- You need an account to use the workspace. We hold your email address and set one cookie to keep you signed in. That cookie is the only one on this site: no analytics, no advertising pixels, no session recording.
- We store your conversations on your account, so they follow you between browsers and devices. You can download all of them or delete all of them from your account page at any time; deleting is immediate and permanent on our side. We also keep a billing record of each request, the model, the token counts and the cost, because that is what you are charged for.
- A collab is shared on purpose. When you join one, everyone in that room sees every message in it, who sent it, which model answered, what each answer cost, and who put credits into the room’s balance. The transcript belongs to the room and stays readable to its members after you leave. The creator can close the room and then clear the pictures and clips made in it; the written messages stay.
- askr Community is public. Every line and picture posted in the room can be read by anyone, without an account, and is kept. Your @ is on every line. A line you delete leaves the room at once, with askr’s answer to it and any picture on it, but it is not erased: we keep it marked deleted, with the record of who deleted it. Mods can remove lines too. What reaches a model is the line that asked and the line it replied to, nothing else from the room.
- We do keep what you make. The images, video clips and audio you generate are stored on your account with the prompt that made them, so they survive a reload and follow you between devices. You can delete any of them from your library; deleting is immediate and permanent on our side.
- Anything you type into the workspace or send to the API leaves our servers. It goes to the model gateway we use, and onward to the company that runs the model you picked. If you pick a version labelled “by” a supplier, or “(direct)”, it goes to that supplier instead.
- Adding credit with crypto goes through a payment processor. It issues the address and sees the payment. It does not learn who you are. Blockchain payments are public and permanent, and no one can edit that record afterwards, including us.
- Paying by card goes through Stripe, and the purchase is sold through Link, Stripe’s merchant of record. Stripe and Link take your card details, which we never see, your email address, your name and your billing address, and use them as their own controller for the payment and for tax. Your receipt comes from Link, and your card statement reads LINK.COM* HEYASKR.AI. We keep the purchase record, with the IP address it came from and your acceptance of the terms, for disputes and tax.
- The home page, the pricing page and the calculator open a live price connection from your browser straight to Binance. That reveals your IP address to Binance.
Who is responsible
heyaskr.ai is operated by the team behind HeyAskr, who decide how the data described below is handled and are the controller of it for UK and EU purposes. Write to ask@heyaskr.ai about anything on this page.
Your account, your credit balance, your usage records and your library sit in a database on a server we run in the United Kingdom. They are not copied to another country. The exceptions are named below, and the important one is the workspace itself: the text of your messages and prompts goes abroad every time you press send.
Your account and how signing in works
An account is an email address. There is no password, no username and no profile. You type your address, we email you a six digit code, and you type it back.
- We store your email address, the date you signed up and your credit balance.
- If you create API keys, we store the name you gave each one, when it was made, when it was last used, any daily cap you set, and a hash of the key itself. Never the key. The same rule as your sign in code.
- We never store the sign in code itself, only a SHA-256 hash of it. The same is true of the session token behind your cookie. Someone holding a copy of our database still could not sign in as you.
- A sign in code lasts 10 minutes, allows 5 wrong guesses, and is single use. We record the IP address that asked for it, so that one address cannot mail bomb someone else’s inbox.
- Being signed in sets one cookie on heyaskr.ai. It holds a random token and nothing about you: no email address, no balance, no identifiers. It expires after 30 days.
That cookie is strictly necessary, in the sense the UK and EU cookie rules use: without it you would be signed out on every page. That is why there is no cookie banner. Our analytics sets no cookie and builds no profile, so it needs none either. We run nothing else that would need one, and if we ever do, it will ask you first rather than appear quietly.
What happens when you use the workspace or the API
When you press send in the chat, your browser posts the conversation so far to our server. Our server checks you are signed in and can afford the request, takes the most recent 20 messages, drops any single message longer than 16,000 characters and any transcript over 32,000, then forwards the rest unchanged to the model gateway we use. The gateway then passes your text to the company that operates the model you selected. A request through the API with one of your keys follows the same path with a longer window: the last 40 messages, up to 120,000 characters.
