Privacy

This beta privacy policy explains what Chat Of Our Own collects, why we use it, what stays private, what can become public, and what you should never send through CO3 forms or chats.

Last Updated

July 6, 2026. CO3 is in beta, so privacy language may change as account, feedback, support, moderation, and app features become more complete.

What CO3 Collects

What CO3 Uses Data For

Accounts

CO3 uses Supabase Auth for beta account creation, login, session persistence, and password recovery. CO3 does not ask you to send passwords through feedback, support, screenshots, chats, or persona fields.

Feedback

Feedback may include your name, email, beta interest, category, message, and bug or safety details if you choose to provide them.

Reports

Bug, safety, moderation, and persona reports may be retained with review status, notes, source page, and timestamps so CO3 can follow up and enforce rules.

Model Access And API Keys

Integrated model access, when granted, does not show users the underlying CO3 provider keys. Integrated provider options may include OpenAI, Gemini, and DeepSeek through Fireworks when available. Some automated persona and review tools may use CO3-managed OpenAI access even when a different chat provider is selected.

BYO API keys are sensitive credentials. Enter BYO keys only through the app's dedicated Connection Settings flow. Do not send them through feedback, chats, screenshots, support messages, bug reports, persona fields, or public posts. If you believe a key was exposed, revoke it in your provider account and create a replacement.

For a shorter non-legal explanation of private work, public personas, saved BYO keys, and feedback review, read the trust and data guide.

What Not To Submit

Storage And Service Providers

CO3 uses service providers to run the beta site and app, including hosting, authentication, database, deployment, and related infrastructure. These services process data as needed to provide CO3 features, keep the site online, and help CO3 review issues.

AI model requests may include the current prompt, relevant personas, runtime briefs, recent messages, memories, formatting rails, and other context needed for that feature. CO3 works to avoid sending unnecessary private material, but roleplay and persona features require processing the content needed to generate or debug the requested output.

Admin Review And Debug Exports

Authorized admins may review reports, public archive listings, account status, moderation queues, provider usage, and selected debug or turn trace exports when needed for support, safety, abuse prevention, debugging, or beta operations. Debug access is intended for admin use, not general public access.

Retention

Beta data may be kept while it is useful for account access, saved work, support, moderation, safety review, abuse prevention, debugging, or product development. Some records may be corrected, archived, migrated, or deleted as the beta changes.

Account And Data Deletion

During beta, you can request account deletion or data review through the feedback form. Choose general feedback, include the account email, and write "account deletion request" or "data request" in the message. Admin deletion tools may remove the account only, or the account plus owned CO3 data such as personas, chats, memories, feedback, profile, and access rows. CO3 may need to keep limited records when required for safety, abuse prevention, audit history, legal compliance, provider usage review, or unresolved support issues.

Data Requests

For account, privacy, or data concerns, use the feedback form and include the email address connected to your account if the request is account-specific. Do not include passwords, API keys, or private tokens.