Release 9123078639f1 Versions and sources

Privacy · collection, retention, controls

Pheme has no accounts, advertising profiles, or cross-device history. Current first-party analytics ingestion excludes raw questions and scenarios; the historical migration status is disclosed below.

Three columns — scroll the table sideways for the rest.

Pheme data retention by category
CategoryWhat's retainedRetention
Page and product eventsCurrent schema: route, event ID, coarse country/region, referrer bucket, and a salted daily-rotating pseudonymous session ID derived from IP + user agent; no prompt textUp to 30 days
Monthly and daily aggregatesCurrent counts without free-form content or a persistent visitor identifierUp to 400 days (about 13 months)
Abuse controlsIP addresses become salted, rotating request-subject hashes before rate-limit keys or alerts are storedAbout 1–48 hours
Operational model cacheHashed lookup keys; cached provider choice labels and generated reasoning may reflect the submitted question, but are excluded from analyticsUp to 30 days
News metadataHeadline, publisher, source URL, dates, topic, and correction statusUp to 730 days
FeedbackMessage and optional email are delivered through Resend to the operator; Pheme keeps no application-database copyDelivery-provider and operator-mailbox retention apply

Unknown verified migration and purge record not yet published

Historical analytics migration status

Until the operator runs and records both the preview and confirmed legacy-data purge, assume older analytics records may still contain raw questions, answer options, or finer-grained geography. Current ingestion excludes those fields. This notice remains until a verified migration record is published; no deletion is implied merely by deploying newer code.

Observed bounded question or story fields sent to the configured provider

External model providers

When provider-assisted reasoning or source discovery is eligible, the bounded question, scenario context, or archived story fields are sent to the configured external model provider. If semantic reasoning is unavailable, Ask publishes no replacement percentage; deterministic scenario and explorer tools remain available without claiming to interpret arbitrary prose. Pheme does not add free-form content to its current analytics event store.

Unknown guaranteed deletion interval not yet published

Feedback deletion

Pheme does not yet publish a guaranteed deletion interval for feedback held by its delivery provider or receiving mailbox. Request deletion through Feedback and include the sending address and approximate date so the operator can locate the message.

Observed device-only preference, no server-side account

Analytics control

Turning analytics off means this browser sends no first-party analytics beacon. It does not disable essential rate limiting, feedback delivery, or a model request you explicitly submit. The preference is stored only on this device.

Observed URL fragments and legacy query parameters

Sharing and local history

Preset IDs may appear in a normal URL. New Ask and simulation shares put free-form questions or custom scenarios in the URL fragment; anyone with that link can read them, but fragments are not sent in HTTP requests. For compatibility, older links using ?q= or ?scenario= still load. Those query values can enter browser history and edge/server request logs before the client removes them, and that earlier logging cannot be retracted by the cleanup. Legacy simulation recent-runs history is stored only in this browser and automatically expires.