BYOKchat
Privacy Policy
Last updated: September 11, 2026
BYOKchat is a bring-your-own-key AI client available on the web, iOS, and macOS. It is designed around local-first storage: conversations, workspace data, provider configuration, and other app data stay in the app or browser environment you are using instead of being synchronized to a BYOKchat cloud workspace. AI requests are sent to the providers, endpoints, or tools you choose. BYOKchat and byok.pro also use the minimal first-party analytics described below.
API keys and credentials
On iOS and macOS, provider API keys, secret headers, and MCP credentials are stored using Apple Keychain. In the web app, credentials are stored locally in your browser environment rather than in a BYOKchat account or cloud synchronization service.
Credentials are kept separate from ordinary workspace data and are not intentionally included in conversation, workspace, backup, or configuration exports.
AI requests and third-party providers
When you send a message or use a provider-backed feature, BYOKchat sends the content required for that request directly to the provider or endpoint configured for the conversation. This can include message content, attachments, project context, and tool-related data when those features are used. The provider you choose processes that data under its own terms and privacy policy.
BYOKchat does not control how third-party AI providers, custom endpoints, local servers, or MCP services handle data after it reaches them. Review the policies of services you connect.
Conversations, Projects, Library, and files
BYOKchat stores conversation history and workspace data locally in the current app installation or browser environment. This can include chat messages, attachments, Projects, reusable instructions, saved Library files, prompt presets, provider and model defaults, tool configuration, and other non-secret settings.
BYOKchat does not operate a cloud service that stores or synchronizes this workspace data between your devices. Workspace content leaves the local environment when you explicitly use a feature that requires sending it to a configured provider, endpoint, or tool service, or when you create and share an export yourself.
Local usage data and diagnostics
BYOKchat can keep local usage accounting and diagnostic data so the product can show information such as token usage, estimated cost, performance, and reliability and help diagnose failures. This information stays local unless a feature explicitly states otherwise.
Local diagnostic data is designed to exclude prompts, responses, reasoning content, credentials, tool arguments and results, attachment contents, URLs, and hostnames by default. It is not used as a synchronized backup database.
Minimal first-party analytics
BYOKchat and byok.pro use a small first-party analytics service to understand basic product usage and reliability. Analytics are limited to non-content product events and the minimal technical context needed to interpret those events.
First-party analytics do not include conversation content, prompts, responses, reasoning content, API keys, secret headers, credentials, attachment or Library file contents, MCP tool arguments or results, or the content sent to AI providers.
We do not use this analytics data for advertising, cross-site tracking, or advertising profiles, and we do not sell personal data.
Backups and exports
When a BYOKchat platform offers backup or export features, exported data can contain conversations, attachments, structured tool rounds, Projects, saved Library data, preferences, non-secret provider configuration, MCP configuration, discovery state, and per-chat MCP policies. Provider credentials, MCP credentials, API keys, and secret headers are excluded from exports.
Exported files are under your control after you create them. Store and share them carefully, because they can contain conversation and workspace content even though secrets are excluded.
Purchases
Optional BYOK Pro purchases offered through the iOS and macOS apps are processed by Apple through the App Store. Apple handles payment, subscription, purchase-history, and related account information under Apple's own terms and privacy practices.
Advertising and sale of personal data
BYOKchat does not use advertising tracking and does not sell your personal data.
Deletion
BYOKchat includes controls for deleting locally stored conversation data and credentials. You can also remove locally stored web-app data through the browser environment you use. Deleting local BYOKchat data does not delete information already sent to a third-party provider, endpoint, or tool service; those services are governed by their own retention and deletion policies.
Changes to this policy
This policy may change as BYOKchat evolves. Material updates will be reflected on this page with a revised last-updated date.