Privacy · collection, retention, controls
Pheme has no accounts, advertising profiles, or cross-device history. Current first-party analytics ingestion excludes raw questions and scenarios; the historical migration status is disclosed below.
Three columns — scroll the table sideways for the rest.
| Category | What's retained | Retention |
|---|---|---|
| Page and product events | Current schema: route, event ID, coarse country/region, referrer bucket, and a salted daily-rotating pseudonymous session ID derived from IP + user agent; no prompt text | Up to 30 days |
| Monthly and daily aggregates | Current counts without free-form content or a persistent visitor identifier | Up to 400 days (about 13 months) |
| Abuse controls | IP addresses become salted, rotating request-subject hashes before rate-limit keys or alerts are stored | About 1–48 hours |
| Operational model cache | Hashed lookup keys; cached provider choice labels and generated reasoning may reflect the submitted question, but are excluded from analytics | Up to 30 days |
| News metadata | Headline, publisher, source URL, dates, topic, and correction status | Up to 730 days |
| Feedback | Message and optional email are delivered through Resend to the operator; Pheme keeps no application-database copy | Delivery-provider and operator-mailbox retention apply |
Unknown verified migration and purge record not yet published
Historical analytics migration status
Until the operator runs and records both the preview and confirmed legacy-data purge, assume older analytics records may still contain raw questions, answer options, or finer-grained geography. Current ingestion excludes those fields. This notice remains until a verified migration record is published; no deletion is implied merely by deploying newer code.
Observed bounded question or story fields sent to the configured provider
External model providers
When provider-assisted reasoning or source discovery is eligible, the bounded question, scenario context, or archived story fields are sent to the configured external model provider. If semantic reasoning is unavailable, Ask publishes no replacement percentage; deterministic scenario and explorer tools remain available without claiming to interpret arbitrary prose. Pheme does not add free-form content to its current analytics event store.
Unknown guaranteed deletion interval not yet published
Feedback deletion
Pheme does not yet publish a guaranteed deletion interval for feedback held by its delivery provider or receiving mailbox. Request deletion through Feedback and include the sending address and approximate date so the operator can locate the message.
Observed device-only preference, no server-side account
Analytics control
Turning analytics off means this browser sends no first-party analytics beacon. It does not disable essential rate limiting, feedback delivery, or a model request you explicitly submit. The preference is stored only on this device.
Observed URL fragments and legacy query parameters
Sharing and local history
Preset IDs may appear in a normal URL. New Ask and simulation shares put free-form questions or custom scenarios in the URL fragment; anyone with that link can read them, but fragments are not sent in HTTP requests. For compatibility, older links using ?q= or ?scenario= still load. Those query values can enter browser history and edge/server request logs before the client removes them, and that earlier logging cannot be retracted by the cleanup. Legacy simulation recent-runs history is stored only in this browser and automatically expires.