Legal
Privacy Notice
Last updated 2026-08-23 · the canonical source is docs/legal/PRIVACY.md in the repository.
This notice supersedes the privacy notice previously kept at docs/PRIVACY.md.
The three things you should know before sending a single prompt:
- ~5% of prompts are re-run on verification infrastructure. To catch dishonest nodes, the gateway randomly samples completed jobs and re-executes the same prompt on oracle infrastructure operated by the protocol, then compares the outputs semantically. Your sampled prompt is therefore processed twice: once by the serving node, once by the oracle.
- Prompts and outputs are processed in memory; only hashes are persisted. The gateway does not write prompt or completion text to disk or database — settlement records, reputation data, and verification checks store SHA-256 hashes and numeric scores, not content. (In-memory processing still means the serving node and, when sampled, the oracle see the plaintext while the job runs.)
- Anomalies can trigger on-chain disputes. If verification flags a node's output, the protocol can open a public, on-chain dispute against that provider. Disputes reference job IDs and hashes — not prompt text — but the existence and outcome of the dispute is permanently public.
What we process, and where it lives
| Data | Who sees it | Persisted? |
|---|---|---|
| Prompt + completion text | The serving node; the oracle when sampled (~5%) | No — memory only, on both |
| Prompt/result SHA-256 hashes, token counts, timing metadata | Gateway | Yes — settlement + reputation records (SQLite off-chain; hashes + batch records on-chain) |
| Your wallet address, API key, quota tier | Gateway | Yes — key store |
| Gateway request metadata (timing, token counts, wallet addresses) and standard server logs (incl. IP addresses for ops/security) | Operator | Yes — retained for operations and security, then deleted |
| Node operator wallet, stake, reputation, flags | Everyone (public API + chain) | Yes — on-chain + gateway DB |
| Verification scores + flags (no text) | Gateway admin review queue | Yes |
Accounts
- Gateway / dashboard / wallet sessions authenticate by Ethereum wallet signature (SIWE). We store the resulting session record and your wallet address.
- The chat app additionally offers Supabase-managed accounts (email/password magic-link sign-in and OAuth). If you use account mode, Supabase Auth processes your email/OAuth identity, and signed-in chat history syncs through the chat backend's Supabase database so it follows you across devices. Anonymous/local chats stay in your browser storage.
What we do NOT do
- We do not store prompt or completion text server-side.
- We do not sell user data. There is no advertising and no analytics pipeline. See the Cookies Notice: essential session/auth storage only.
- We do not associate prompts with identity beyond the API key → wallet binding you provided.
Third parties we rely on
| Party | Role |
|---|---|
| Supabase | Chat-app accounts (auth) and synced signed-in chat data |
| Cloudflare | CDN / Tunnel in front of the gateway and sites |
| Vercel | Hosting of this documentation/marketing site |
| Arbitrum RPC providers | Reading and broadcasting public chain data |
| Independent node operators | Serve your prompt in memory while the job runs |
What we cannot promise
Independent node operators run their own machines. The daemon we ship does not log prompt text, but we cannot technically prevent a modified node from recording what it serves. Treat any prompt sent through the network as visible to the operator who serves it. Do not send secrets or personal data — this is also a term of service (Terms).
On-chain data is forever
Wallet addresses, stakes, settlements, disputes, and reputation snapshots live on a public blockchain and cannot be deleted or edited. Anyone can read them, forever. Choose wallets accordingly before transacting on mainnet.
Deletion reality
- Off-chain records are deletable on request: ask us and we will delete your off-chain hash records, key-store entry, and gateway metadata where we do not need them for security or fraud prevention.
- On-chain records are NOT deletable — by anyone, ever. This is a property of public blockchains, not a policy choice.
- Chat users signed in with an account can export or delete their synced history from the app's account page.
Contact
Privacy questions: open an issue at github.com/ShavitR/querais/issues or email shavitrwork@gmail.com. Security vulnerabilities: follow SECURITY.md in the repository.
Related documents: Terms of Service · Cookies Notice