An image, video or audio prompt travels the same way. The prompt, and for a reading the text and the name of the voice you picked, goes to the gateway and on to the provider behind the model, and the picture, the clip or the audio comes back to us.
So the text you type reaches at least two other organisations: the model gateway, and the model provider behind that model. We say so here because we have no way to run the workspace without them, and you should know before you type.
A version labelled “by” a supplier, or “(direct)”, such as “Claude Opus 5 (direct)”, goes to that supplier instead. What it receives and what it keeps are set out under who else receives your data, below.
- We forward the messages, the model name, for video the aspect ratio and length you chose, and for audio the voice and the length. Nothing else. In a collab, where several people share one conversation, each message is forwarded with the @ of whoever wrote it so the model can tell the room apart.
- We do not attach your email address, your account, your IP address or your browser details to the request. It goes out under our API key, not yours, so the gateway and the model provider see our account rather than you.
- We do not use anything you type or make to train models. We cannot make that promise for the gateway or the model providers, so read their terms if it matters to you.
When Search the web is on, the search terms the model chooses are sent to Brave Search; page fetches are made by askr’s server, never from your browser. Neither carries your account.
Practical advice: treat the prompt box as something you are publishing. Do not paste credentials, secrets, personal data about other people, regulated records or anything under an NDA.
Conversations are stored on your account
Since 16 September 2026 your chat messages and the replies are kept on your account, so a conversation started on one device is there on the next. Your browser keeps a copy too, keyed to your account so that two people sharing one browser never see each other’s work. Before that date conversations lived only in the browser, and we hold nothing from then.
Collabs are different, and shared on purpose. A collab is a room where several people prompt one model together and pay for it from one collab balance. It is private unless its creator makes it public: private, only the people invited by @ can see it; public, anyone with the link can read it, watch it live and play what was made in it, with no account, and anyone with an account can join it. Everything in the room is visible to everyone in it: each message and who wrote it, each answer and what it cost, every picture and clip made there and who asked for it, and who added credits. Pictures and clips made in a room are stored on the room, not in your personal library. Messages you send there are stored on the room, not on your account, and they stay with the room for the other members after you leave. The room’s creator can close it, and once it is closed can clear the pictures and clips made in it, along with the prompts that asked for them; the written messages remain with the room. A room itself is not deleted, and nothing in a collab is removed by deleting your own chats. Your @ is shown to the other members. Do not put anything in a collab you would not say to everyone in it.
They are yours. On your account page you can download every conversation as a file, or delete every one of them; deletion is immediate and permanent on our side. We keep at most 300 conversations per account and drop the oldest beyond that. We do not read them, train on them, or use them for anything except showing them back to you. Copies that reached the gateway and the model provider are governed by their retention rules, not ours.
askr Community is public
askr Community, at heyaskr.ai/community, is one public room. Unlike a collab it has no members: anyone can open it and read every topic, every line and every picture, live, without an account, and it is built to be read on a phone. We ask search engines not to index it, but it is public, and anything you post there can be read, quoted or copied by anyone. Do not put anything in it you would not say in public under your @.
- With every line you post we show your @, your avatar if you set one, the time and the topic, and we keep the line. If you are one of askr’s admins or mods, that role is shown too. Reactions are public; who reacted is shown to signed-in viewers only. While you type, everyone watching can see that you are typing, with your @.
- Speaking needs a wallet linked to your account. The room never shows your wallet address, what it holds, your email address or your account id, to anyone: no route in the room returns them. What the room uses is whether a wallet is linked and when, and, only if the team switches a minimum holding on, whether the wallet holds it.
