Privacy FAQ

Does ChatGPT store my data? A GDPR-compliant AI alternative, explained

The two questions UK and EU users ask most before they can sign off on an AI tool are simple: does the big-name chatbot keep my data, and is there a GDPR-compliant alternative? Here are plain-English answers, and how Alice handles each one.

Does ChatGPT store my data?

OpenAI's consumer plans retain chat history on its servers by default, keep prompts for 30 days (longer for flagged content), and may use your conversations to train its models unless you opt out. Because OpenAI is a US company, that stored data is also within reach of the US CLOUD Act. Alice takes the opposite approach: prompts are never written to disk, never used for training, and chat history is encrypted on your own device, not on our servers.

Is there a GDPR-compliant AI alternative to ChatGPT?

Yes. Alice is a GDPR-compliant AI chatbot hosted on hardware we own in Dorset, United Kingdom. It keeps no prompt logs, never trains on your conversations, stores chat history encrypted on your own device, and processes account data only for the service you asked for. The data controller is a named UK sole trader, so there is no US parent company that could be compelled under the CLOUD Act.

Is there a UK-hosted AI chatbot that does not send data to the US?

Alice runs entirely on our own hardware in Dorset, England. No US cloud provider, overseas inference API or third-party model vendor sits in the path between you and the model. The only sub-processors are Stripe for payments and our UK/EU-hosted database for sign-in, and neither ever receives the content of your conversations.

Where is my chat history stored with Alice?

Your chat history is encrypted with a passphrase only you know, using PBKDF2-SHA256 and AES-256-GCM, and stored in your own browser. It is never sent to our servers. If you clear your browser or delete your account, the history is gone. Because we do not hold it, we could not produce your conversations even if asked.

Does Alice use my conversations to train its models?

No. We do not train, fine-tune, evaluate or improve any model using your conversations. We never sell, share or licence them, and no human at Alice reads your chats. Prompts are held in memory only for as long as it takes to generate the reply, then discarded.

What GDPR rights do I have with Alice?

Under UK GDPR and EU GDPR you can ask for a copy of your account data, ask us to correct or delete it, object to how we use it, or complain to the Information Commissioner's Office. Email us from the address on your account and we will reply within one month. We hold only your email address, setup preferences and daily message counts — no conversation content.

Is Alice compliant with the EU AI Act?

Alice follows EU AI Act transparency principles: it states plainly that you are talking to an AI, warns that output can be wrong, names the model answering you, and keeps a human in the loop rather than making automated decisions about people. It is a general-purpose assistant, not a high-risk system used for hiring, credit or similar decisions.

Want the full technical detail?

Our Trust & compliance page sets out data residency, retention, security controls and your GDPR rights in full, and our Privacy page is the formal notice.

Home · Privacy · Terms