Back
Legal

Privacy Policy

Last updated: April 6, 2026

1. Who We Are

Ask The Master operates the website askthemaster.app. This policy explains how we collect, use, and protect your information when you use our service.

2. Information We Collect

Account Information

When you create an account, we collect your name, email address, and (if using Google Sign-In) your Google profile picture. Passwords are hashed using PBKDF2-SHA256 and never stored in plaintext.

API Keys (BYOK)

If you provide your own API keys, they are encrypted at rest using AES-256-GCM. We never log, display, or transmit your keys in plaintext. Only the last 4 characters are stored as a hint.

Debate Content

We store the topics you submit and the AI-generated responses. Content is associated with your account and not shared unless you use the share feature.

3. How We Use Your Information

  • To provide and maintain the service
  • To process payments via Stripe
  • To enforce rate limits based on your plan
  • To send transactional emails
  • To improve the service based on aggregate usage patterns

4. Third-Party Services

  • Stripe processes payments.
  • Google OAuth is used for sign-in.
  • OpenAI / Anthropic process debate prompts via their APIs.

5. Data Retention

We retain your data for as long as your account is active. You can delete your account and all associated data at any time. Free plan debate content older than 30 days may be automatically removed.

6. Data Security

We use industry-standard security: HTTPS, AES-256-GCM encryption for API keys, PBKDF2 password hashing, and isolated Docker containers.

7. Cookies

We use a single localStorage token for authentication. No tracking cookies, no advertising cookies, no third-party cookie services.

8. Your Rights

  • Access your personal data
  • Correct inaccurate data
  • Delete your account and data
  • Export your debate history
  • Withdraw consent for data processing

9. Contact

For questions about this policy, contact [email protected]