- A line that asks askr goes to the model gateway like any chat: the text of that line and, if it replied to one, the line it replied to, each with the writer’s @ in front, plus askr’s standing instructions for the room. Nothing else from the room goes. The room pays, and we keep a usage record of each run against the room that notes which account asked, as we do for any request.
- Deleting a line, your own or a mod deleting anyone’s, takes it out of the room at once for everyone, together with askr’s answer to it, and its pictures and clips stop being served. It is not erased: the line stays in our database marked deleted, and the moderation record keeps a short excerpt of it, who deleted it and why. A ban can delete a person’s lines from the last 24 hours the same way.
- Moderation is recorded. Mutes, bans, pins, slow mode changes and reports are written to an audit trail with who did what, kept, and readable by askr’s admins. When you report a line we store your account as the reporter, with the reason and any note; the mods see the report and its count, the room never does.
- Pictures and clips made in the room, and pictures attached to lines, are public while the line stands. They are stored on the room, not in your library.
Two topics are fed by askr’s own server, and one part of the page is private.
- X posts. When someone shares a link to a post on X, our server fetches that post from X once, under our own identity, and stores what the card needs: the author’s name and @, the text, whether it has a picture or video, its time, and two pictures, the author’s avatar and the post’s first picture (none when X marks the post sensitive). Your browser gets all of it from our address and loads nothing from X unless you open the link, so X does not see you read the room. A card viewed a day or more after its last check is checked again, and a post deleted, protected or withheld on X has its stored text and pictures removed within a day of the next view. Pictures of posts nobody has shared for 90 days are removed.
- Buys. The buy feed is read from the public blockchain by our server and posts each ASKR buy over a set value with a shortened buyer address and a link to the transaction on the public explorer. That is public chain data, written by whoever made the buy. We never join it to any account, @ or linked wallet, and we never show a whole address in the room. If you say in the room that a buy was yours, you have connected your @ to that wallet yourself, in public. The dollar value comes from a price our server reads from DexScreener; nothing about you is sent to get it.
- The private chat beside the room is an ordinary chat on your account: only you see it, it is saved to your History like any conversation, it is paid from your balance, and its text goes to the model gateway as described above.
The live feed of the room is a long connection from your browser to our server. We count open connections per address and per account in the memory of the server process, to cap them, in the same way as the rate limits below; nothing is written down.
What you make is stored
Images and video clips are different from chat text, and we treat them differently on purpose. A picture that vanished on reload was a receipt pointing at nothing, so now we keep it.
- For each image you generate we store the image itself, the prompt you wrote, the model, the credits charged and the time.
- For each video we store the clip once it has finished rendering, the prompt, the model, the aspect ratio and length you chose, the credits charged and the time. Until we have copied the clip, and for up to 24 hours regardless, it also exists at a temporary address on the gateway.
- Your library shows all of it, on any device you sign in from. It is yours to see and nobody else’s. We do not publish it, browse it or use it for anything other than showing it back to you.
- It is kept while your account exists. Delete any item from your library and it is gone from our side at once, prompt included; the billing record of what it cost stays, as described below. Ask and we delete all of it; closing your account deletes it all.
What we record when you spend credit
We keep a record that a request happened, because you are being charged for it and a bill you cannot check is not a bill you should trust. For each request we store the model you used, how many input and output tokens it involved, what it cost us upstream, how many credits you were charged, the time, and a reference id from the gateway.
The billing record itself holds no text. Token counts are lengths, not words: they say a message was 37 tokens long, not what it said. The text lives in your conversation history, described above, which you control; for images and video the prompt is kept with the thing it made.
Where a request came through the API rather than the workspace, the record also notes which of your keys made it. That is what lets you see what a particular key has spent, and what makes a daily cap possible.
Your credit balance is kept as a ledger, an append-only list of every deposit, every hold and every charge. Entries are never edited or deleted, including by us. A correction is made by adding a further entry that reverses the first, so the history stays readable rather than being quietly rewritten. This matters for your rights, and it is covered again below.
