Privacy
Privacy Policy
Last updated 29 September 2026
What we collect
Your wallet address is the account. To open the workspace you sign a message (Sign-In with Ethereum). That signature proves you control the address. We then keep a session so you stay signed in.
In the workspace we store what you put there: messages, files you attach (and extracted text from documents), personas you write, the model a conversation uses, pins and titles, reply ratings, the auto-delete window you choose, a quiet activity count per month, and which browsers are signed in.
We do not ask for an email, password, name, phone number or card. Credit top-ups, if you make them, are USDC transactions signed by your wallet; we keep the transaction hash and the credit balance. For each reply we also keep a usage record — the model, the tokens read and written, whether the reply was included or paid, and the conversation it belongs to — to compute the trial, Core period and the balance. The monthly totals appear in Settings. For the one-time trial we keep how much of it the account used. We cannot tell whether two wallets belong to one person and do not try to. If the address has an ENS name or avatar, the workspace may show it by looking it up on Ethereum.
Each reply has a privacy receipt, opened from the reply: where the question came from, the model and its route, the Knowledge it used, the sites Diogenes read, what an on-chain lookup sent, what left Diogenes, how it is kept and what it cost. It holds no message text. You open it in the app, in the Diogenes panel inside a connected app, or through the API, and your data export includes it. Only you can open a chat reply's receipt; every member of a JAR can open the receipt of a Diogenes reply in its Consilium. What a receipt touched is encrypted like the chat or room it belongs to, and it is deleted with the reply.
How chats are stored
Chat content, attachments and JAR Knowledge content are encrypted at rest. Diogenes decrypts the content needed to answer your requests. This is server-side encryption, not end-to-end encryption.
JAR names, operational metadata and embeddings are not covered. Older backups and retained pre-migration file copies may still contain plaintext. Those copies have not been erased.
What we do not do
Diogenes does not sell conversations, does not use them to train a public model, and does not run advertising or analytics products on the workspace. What you write goes to a model maker such as Anthropic or OpenAI only when you choose an external model and confirm its provider. We do not claim that models run on your device.
How a message is answered
The browser talks only to Diogenes. The Diogenes API sends the conversation to a private model endpoint we control and streams the reply back. The model sees the text, images a vision model can see, and extracted text from documents. The reply is stored with your account. PDF bytes are not sent to a third-party reader.
Some models use confidential inference through NEAR AI. This protects model processing inside a hardware-isolated environment: the Diogenes API verifies the attestation of the very machine it is connected to before sending a word, keeps the reply and its signature on that connection, and checks the cryptographic evidence for each reply afterwards. Diogenes still processes your messages before sending them to the model and receives the reply in the clear, as with any model. This is separate from encryption of stored chats and is not end-to-end encryption. It does not cover the browser, stored files or JAR indexes, which stay with Diogenes. A model you pick says so in the model list; Settings → Models shows the current verification state.
When you ask about an address, a transaction or a token and on-chain reading is offered, the model calls read-only chain tools: the addresses and hashes in your question go to the RPC endpoints we run against (Ethereum and any other network we configure) and, for prices, to DefiLlama. Nothing else from the chat goes with them, nothing is signed or sent on chain, and your signed-in wallet address is included only when you ask about your own wallet.
My Knowledge holds your own notes, pages and imports, and only you can read it. Your personal chats draw on it unless you turn it off in a chat; it is never sent to an external model, and an API key or a connected app reaches it only through the personal chats it may use. Importing notes reads the folder or export in your browser: only the notes you pick are uploaded, and pictures and other files stay on your computer. Saving a link fetches that one public page, and only its address leaves Diogenes.
When you ask for a picture and image generation is offered, the model writes a short description and sends it to the image model on the same private endpoint; nothing else from the chat goes with it. The picture comes back to Diogenes and is stored as an attachment on the reply, encrypted at rest with the chat, for your account only.
Personal API keys (Settings → API) let your own scripts use the same models as this app. We store only a hash of each key, its name, and when it was last used. Requests made with a key are stored as chats in your workspace, encrypted like any other, and count against your Core period, credits and spending limit — never the trial. Browsing is not offered through the API, and a key never publishes to a JAR by itself.
A new API key reaches only your personal chats; you choose which JARs, if any, it may use, and can keep it out of personal chats. An app connected over MCP, such as Claude or Cursor, reaches only the JARs you chose and spends pay-as-you-go credits only up to its cap, and a shared JAR is open to connected apps only if its owner allows it. You can revoke a key or disconnect an app at any time in Settings.
In a JAR, each model request for a chat in the JAR includes the JAR's instructions and its shared Knowledge (the whole library while it is small, otherwise the passages that best match the question) and is sent to the same inference provider. To make Knowledge searchable, each document's text is also sent to that provider when it is added or changed, to build a search index that is stored with the JAR and removed with the document. Shared Knowledge is stored for that JAR and readable by all current members, including members who join later. Member wallet addresses are visible within the JAR. Your chat transcripts in a JAR are stored with your account and shown to no other member; Diogenes processes them to answer, as with any chat.
