Your conversations and data
Myllash AI stores conversations to provide your responses, context and history. They are private product data—not a public knowledge base.
History and deletion
Anonymous sessions and their conversations expire after 24 hours and are removed by retention maintenance. Signed-in history remains until you delete a conversation or your Myllash account. Conversation deletion also removes associated retry references, execution briefs and response feedback. Separate metadata-only security and operational records have bounded retention. Deletion is not a promise to immediately erase provider logs or existing infrastructure backups.
AI and search providers
Signed-in users can attach plain-text documents and images. Files are stored privately in Cloudinary with ownership metadata in Appwrite. Attached document text is sent to the model with your question; images are stored only and are not analyzed yet. Unsent uploads expire after 24 hours through retention maintenance. Chat and account deletion also remove associated stored files. Do not upload sensitive information.
Your message, limited recent conversation context, public curated knowledge and relevant retrieved evidence are sent through OpenRouter to the configured model provider to produce a response. Account/session identifiers and Myllash credentials are not sent to the model. We request routes that deny provider data collection; availability and provider retention depend on the endpoint and applicable terms. Do not enter passwords, confidential business records or unnecessary sensitive personal information.
When current information is needed and search is configured, a bounded version of your latest question is sent to Tavily. Tavily may use third-party search indexes. Retrieved public excerpts may be sent to the model. Search receives no Accounts identity or private Go context, but a question can itself contain personal information.
Analytics and response feedback
We use operational metadata such as model, token counts, estimated cost, latency, errors and broad topic categories to understand reliability and usage. Helpful/not-helpful feedback records a vote and hashed references, not your transcript. Feedback does not grant permission for training or public knowledge reuse.
Staff access and reuse
Administration is metadata-first. There is no general staff conversation browser. This implementation does not offer staff transcript access; a specific permissioned, reasoned and audited support/security process would need separate approval before such access is enabled. Your raw chats are not automatically placed into public retrieval, other users’ context, training or evaluation datasets. Optional conversation contribution and training reuse are disabled.
Myllash Go
Go receives context only when you explicitly review and confirm an execution brief. That is not unrestricted transcript transfer and does not automatically create a project, business or wallet. Shared Accounts identity does not grant public AI access to your private Go records.
These describe current implemented data flows. Public release also requires the owner to verify provider settings, operational maintenance and final privacy/support notices.