Adding credit
Credit is bought with cryptocurrency through a payment processor, or by card through Stripe, which the next section covers. When you ask to add credit with crypto we ask the crypto processor for an address for that one payment, and show it to you. We tell them the dollar amount, the asset you chose, a deposit reference of ours and the words “askr credits”. Nothing else: not your email address, not your account, not who you are.
That matters for how little they learn. The processor can see that an invoice was paid and from which on-chain address. They cannot see whose account it belongs to, because the record connecting that invoice to you is ours and stays here. We are the only party holding both halves.
- We store the asset, the address issued, the amount requested, the amount that arrived, the status, the processor’s payment reference and when the address expires. We link it to your account, because that is how your credit reaches you and no one else.
- Your payment lands in our balance with the processor. From there we pay the model gateway for the usage your credit will buy. The gateway receives our payment, not yours, and learns nothing about you from it.
- We never see or hold a card number or a bank detail. There are none in the crypto flow.
- We never hold your wallet, your keys or your seed phrase, and we will never ask for them.
- The processor is its own controller for what it does with the payment. Their privacy policy governs it, not this page.
Be aware of what a blockchain is before you send. The payment, the amount, the address it came from and the address it went to are written to a public ledger that anyone can read and no one can erase, including us and including you. If your wallet address is already publicly connected to your name somewhere else, that connection follows the payment. This is a property of paying in crypto, not something we chose or can switch off.
Paying by card
Card payments are processed by Stripe, and each purchase is sold through Link, Stripe’s checkout and customer brand, as the merchant of record: Link sells it on our behalf and takes the payment. When you pay by card we open a Stripe checkout for that one purchase and send you to Stripe’s payment page. Unlike the crypto processor, Stripe and Link learn who is paying.
- Stripe and Link receive your card details. You type them into Stripe’s page, not ours, and askr never sees or stores them.
- Stripe and Link also receive your email address, the one on your askr account when it has one, your name and your billing address. As merchant of record they use them as their own controller, for the payment and for tax.
- Your receipt comes from Link, and the charge shows on your card statement as LINK.COM* HEYASKR.AI. We also send a confirmation of your purchase to the email address you gave Stripe.
- We tell Stripe the dollar amount, the credits it buys, a purchase reference of ours and your account id, so the payment can be matched to your account. Nothing about what you do on askr goes with it.
- We keep a record of each card purchase: the amount, the tax included in it, the credits it bought, Stripe’s references for the payment, its status, and any refund or dispute on it. With it we keep the IP address the checkout was started from and whether you accepted the terms at checkout. We keep them to answer a dispute and for tax. Your card details, name and billing address stay with Stripe and Link.
- If a card payment is disputed, we prepare evidence for Stripe to contest it: the purchase, the IP address, that you accepted the terms, your email address, your @ and when the account was made, and the usage record of the requests the account made after the purchase, meaning the time, the door (workspace or API), the model and the credits of each, never the text. Stripe passes it to the card issuer.
- Stripe and Link are their own controller for what they do with your payment details, including tax, fraud checks, receipts and refunds. Their own privacy policies govern that, not this page.
Rate limiting, security and IP addresses
To stop one visitor exhausting the gateway, our server counts requests per IP address: 120 a minute across the site and the API, 20 a minute for the chat, 10 a minute for starting a video or a deposit. Those counters live in the memory of the server process, are never written to disk, and are lost whenever the server restarts or is redeployed. We do not use them to profile anyone.
The one place an IP address is written down is a sign in request, as described above, so that the code sending emails cannot be pointed at a stranger’s inbox. Ordinary browsing and ordinary requests do not record one on our side beyond the server logs below.
Live prices connect your browser to Binance
Three pages show live cryptocurrency prices: the home page, /pricing and /calculator. On those pages your browser opens a WebSocket directly to data-stream.binance.vision, a public Binance market data endpoint. That connection comes from your device, so Binance can see your IP address, your approximate location from it and the fact that a browser connected. It is a read only price feed: we send nothing about you over it and we receive nothing about you back.
