Privacy

Askoraly collects the strict minimum needed to work. This page says what, for how long, and what you can demand. The durations below are not declarative: they are enforced by an automated task.

What we collect

Four things, no more:

  • Your email address, because it is your identifier and it is how sign-in works.
  • Your preferences: account type, interface language, output language.
  • Technical security data: IP address and browser at the time of a sign-in, to detect abuse.
  • The topics you submit and the questions generated, because they are your results and we have to give them back to you.

We store no passwords

There are none. Sign-in goes through a single-use link valid for fifteen minutes, and only a cryptographic fingerprint of the token is kept: a read of the database yields nothing usable. The same goes for sessions.

How long

Each category has a duration and a reason. Data with no reason to stay is deleted.

Data retention periods
Data Duration Why
Sign-in link 15 minutes After that, it opens nothing. The fingerprint is purged within 24 hours.
Session 30 days Extended as long as you are active. Purged 7 days after expiry.
Security log 12 months Abuse detection. Contains no email address.
Inactive account 24 months With no sign-in for this long, you are warned by email and the account is erased 30 days later.
Accounting records 10 years Legal retention obligation. If the account is deleted, these records are anonymised, not erased.

Your rights

Everything is exercised from your account, without going through us. A deletion takes effect immediately and becomes permanent after 30 days.

  • Access: download all your data from the "My account" page.
  • Rectification: your preferences can be changed directly in the interface.
  • Erasure: account deletion is self-service, it requires no request.
  • Portability: the export is in JSON, structured and reusable elsewhere.

Your API key

If you use your own Claude key, it is encrypted with AES-256-GCM using a master key stored outside the database. It is only decrypted in memory, for the duration of a call. It is never returned to the browser, never written to a log, and does not appear in your export — including for you: a secret is not personal data to hand back, and exporting it would turn a hacked inbox into a key leak.

Cookies

Three cookies, all strictly necessary to operation. None requires consent, because none is used to track you.

  • Session: keeps you signed in. Inaccessible to JavaScript.
  • Security: prevents a third-party site from submitting a form in your name.
  • Language: remembers the language you chose for your next visit.

There is no advertising tracker, no third-party analytics tool, no measurement pixel.