Privacy
Askoraly collects the strict minimum needed to work. This page says what, for how long, and what you can demand. The durations below are not declarative: they are enforced by an automated task.
What we collect
Four things, no more:
- Your email address, because it is your identifier and it is how sign-in works.
- Your preferences: account type, interface language, output language.
- Technical security data: IP address and browser at the time of a sign-in, to detect abuse.
- The topics you submit and the questions generated, because they are your results and we have to give them back to you.
We store no passwords
There are none. Sign-in goes through a single-use link valid for fifteen minutes, and only a cryptographic fingerprint of the token is kept: a read of the database yields nothing usable. The same goes for sessions.
How long
Each category has a duration and a reason. Data with no reason to stay is deleted.
| Data | Duration | Why |
|---|---|---|
| Sign-in link | 15 minutes | After that, it opens nothing. The fingerprint is purged within 24 hours. |
| Session | 30 days | Extended as long as you are active. Purged 7 days after expiry. |
| Security log | 12 months | Abuse detection. Contains no email address. |
| Inactive account | 24 months | With no sign-in for this long, you are warned by email and the account is erased 30 days later. |
| Accounting records | 10 years | Legal retention obligation. If the account is deleted, these records are anonymised, not erased. |
Your rights
Everything is exercised from your account, without going through us. A deletion takes effect immediately and becomes permanent after 30 days.
- Access: download all your data from the "My account" page.
- Rectification: your preferences can be changed directly in the interface.
- Erasure: account deletion is self-service, it requires no request.
- Portability: the export is in JSON, structured and reusable elsewhere.
Your API key
If you use your own Claude key, it is encrypted with AES-256-GCM using a master key stored outside the database. It is only decrypted in memory, for the duration of a call. It is never returned to the browser, never written to a log, and does not appear in your export — including for you: a secret is not personal data to hand back, and exporting it would turn a hacked inbox into a key leak.
Cookies
Three cookies, all strictly necessary to operation. None requires consent, because none is used to track you.
- Session: keeps you signed in. Inaccessible to JavaScript.
- Security: prevents a third-party site from submitting a form in your name.
- Language: remembers the language you chose for your next visit.
There is no advertising tracker, no third-party analytics tool, no measurement pixel.