Removing shared content deletes it live for every member, subject to the backup window below. It cannot retract information already included in another member's answers, downloads or exports. Leaving a JAR does not remove what you published; the owner can remove it.
If you turn on auto-save in a JAR chat, each completed answer in that chat is published to the JAR's Knowledge under your address, for all current and future members. Your own messages and attachments are not published, but answers may repeat information from them.
A scheduled task in a JAR runs your saved prompt on the schedule you set, as a chat in that JAR billed to you and never above the task's monthly credit cap. A private task is seen by no one else. If you share a task, the JAR's current members see its name, its prompt and the answers its runs produce, but not anything you add to its chat yourself. A task stops when you pause or delete it, or when you leave the JAR.
If you paste a public web link or a site name and ask about it, the Diogenes API fetches that page from its own servers — the site sees a Diogenes reader, not you. The extracted text is stored with your chat, shown to no one else, and deleted with the chat.
If you ask it to explore a site — its navigation, filters or a dashboard — an isolated browser on Diogenes servers opens the public page you asked for. The site sees Diogenes, not your wallet, cookies or JAR Knowledge. Observed excerpts and filters stay with that chat and are deleted with it. Models receive page text and structure only, never screenshots.
A page that needs an account is never signed into for you. You may sign in yourself through a live view of that isolated browser, shown to your session only over an encrypted connection. Keystrokes and pictures from that view are relayed and not stored; password, code and card fields are blanked in anything a model could see; the assistant does not act until you confirm. The browser, with the site's cookies, is destroyed when you stop, disconnect, leave it idle for ten minutes or reach 45 minutes. Replies drawn from a signed-in page, and later replies in that chat, are marked as such and are never auto-saved to a JAR; publishing one requires your review.
External models
Models listed under External are run by the provider named on them — at present Anthropic or OpenAI. They are used only when you pick one; Diogenes never falls back to them from private or confidential inference. Before the first message to a provider in a chat, you are asked to confirm that provider, and the choice is recorded with that chat.
What is sent: the message, the conversation so far, text from its attachments and images if the model can see them — whatever the model needs to answer. Your wallet address is not included. The request travels from the Diogenes API through the inference service Diogenes uses, which passes it to the provider. External models are unavailable in JAR chats and in Consilium, so JAR instructions and shared Knowledge are never sent to them.
Retention, from each company's current documentation. The inference service Diogenes uses states that it does not store inputs or outputs of these requests. For Anthropic models on this route, Anthropic deletes prompts and outputs after generation except where law requires otherwise or to address misuse, and may run safety classifiers on them; some Anthropic models require 30 days of retention for safety review, and the model's details say so when that applies. Anthropic data retention. For OpenAI models on this route, OpenAI's zero data retention terms apply: content is excluded from abuse-monitoring logs and responses are not stored, with limited exceptions that OpenAI documents. OpenAI data controls. Neither provider trains on API content by default. Diogenes stores the chat and the reply with your account, encrypted like any other chat.
Who else is involved
Our cloud provider hosts the API, the database, file storage, the inference endpoint and this website. Your wallet software stays on your side; we never see the keys. If you connect through WalletConnect, that service is used only for the connection. A public Ethereum RPC is used to verify the signed message and, when present, to resolve ENS.
For a model marked confidential, NEAR AI operates the hardware-isolated inference service that receives the conversation for that reply. Diogenes checks Intel and NVIDIA attestation evidence for that service; the check itself does not send your content anywhere.
If you choose an external model, its provider (Anthropic or OpenAI) receives that chat's request, as described under External models.
Our cloud provider holds the stored workspace and the inference request. The others see only what that piece of the path requires.
How long we keep things
Conversations stay until you delete them, or until they sit idle longer than the window you set in Settings — 7, 30 or 90 days. Pinned conversations are kept. Deleting a conversation removes its messages, images and privacy receipts. Shared Knowledge stays until its author or the JAR owner removes it, or the JAR is deleted. Deleted content leaves live storage at once; copies may remain in backups for a short time. You can export your chats or delete the workspace from Settings. A signed-in browser session keeps nothing beyond its own lifetime: only the reply text you saw, and which citations required a login, stay with the chat.
Your choices
Export your data. Delete one conversation or all of them. Disconnect the wallet. Set auto-delete. Rate a reply — that verdict stays with the message.
Children
Diogenes is not directed at children under 16. Do not use it if you are younger.
Changes
If this page changes in a material way, the date at the top will change with it.
Contact
There is no account email — the wallet is the identity. Use Settings to export or delete what we hold. The Terms of Use sit beside this policy.