Those same pages also call our own price endpoint once a minute as a fallback. That call is made from our server to Binance, with CoinGecko as a backup, so neither of them sees you on that path. The network fee figures come from public blockchain endpoints called from our server for the same reason.
If you would rather not connect to Binance, the rest of the site does not open that socket. The workspace, your wallet, your library, the model catalog, the docs and these legal pages do not.
Hosting and server logs
The site and its database run on a virtual server we rent from OVH, in the United Kingdom. OVH provide the machine and the network; they do not use anything on it for their own purposes.
Like any web server, ours records standard request data as it runs: IP address, user agent, the URL requested, the time and the response status. We use it to keep the site up and to debug errors, we do not build profiles from it, and we do not combine it with your account. Logs rotate and are discarded as they age.
Web fonts are served from our own domain rather than a font CDN, so loading a page does not call out to Google.
Dictation uses your browser's speech service
The microphone button in the workspace uses the speech recognition built into your browser. The audio goes from your browser to that browser’s speech service, which is Google for Chrome and Edge and Apple for Safari, and the text comes back to the page. Our server never receives the audio; it receives the text only when you send the message, like anything you type. Firefox has no speech service, so the button does not appear there. Nothing listens until you press the button, and pressing it again stops it.
Sign in codes are sent through our mailbox provider, which handles the delivery of that message. The address we send to is the one you signed up with.
If you write to ask@heyaskr.ai we receive your address, your message and anything you attach. It sits in that same mailbox. We keep it while we deal with your request and for a reasonable period afterwards so we have a record of what we told you, then delete it.
We do not run a newsletter and we do not send marketing. If that changes, it will be something you opt into, not something you are enrolled in by signing up.
Feedback
If you send the form at heyaskr.ai/feedback, what you write, the Telegram username you leave and, when you are signed in, your @ or email address, when your account was made, how many requests it has run and how much it has topped up go to our team’s group on Telegram as a message, so we can read it and reply. We keep no other copy. Telegram holds that message under its own terms. Ask us and we will delete it.
Who else receives your data
The complete list, and what each one gets. There is no one else.
- The model gateway: the text of your chat messages and your image and video prompts, with the model name and no identifier attached. They also receive our payments for usage, which carry nothing that names you.
- The model provider behind the model you chose, via the gateway: the same text.
- The supplier named on a version you pick, and only when you pick it: what that version needs to run, set out below.
- Brave Search, only when Search the web is on: the search terms the model chooses, under our key. Nothing that names you.
- X, only for a post someone shares in askr Community: our server asks X for that post, under our own identity. Nothing that names you, and nothing from your browser.
- The crypto payment processor: the dollar amount, the asset, our deposit reference, and the on-chain payment you make to the address they issued. Nothing that names you.
- Stripe and Link, only when you pay by card: Stripe processes card payments, and Link, Stripe’s checkout and customer brand, is the merchant of record that sells the purchase. They receive your card details, which askr never sees, your email address, your name and your billing address, and use them as their own controller for the payment and for tax, with the amount, our purchase reference and your account id. If a payment is disputed, they also receive the evidence we prepare to contest it, described above.
- Our mailbox provider: your email address and the messages we send you.
- Telegram, only when you send the feedback form: what you wrote there, as a message to our team’s group, with the details the Feedback section above lists.
- OVH, our hosting provider: they run the machine everything else sits on.
- Ahrefs Web Analytics: which pages are visited and which site sent you, in the aggregate. No cookie, no identifier, nothing that names you, and nothing from inside the workspace: it counts page views, not what you type or what you make.
