DarkGPT is built so that the people running the network cannot read your prompts. This page says exactly what we do collect, on the website and in the desktop app, and what we do with it.
This policy covers darkgpt.ai, the DarkGPT P2P desktop app, and the backend services behind them, operated by DarkGPT ("we", "us"). Providers on the network are independent people running the app on their own hardware; the section on prompts explains what they can and cannot see.
darkgpt.ai uses Vercel Web Analytics, which records page views, referrers, country, device type and browser in aggregate. It does not set cookies and does not build a profile of you. Our hosting provider keeps ordinary server logs (IP address, requested page, time) for a short period for security and debugging.
The chat box on the home page sends your message to our backend, which forwards it to a provider on the network and returns the answer. We use your IP address only to enforce the free daily limit. We do not store the text of your message or the answer on our servers; the message is relayed in memory and discarded.
When you sign in with Google we receive your name, email address and Google account ID. When you sign in with an email code we receive your email address, and Postmark delivers the code on our behalf. We use these to identify your account, show your balance and earnings, and contact you about the service. We do not sell or share them for advertising.
The app sends a heartbeat and a small set of events so we can show how many nodes are online and know when a release breaks. Each install gets a random device ID that is not derived from your hardware. The fields are:
The event schema is a whitelist. Prompt text, answers, file contents, chat history and window titles are not in it and cannot be sent by construction. If you sign in, the device is linked to your account so your earnings can be credited.
When you chat through the app, your prompt is encrypted on your machine to the public key of the provider that will serve it, and the answer comes back encrypted to you. Our servers do not sit in the middle of that connection and cannot read either side.
The provider's machine decrypts your prompt to run the model. Providers must be in a hardware trust boundary (today, Apple Silicon with Secure Enclave keys and an attested system posture), and the terms of service forbid providers from logging, inspecting or retaining prompts. We cannot technically stop a determined operator from modifying their own machine, so do not send secrets, passwords or regulated personal data through the network.
For each served request we record a request ID, token counts, timing and the provider and model that served it, so rewards can be settled. None of that includes the prompt.
Providers earn DCN on a test network. We create a custodial wallet address for your account and keep a ledger of rewards and payouts. That ledger holds your account ID, wallet address, token counts and amounts. DCN on the test network has no monetary value.
Purchases are disabled during the beta. If we enable them, payment details will go directly to Stripe and we will update this page first.
When you download the app from darkgpt.ai we record that a download happened, the platform and the version, so we can count installs. The app checks for updates from our servers and fetches them over the peer-to-peer swarm; other nodes can see that a node fetched an update, not who you are.
We rely on Vercel (website hosting and analytics), Railway (backend hosting), Supabase (database), Postmark (sign-in emails), Google (sign-in) and Discord (community). Each processes only what its role requires under its own privacy terms. We do not share your data with advertisers or data brokers.
Account data is kept while your account exists. Telemetry and request records are kept for up to 12 months, then aggregated or deleted. Server logs are kept for a short period, typically under 30 days. You can ask us to delete your account and the data tied to it at any time.
Wherever you are, you can ask what we hold about you, ask us to correct or delete it, and object to how we use it. If you are in the EU, UK or another jurisdiction with data protection law, those are your statutory rights and we honour them. Ask through the Discord server or the contact below and we will answer within 30 days.
DarkGPT is not for anyone under 18. We do not knowingly collect data from children, and we delete it if we learn we have.
If this policy changes in a way that matters, we will note it in the release log and on this page before the change takes effect. Questions and requests: the DarkGPT Discord, or the security contact on the security page.