Toothed AI

Privacy Policy

Last updated: October 8, 2026 · Version 1.2

1. Who we are and what this policy covers

This Privacy Policy explains what information the Toothed AI website (the “Site”) and the Levy 1 chat service (the “Service”) collect, why we collect it, how it is used, how long it is kept, and what rights you have. Toothed AI (“Toothed AI”, “we”, “us”) operates the Site and the Service; where applicable data protection law uses that term, Toothed AI is the data controller in respect of the personal data processed through them.

The short version: we keep very little. There is no advertising, no analytics and no tracking; your chat conversations are processed in memory and are not stored. What we do keep is your account — a username, an email address and a password stored only as a cryptographic hash — and an active login session when you are signed in.

2. Information we collect

Chat messages

When you send a message to Levy 1, the text of your message — and anything you include in it, which may be personal data — is transmitted to our server so the model can generate a response. Your messages and the model’s replies are processed in memory for the duration of the conversation in your browser tab and are not written to storage; closing the tab discards them.

Account and login data

To chat, you register a username, an email address and a password. The email address is used once, to send the verification code that confirms the address before we issue a session. We store the password only as a salted PBKDF2-HMAC-SHA256 hash, never in plain text. When you sign in, a session token is stored on the server (again, only as a hash) and in a cookie in your browser.

Server logs

Like any web server, ours keeps basic operational logs: requested URLs and paths, HTTP status codes, timestamps and, in some configurations, IP addresses and user-agent strings. We use them to keep the service running, diagnose problems and detect abuse.

Local storage

Your browser stores a small value recording your choice in the cookie notice, and the chat page stores the reasoning level you choose for Levy 1 (Off / Standard / Deep). Both are explained in “Cookies and local storage” below.

We do not collect your postal address, telephone number or payment information, and we do not gather data about you from any third party. We do not use analytics beacons, fingerprinting, advertising networks or any other tracking technology.

3. How we use your information

We use chat messages solely to generate responses for your current conversation. We use your account data solely to run the Service for you: the username to identify you, the email address only to send the one-time verification code, and the password hash to authenticate you. We use server logs to operate, monitor, secure and improve the Site and the Service. We use the local storage values solely to remember your cookie-notice choice and your reasoning preference.

We do not sell your information. We do not use chat messages to train models, build profiles about you, or target advertising at you. We do not read your conversations beyond generating the response you asked for.

4. Legal bases for processing

If the GDPR applies to our processing, the legal bases are:

  • Performance of a service you request (Article 6(1)(b)) — operating your account and session so you can sign in and chat, and processing chat messages to generate the responses you asked for;
  • Our legitimate interests (Article 6(1)(f)) — operating and securing the Site and the Service, keeping them available, and detecting abuse or technical faults.

Where we rely on legitimate interests, you can object at any time as described under “Your rights” below.

5. Cookies and local storage

The Site sets exactly one cookie: the login session on the chat page (toothed_session). It is HttpOnly and SameSite=Lax, it is sent over HTTPS, and it lasts up to 30 days or until you sign out. Because it is strictly necessary for the Service you asked for, the consent rules for non-essential cookies do not apply to it, and accepting or rejecting the informational cookie notice changes nothing about how the Site behaves.

Your browser also stores two small local-storage values: your choice in the cookie notice, and the reasoning level you select for Levy 1 (Off / Standard / Deep) on the chat page. Local storage is not a cookie: those values never leave your device and are not read by us. You can clear them at any time through your browser settings. See the Cookie Policy for details.

6. Sharing and third parties

We do not share personal data with any third party, and we do not currently use third-party processors, analytics tools or content delivery networks. All assets, including fonts and icons, are served from our own server.

If the verification email is delivered through a third-party email service, that service receives your email address for the sole purpose of delivering the message to you.

If we ever engage processors, we will contractually require them to process personal data only on our documented instructions and in accordance with this policy and applicable law (including Article 28 of the GDPR), and we will update this policy.

7. Storage and retention

Chat messages are processed in memory while your conversation is active and are not written to storage; they are discarded when your conversation ends. Server logs are kept for a short period (a few weeks) for operational and security purposes and are then deleted or made non-identifiable. We do not maintain archives or backups of conversations.

Account data (username, email address, password hash and active sessions) is stored in the Site’s database for as long as your account exists. The Service does not currently offer self-service account deletion; contact us (section 14) and we will delete your account and its sessions on request.

8. Security

We apply reasonable technical and organisational measures to protect the information processed through the Site and the Service, including HTTPS transport and minimising what we collect. Because the Service is operated by an independent research project, these measures are proportionate to the small amount of data involved. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

9. International transfers

Currently, the information you send us is processed on servers we operate. If, in the future, we rely on processors located outside the European Economic Area, we will put appropriate safeguards in place (such as the European Commission’s Standard Contractual Clauses) and update this policy.

10. Children

The Site and the Service are not directed to children under 13, and we do not knowingly collect personal data from them. If you believe a child has sent us information, contact us and we will delete it.

11. Your rights in the EU and the United Kingdom

If you are in the European Union, the United Kingdom or another jurisdiction that grants these rights, you have the right to:

  1. access the personal data we hold about you (if any);
  2. request its rectification or erasure;
  3. restrict or object to its processing;
  4. receive it in a structured, machine-readable format (data portability); and
  5. withdraw any consent you have given, without affecting the lawfulness of processing based on consent before its withdrawal.

We keep only what is described above — your account details, your verification email address, active sessions and the short-lived server logs. Most requests can be satisfied by updating or deleting that data directly, and we will respond to any request within the time required by law (generally one month). You also have the right to lodge a complaint with your data protection authority (in Spain, the Agencia Española de Protección de Datos).

12. California residents

If you are a California resident, the California Consumer Privacy Act, as amended (CCPA/CPRA), gives you the right to know what personal information we collect, use and share; to request its deletion; and to opt out of the “sale” or “sharing” of personal information. We do not sell or share personal information, and we do not use it for cross-context behavioural advertising. If you make a verifiable request, we will respond as required by law and will not discriminate against you for exercising these rights.

13. Changes to this policy

We may update this Privacy Policy from time to time. The current version is always published on this page with the date shown above. If we make material changes, we will highlight them on the Site.

14. Contact

Questions about this policy, or about your personal data, can be sent to us through the chat on the Site or through any contact channel Toothed AI makes available. Please include “Privacy” in your message so we can route it correctly.