Privacy Policy
Plain privacy terms.
Azure AI collects the minimum data needed to run authenticated AI chat, coding tools, and APIs — and nothing for advertising or resale.
Last updated: September 16, 2026.
1. Operator
Azure AI (“the service”) is operated by [OPERATOR LEGAL NAME — PLACEHOLDER]. The legal operator name is still to be confirmed; it is shown as a placeholder until then.
The fastest contact route is the Azure Discord community. Privacy requests sent there should include the account email address so the request can be matched to the correct account.
2. Data collected
Account data: email address, plan tier, plan expiry, account creation date, and a PBKDF2-SHA256 password hash. Passwords are never stored in readable form.
Email verification: a hashed six-digit code, its expiry, and the number of verification attempts. Codes expire after 10 minutes.
Sessions: a random 32-byte session token is stored as a hash on the server and as an HTTP-only session cookie in the browser. See the Cookie Policy.
Connected providers (optional): when Discord, GitHub, or Google sign-in is linked, the provider username, account email, and encrypted OAuth tokens are stored, plus a short security audit log (connect, refresh, disconnect events).
Chat and workspace content: browser chat history, project files, and project memory are stored so conversations and projects survive reloads. Chat history lives in first-party browser storage on the device; project data is stored server-side per account.
Usage records: weighted token counters in rolling five-hour and weekly windows, recent request entries (model, HTTP status, latency, timestamp), and aggregate usage analytics. Analytics never include prompt text, account emails, API keys, or provider credentials.
Abuse prevention: signup, login, and verification attempts are rate-limited. Anonymous chat limits are keyed by an opaque identifier; raw IP addresses are not stored. Cloudflare Turnstile evaluates a security challenge on signup, login, and code-resend requests.
User-configured integrations (optional): outbound webhook endpoints and event selections for Slack, Discord, GitLab, or Bitbucket. Endpoint credentials stay encrypted and are never shown again.
3. Where submitted data goes
Account, session, usage, and project data is stored in the service database (Cloudflare D1) and processed by the service backend (Cloudflare Workers).
Verification emails are delivered through the Cloudflare email pipeline to the address provided at signup.
Prompts and attachments are forwarded to the model serving this chat to generate a response.
Turnstile challenges are verified by Cloudflare and are subject to the Cloudflare privacy policy.
Data is never sold, never shared with advertisers, and never used for marketing. No marketing emails exist and no marketing consent is requested.
4. Retention
Sessions expire after 30 days of issuance and are deleted from the database. Signing out deletes the session immediately.
Verification codes expire after 10 minutes; failed-attempt counters are cleared on success. Throttle records older than 7 days are cleaned up automatically.
Usage counters reset on rolling account-anchored windows. Promotional token balances do not expire while the account exists.
Deleting the account from the dashboard permanently removes chats, API keys, sessions, usage data, and connected-provider credentials. Provider grants are revoked where the provider supports it.
5. Account rights
Account holders can view usage, plan state, request history, notifications, and connected providers at any time on the dashboard.
Correction happens in place: reconnect a provider, renew an API key, or update integrations from the dashboard. Export and erasure requests can be made through the Discord community; erasure is also self-serve through permanent account deletion.
6. Security
Passwords use PBKDF2-SHA256 with 100,000 iterations, a per-account salt, and a 12-character minimum. Sessions are random 256-bit tokens, HTTP-only, SameSite=Lax, and Secure over HTTPS. Mutating API requests require same-origin fetch metadata, and uploads are restricted to an allowlist of document, image, and text types with size caps and executable screening.
7. Changes to this policy
Material changes are announced on the changelog. Continued use of the service after the posted update date constitutes acceptance of the revised policy.