1. Status and operator
Individual entrepreneur Andrey Sergeevich Rudakov, INN 312832529605. Website: https://gptaid.ru. Support, complaints and personal data enquiries: support@gptaid.ru.
2. Browser data
The site stores your theme, optional-feature choice and a temporary selected prompt draft in your browser. With optional-feature permission, the browser contacts ipwho.is to estimate your city; that service sees the public request IP. GPTAID does not store the full IP for this feature.
3. Account data
The primary server stores email, password hashes, linked social account identifiers, sessions, projects, chats, agent settings, tickets, API key records and usage logs. Uploaded and generated files use private Beget S3. API secrets are shown once and then stored as hashes. YooKassa processes payment details. GPTAID stores transaction and saved-method identifiers, method type, last card digits and renewal consent, never full card numbers or CVC.
4. Purposes
Providing accounts, processing requests, saving projects, calculating usage, support and abuse prevention. Processing grounds and periods must be defined per purpose. Optional analytics must not load before a user choice.
5. Connected services
Generation requests, necessary context, instructions and selected attachments go to external API providers and the selected model. Music uses a separate music API. Beget supplies server infrastructure, private storage and mail. Yandex and VK participate when you choose social sign-in, and YooKassa processes payments. Public assets use a CDN; the personal library requires authorization. External processing depends on the model and may take place outside Russia. Do not upload third-party personal data without a valid basis.
6. Retention and deletion
Free: 15 days; Pro: 45 days; Ultra: 120 days; Enterprise: 190 days; Business: 300 days. Retention starts when a chat or file is created. Access ends at expiry and content is removed from active storage. Financial and mandatory accounting records are retained separately from conversation history. Primary-server backups are retained for up to 14 days and are not user-accessible. Deletions and retention expiry must be reapplied after recovery.
7. Choices and requests
You can end sessions, revoke API keys, delete gallery files, hide entries from your history and change cookie preferences. Closing an account disables sign-in, sessions, API keys and auto renewal; account data and requests remain available to administrators. History and files follow their stated retention periods. Send account access, correction or deletion requests through workspace support or to support@gptaid.ru. Email registration uses a separate data-processing consent checkbox. Yandex and VK buttons have a visible terms and consent notice; clicking a button confirms consent. Marketing emails are not enabled.
8. Protection and updates
Provider secrets remain on the server, passwords use strong hashes, and private material requires access checks. These are architecture requirements, not a completed security audit. The policy will be versioned and updated before new processing is launched.
Operator details
Individual entrepreneur Andrey Sergeevich Rudakov, INN 312832529605. Website: https://gptaid.ru. Support, complaints and personal data enquiries: support@gptaid.ru.