, not independently audited. Our testing covers the surfaces we have enumerated, not every conceivable one.
What we hold and for how long
| Data class | What it is | Retention |
|---|---|---|
| Encrypted envelopes | Your chat history and memory, encrypted client-side. We hold ciphertext only. | Until you delete it or close your account |
| Sync metadata | Timestamps, sizes, and version markers needed to sync envelopes between your devices | Until the related envelope is deleted |
| Account identifiers | Email or login handle, hashed credentials | Life of the account |
| Entitlements | Which plan you are on, renewal dates, payment status (not card numbers) | Life of the account, then per the retention table |
| Per-epoch age nullifiers | A privacy-preserving token that shows an age check passed, without identity | Rotated per epoch; not linked to your identity |
| Spent quota tokens | Markers that free-tier tokens have been used, to prevent double-spend | Until the token epoch expires |
| Security events | Login failures, abuse signals, enforcement actions | 90 days |
| Anti-abuse counters | Transient rate and pattern counters | Up to 24 hours |
| Infrastructure logs | Server and network logs without conversation content | 30 days |
| Aggregates | Counts and totals with no per-user linkage | 13 months |
Some business, tax, and payment records must be kept for the periods the law sets; the retention table for those is being confirmed with counsel and will be published here.
What we do not hold
Plaintext conversation content after inference (see posture above). Identity documents: our age check is performed by a vendor and we do not store IDs. Card numbers: our payment processors hold them, not us.
Processors
We use a small number of service providers to run the Service: [PROCESSOR LIST] (payments, age attestation, hosting/inference). Each is bound by contract to use data only to provide the service to us. We publish the list and update it when it changes.
No sale, no ads
We do not sell or share personal information for money or for advertising. We do not run third-party trackers or advertising scripts on our sites or apps. We do not use your conversations to train models.
Your rights
Wherever you live, you can: see what we hold about your account, correct it, export it, and delete it. Deleting your account removes the data classes above, except what the law requires us to keep. California residents have the additional rights described in the CCPA/CPRA, including the right to know, delete, correct, and not be discriminated against for exercising them; we do not sell or share personal information, so there is nothing to opt out of. To make a request, use Settings → Privacy or email hello@dusken.ai. We verify requests through your account and answer within the time the law sets (45 days in California).
Security
Data in transit is encrypted. Chat data is encrypted on your device before it leaves it. Our security controls are internally tested, not independently audited; we will say so plainly until that changes.
Legal requests
We comply with valid legal process. We can only produce what we hold, in the form we hold it (see the table). We notify affected users when the law allows.
Children
The Service is for adults. We do not knowingly collect information from anyone under 18; if we learn we have, we delete it. Material changes to this notice are posted with an effective date before they take effect.