Privacy Policy
Last updated: July 8, 2026
NoFootprint is private, solar-powered AI. We built it so you can use AI chat,
search, and creation tools without your conversations being mined, sold, or handed to a
third-party AI provider. This policy explains what we collect, what we deliberately don't,
and the controls you have.
This policy covers the hosted service at nofootprint.chat, operated by
Universal Basic Inc ("NoFootprint", "we"). If you run NoFootprint on your own hardware, you (or
whoever operates that instance) are the data controller for it — your data stays on your
machines and this policy describes the hosted service only.
The short version
- Your prompts run on hardware we own — not OpenAI, Anthropic, Google, or any third-party AI API.
- We don't sell your data, show ads, or use third-party analytics/tracking.
- We don't use your conversations to train AI models.
- Your saved memories are encrypted at rest (AES-256-GCM, a key derived per user).
- You can export everything and delete it — including your whole account — from inside the app.
Information we collect
Account information
When you register we collect your name, email address, and a password (stored only as a
salted hash — we never store your plaintext password). We use your email to sign you in and to send essential service emails (e.g. verification, password reset). If you opt in — via a
clearly-labelled, unticked box at signup — we may also send occasional product-update emails
and/or our newsletter (two separate opt-ins); these are entirely optional, separate from
essential emails, and you can turn each on or off at any time in Settings → Email.
Content you create
- Conversations — the messages you exchange with the AI, stored so your chat history is there when you return.
- Memories — to personalize your experience, the assistant may save short facts you share (e.g. preferences). These are stored encrypted, are tied to your account only, and you can view, edit, and delete them at any time.
- Files & documents you upload for tools (e.g. document Q&A, conversion, audio cleanup), stored per-account so you can access them.
- Voice input (microphone) — if you tap the voice-input button, your device's microphone records audio only while you're speaking and sends it to our servers to transcribe into text; the transcription becomes your message. We use the audio solely to provide this feature — never to train models or for advertising. You can use the app entirely by typing; the microphone is only accessed when you choose voice input.
- Reports — if you use the report button, we store the report (reason, the reported item, your account id) to review and act on it.
Technical information
We keep minimal operational logs needed to run and secure the service (e.g. timestamps,
error and request metadata). By default these logs do not contain the text of your
messages; verbose content logging is off. We use your authentication token and a few
preferences stored in your browser's local storage to keep you signed in and remember settings —
these are not advertising or cross-site tracking cookies.
How we use your information
Only to provide and protect the service: to authenticate you, run your AI requests, store
and show your conversations/memories/files, operate the tools you invoke, keep the service
secure, and meet legal obligations. That's it — no profiling for ads, no selling, no sharing
for marketing.
What we don't do
- We don't send your prompts or content to third-party AI providers — inference runs on our own hardware.
- We don't sell, rent, or trade your personal information.
- We don't use third-party advertising or analytics trackers.
- We don't train AI models on your conversations.
How your data is protected
- Encrypted in transit — all traffic uses HTTPS/TLS.
- Encrypted at rest — saved memories are encrypted with AES-256-GCM using a key derived per user.
- Access controls — requests are authenticated with signed, expiring tokens; your data is scoped to your account.
- Self-hosted infrastructure — the service runs on hardware we control, powered by solar, rather than rented hyperscale cloud.
- Safety filtering — automated content moderation and a user reporting tool help keep generated content within our Content Policy.
No system is perfectly secure, but we design to minimize what's collected and to keep it under our (and your) control.
Third parties & sub-processors
We keep these to a minimum:
- Web search — when you use search, your query is sent to a privacy-respecting search provider — Mojeek (mojeek.com, an independent search engine), with our self-hosted SearXNG metasearch as a fallback — to fetch results. The provider receives the query text but not your identity or account. For current-events questions we also retrieve public news RSS feeds; this sends no user data (we fetch whole feeds on our server and match locally).
- Email delivery — emails (verification, password reset, and optional product updates or newsletter if you opted in) are sent via Resend (resend.com), which receives the recipient address and message content needed to deliver the email.
- TLS certificates — issued by Let's Encrypt.
AI model weights are obtained from open model repositories at setup time; this involves no
user data. We do not use cloud AI APIs.
Data retention
We keep your account and content until you delete it or close your account. When you delete a
conversation, memory, or your account, we remove the associated data from active storage; routine
encrypted backups, if any, are rotated out on a regular cycle.
Your rights & controls
From within the app you can:
- Export your data.
- View, edit, and delete individual memories.
- Manage email preferences — opt in or out of product-update emails and the newsletter at any time (Settings → Email).
- Delete your account and associated data.
Depending on where you live, you may also have rights under laws such as the GDPR or CCPA —
including access, correction, deletion, portability, and objection. To exercise any of these,
use the in-app controls or email us at devteam@universalbasicinc.com.
Children
NoFootprint is not directed to children under 16 (or the minimum age in your country), and
AI-generated content makes it unsuitable for minors. We don't knowingly collect data from
children; if you believe a child has provided us data, contact us and we'll delete it.
Changes to this policy
We may update this policy as the service evolves. We'll revise the "last updated" date above
and, for material changes, provide notice in the app.
Contact
Questions or requests: devteam@universalbasicinc.com
· Universal Basic Inc, 2722 Erie Ave Ste 219, PMB 805065, Cincinnati, Ohio 45208-2154, US.