Some models come in more than one version. A version labelled “by” a supplier, or “(direct)”, such as “Claude Opus 5 (direct)”, runs at that supplier. When you pick one, in the workspace, a collab or the API, we send that supplier what the model needs: your prompt, any picture you attach, the earlier messages and replies of a chat, and for video the aspect ratio and length you chose. The supplier makes the reply or the clip, so it has that too. It goes out under our account, not yours.
Of the suppliers, only the one named on the version you picked receives it. Nothing goes to a supplier unless you pick its version; in a collab, the version the room uses decides. Where a supplier passes your request on, its line below says so. The receipt names the supplier that ran your request. If a supplier fails before it starts, we may run the request once on the version with no supplier named, which travels as described above. A version marked ZERO RETENTION is never moved that way.
What a supplier keeps is set by its own terms, and it may process your request outside the UK and the EEA. A version marked ZERO RETENTION in the model picker comes from a supplier whose terms say it keeps neither the prompt nor the reply. A version without the mark makes no such promise. The suppliers, what each runs and what each keeps:
- Anthropic (chat). Anthropic’s own API, for the Claude versions marked (direct). With each request it also gets a fixed code made from your account id, so it can tell one person’s requests apart; never the id itself or your email. It keeps requests for 30 days under its commercial terms and does not train on them.
- fal (video and audio). It makes no zero-retention promise: fal keeps the request, with your prompt and any start frame, for 30 days, and the clip for at least 7. For audio it gets the text you have read, or the description of the song or sound, and the name of the voice you picked, under the same terms. For Seedance it also gets a fixed code made from your account id; never the id itself or your email.
We do not sell personal data, and we do not share it for anyone else to market to you. If we are ever legally compelled to hand something over, we will tell you unless we are prohibited from doing so.
What we do not collect
Some of this may change as the product grows. It is true on the date at the top of this page.
- No passwords. Sign in is a mailed code, so there is no password of yours for us to leak.
- No card numbers or bank details. When you pay by card, your card details, name and billing address go to Stripe and Link, not to us.
- No custody of your wallet, keys or seed phrase.
- No chat text, on either side of the conversation.
- No analytics, no advertising or social pixels, no session recording, no device fingerprinting, and no cookie other than the one that keeps you signed in.
- No uploaded files. The workspace takes text in; it does not yet accept files or reference images.
- No name, date of birth, address or identity documents. We do not ask who you are, only where to email you.
How long anything is kept
- Chat messages on our side: not stored. They exist in your browser until you clear it.
- Copies received by the gateway and the model provider: kept under their retention rules, which we do not control.
- Images and clips you generate, with their prompts: while the account exists, or until you delete them.
- Lines, pictures and clips in askr Community: kept, in public, while the room exists. A deleted line leaves the room and its pictures stop being served; the line stays marked deleted, with the moderation record.
- Cards of posts on X shared in askr Community: checked again a day after the last check and cleared when the post is gone from X; their pictures are removed after 90 days without a share.
- Your account and email address: while the account exists, then deleted when you ask us to close it.
- Sign in codes: 10 minutes, then expired and cleared.
- Your session: 30 days, or until you sign out.
- Billing records, the ledger and usage records: kept as long as the law requires financial records to be kept, which outlives the account itself. See the limit under your rights below.
- Deposits: alongside the billing records, for the same reason.
- Card purchases, with the IP address and terms acceptance kept with them: alongside the billing records, for disputes and tax.
- Rate limit counters: seconds, in memory only. Lost entirely on restart.
- Server request logs: rotated and discarded as they age.
- Email: while we handle your request and a reasonable period after, then deleted.
- Feedback form answers: not kept on our servers. The message in our team’s Telegram group stays until we delete it, or until you ask us to.
Legal bases and where data goes
If you are in the UK or EU, these are the bases we rely on.
- Running your account, taking your deposit or card payment, metering what you spend and keeping your library is performance of a contract with you. Without it there is no service to give you.
- Sending your prompt to the gateway is part of that same contract: it is the thing you asked for when you pressed send.
