Askpert Privacy Policy
Version 2026-07-14. Effective July 14, 2026.
This policy explains what data Askpert collects, how it flows when you use experts, who processes it, and the choices you have. "Askpert," "we," and "us" mean the Askpert service and its operator, currently the founder doing business as Askpert, who is the data controller for the personal data described here. Contact: info@askpert.dev.
1. What we collect
- Account data. Your email address and a hashed form of your password (we store a one-way hash, never the password itself), plus profile details you choose to add.
- Content you submit. The inputs you send to experts and the outputs you receive, the experts, skills, and documents you create or upload as a creator, and reviews or ratings you post.
- Keys you store. LLM API keys you save for expert runs (see Section 4).
- Usage and technical data. Records of expert runs and API activity (timestamps, status, token counts), rate limiting counters, and standard server logs such as IP address and user agent. Our logging is designed to record events about runs without recording the private content of prompts.
We do not run third-party advertising or analytics trackers on the Service.
2. How an expert call works
When you send a request to an expert:
- Your input is received by our servers and processed by the expert's configuration, which was authored by its independent creator and executes on our infrastructure. The creator's sealed assets stay on the server; your input is processed against them.
- Your input (and relevant context) is sent to the underlying large language model provider chosen for that expert to generate the response.
- If the expert uses web search, your query text is sent to a search provider.
- If the expert runs code or processes files, that happens in an isolated sandbox environment, separate from your machine and designed to restrict network access.
- The output is returned to you, and the run is recorded (see Retention).
Creators do not receive your identity with a run. Do not include secrets or other data in a prompt that you would not want processed by the providers listed below.
3. Service providers and sub-processors
We use the following third-party providers to operate the Service: OpenAI, Google, OpenRouter, Exa, Parallel, Cloudflare, Supabase, Railway, and Vercel. Your data reaches a provider only as needed for the functions below.
Depending on what an expert uses, your data may reach these providers as follows. Expert inputs and context go to the large language model provider that generates the response. Search query text goes to a web search provider when an expert searches the web. Code and files processed by an expert's tools run on isolated execution infrastructure. Account data, stored content, and data in transit pass through our database, hosting, and delivery providers.
4. Your stored LLM API keys
If you save an LLM API key with Askpert (as a creator funding your experts, or as a buyer bringing your own key), the key is stored encrypted at rest and used solely to make provider calls on your behalf. Keys are never displayed back to you after saving; the Service shows only a short hint so you can recognize which key is which. You can delete a stored key at any time in your key settings. Deleting your account (Section 7) removes your stored keys.
5. Cookies
We use essential cookies only: a session cookie that keeps you signed in and a security cookie that protects forms against cross-site request forgery. We do not use advertising or tracking cookies.
6. How we use data
To provide and operate the Service; to secure it (authentication, rate limiting, abuse prevention); to run the automated inspection that experts pass before listing; to maintain usage records and enforce plan limits; and to comply with law. We do not sell your personal data, and we do not use your expert inputs or outputs for marketing or promotion.
7. Retention and deletion
We retain your account data, and the inputs and outputs processed through the Service, for as long as your account is active and as needed for legitimate business and legal purposes. We do not currently delete this data automatically, and run records are kept to operate usage accounting and support.
To request deletion of your account or specific data, contact info@askpert.dev. We will honor verified requests as required by applicable law. Stored LLM API keys can be deleted by you directly at any time (Section 4).
8. Security
Passwords are stored as one-way hashes. Stored keys are encrypted at rest. Sessions use HTTP-only cookies. Expert code executes in isolated sandboxes, and creators' sealed assets are designed to stay server-side. These are measures, not guarantees: no method of storage or transmission is completely secure. If a breach affects your personal data, we will notify you as required by applicable law.
9. Your rights
Depending on where you live, you may have rights to access, correct, delete, or receive a copy of your personal data, to object to or restrict certain processing, and to complain to a supervisory authority. To exercise any of these rights, contact info@askpert.dev. We will verify your request and respond as applicable law requires.
10. Children
The Service is not directed to children. We do not knowingly collect personal data from children under 13 (or under 16 in the European Economic Area or the United Kingdom). If you believe a child has provided us data, contact us and we will delete it.
11. International transfers
The Service is operated from the United States, and the providers in Section 3 may process data in the United States or other countries. Where required, we rely on appropriate legal mechanisms for such transfers. By using the Service you understand your data will be processed as this policy describes.
12. Changes to this policy
We may update this policy from time to time. Each version is identified by the version date at the top. Material changes will be flagged in the product. Continued use after a change takes effect means the updated policy applies.
13. Contact
Privacy questions and requests: info@askpert.dev.