- Rate limiting, security and error logs rest on our legitimate interest in keeping the service available and affordable, which we consider proportionate given how little data is involved and how briefly it exists.
- Keeping billing records after you leave is a legal obligation, not a choice of ours. That includes card purchase records kept for tax.
- Keeping the IP address and terms acceptance with a card purchase, and preparing evidence for Stripe to contest a dispute, rest on our legitimate interest in defending payments for credit we supplied and in stopping card fraud.
- Answering your email rests on our legitimate interest in replying to you.
We do not rely on consent for any of it, because the only cookie we set is the one that keeps you signed in and we run no tracking that would need permission.
Your account data and your library stay in the United Kingdom. Two things leave it. The gateway and the model providers operate outside the UK and the EEA, including in the United States, so sending a prompt means your text is processed there. The crypto payment processor also operates outside the UK, and sees the payment details described above. Stripe and Link may process card payment data outside the UK, including in the United States, under the safeguards their own privacy policies describe. We have not yet put standard contractual clauses in place for those transfers. Until we publish that we have, treat the workspace as a service that sends your text abroad, and do not put personal data into it.
Your rights and how to use them
You can ask us for a copy of what we hold about you, ask us to correct or delete it, ask us to restrict or stop a particular use, and object to processing we base on legitimate interests. Email ask@heyaskr.ai with Data request in the subject line, from the address on the account. We reply within 30 days and we do not charge for it.
A request about your account will come back with something in it: your email address, your balance, your deposits and card purchases, your usage records, and the images and clips in your library with their prompts. A request about chat use will come back close to empty, because we never held the conversations.
Three honest limits.
- We can close your account, delete your email address and delete your library. We cannot delete the ledger and billing records behind it. They are financial records the law requires us to keep, and the ledger is deliberately built so that no one can edit or remove an entry, which is the same property that lets you trust your balance. What is left after closure is a row of amounts and dates that is no longer attached to your name.
- Credit is spend only and is never refundable, so closing an account with credit left on it gives up that credit. Spend it before you ask us to close the account.
- Once a prompt has reached the gateway or a model provider, they hold that copy. We will pass your request on, but their policy governs what happens to it. The same is true of a payment already written to a blockchain, which no one can erase.
We may ask for enough detail to find what you are referring to. We will not ask for identity documents we do not need. If you are unhappy with our answer you can complain to the data protection authority where you live or work.
Changes to this notice
When how we handle data changes, this page changes and the date at the top moves with it. If the change is material, for example a new recipient of your prompts or the start of stored chat history, we will say plainly on this page what changed.
What changed on 25 September 2026: the feedback form at heyaskr.ai/feedback was added, and Telegram joined the list of who receives data, for what you send through it.
What changed on 24 September 2026: card payments were added, and Stripe and Link joined the list of who receives data: Stripe as the payment processor for card payments, and Link as the merchant of record that sells each purchase and uses your payment details as its own controller. This notice says what they receive when you pay by card, where your receipt comes from, what we keep of a card purchase and why, and what we give Stripe if a payment is disputed.
What changed on 25 September 2026: Anthropic and fal joined the list of who receives data, for the versions labelled with their names.
What changed on 23 September 2026, with askr Community: a public room was added, and this notice says what is public in it, what a deletion does, what a line that asks askr sends to the model gateway, and how the X posts and Buys topics are fed. X joined the list of who receives data, for the one request our server makes for a shared post.
What changed on 23 September 2026: Search the web was added to the workspace and the API, and Brave Search joined the list of who receives data, with the one line above about what it receives.
What changed on 15 September 2026: the images and clips you generate are now stored on your account with their prompts, and this notice says so and says how to delete them; the payment processor was added to the list of who receives data; the API and video were added to the description of what leaves your browser and how requests are limited.
Contact
Privacy questions, data requests and corrections all go to ask@heyaskr.ai. If something on this page does not match what the product actually does, tell us and we will fix the page.