PUBLIC POLICY
Privacy
Plain-language privacy information for the public pui.ai build. Last updated: August 16, 2026.
What pui.ai stores
Chats, projects, workspace settings and reviewed custom-model metadata are stored in an independently versioned browser-local workspace. Explicitly indexed file, pasted-text and public-URL passages use a separate local Knowledge index. The workspace can use a limited in-memory fallback when IndexedDB is unavailable; the persistent Asset Vault cannot and reports storage failure visibly.
Ordinary composer files remain one-message inputs: bounded document text and processed image data are held only until the request finishes, while message history keeps file name, type, size and provenance. Explicit Asset Vault uploads persist canonical derivatives: PDF and DOCX become bounded normalized plain text; PNG, JPEG and WebP are decoded and re-encoded locally to strip metadata. A supported inline file returned by an approved MCP call is a separate generated-output path: PUI validates its base64, MIME, name, size and signature, sanitizes generated UTF-8 text, preserves exact verified PDF/DOCX bytes and canonicalizes images. Binary bytes stay outside the model transcript and workspace record. Metadata-only Workspace JSON and chat exports contain no vault Blobs, base64, data URLs or temporary object URLs. Only an explicitly requested complete backup includes verified vault files.
Visitor-provided provider and MCP keys have three browser-local storage choices. Remember in this browser (recommended) stores AES-256-GCM ciphertext and keeps a separate non-extractable device key in IndexedDB, allowing automatic reuse after reloads, new tabs and browser restarts in the same browser profile. This tab only uses session storage for that tab session. Passphrase-protected vault (strict) persists encrypted data but never stores its passphrase and requires unlock after a browser restart. Every choice is scoped to one immutable workspace and exact provider or MCP authority. None sends a key to pui.ai or includes it in workspace, library, chat or plaintext exports. The explicit password-protected complete backup is the sole portable encrypted exception. The OpenRouter free fallback is different: it is intentionally public application code, is not treated as a visitor secret and is never copied into credential storage or exports.
Web search is disabled by default for each chat. Its ordinary chat setting stores only whether OpenRouter search is enabled, a bounded result limit from 1 to 10 and the selected context size. A completed search answer may keep source URL, title and optional character-position indices so its citations survive reload. It does not store raw search snippets or search-result content, request headers, or a second copy of the OpenRouter API key. The user's message remains part of the normal chat record; web search creates no separate local query history.
Voice input is click-to-start. Custom spelling corrections are ordinary browser-local workspace settings. The separate dictation-history feature is off by default; if you enable it, its entries are kept only in session storage for that browser tab, can be cleared from the microphone status panel and are excluded from workspace exports and backups. Dictated text you leave in an ordinary saved draft or chat follows the normal workspace-storage rules above.
Edit in Canvas makes a second local copy of the selected assistant response inside the workspace, together with source chat and message references and any versions you save. The action itself contacts no AI provider, tool endpoint or clipboard. Canvas content and its history are included in workspace exports, so review them before sharing a backup.
Automations are not stored in the browser workspace. If an owner connects the optional private scheduler, its separate Host SQLite database stores reviewed schedule definitions, prompts, execution status, bounded results and Inbox acknowledgements. Browser Workspace JSON, complete device transfer and chat/agent packages never copy that database. A browser-notification preference stores only non-secret job IDs and the last seen run ID in this browser; notification text contains no result.
What leaves your device
Your browser sends messages, selected context, locally processed images and the applicable API credential directly to the selected model provider. OpenRouter uses the app's intentionally public shared credential only when no personal OpenRouter key is unlocked; in that mode the UI and request runtime allow only openrouter/free and model IDs ending in :free. Shared quotas can be exhausted and availability is not guaranteed. A visitor-owned OpenRouter key always takes precedence and exposes the full catalog. OpenAI Direct sends only the visitor's Bearer key and selected request content straight to https://api.openai.com/v1: model discovery uses /v1/models and generation uses /v1/chat/completions. It does not use the Responses API. If you explicitly enable the OpenAI Direct dictation fallback, PUI offers it only after browser recognition fails; recording still requires a separate click, and the recorded audio is sent to /v1/audio/transcriptions only after you stop that recording. OpenRouter and generic compatible providers are not substituted. Selected context can include bounded composer attachments or Asset Vault items that you explicitly attached for that request, plus bounded excerpts from local documents assigned to the active agent or allowed by its current project/tag scope; source headings accompany those excerpts. Merely saving or viewing an Asset Vault item sends nothing. Images are sent only when the selected model, every route member or every Council candidate declares usable Vision support. The provider's privacy policy and retention rules apply. Browser speech recognition may be processed by the browser vendor; pui.ai asks for microphone permission before listening.
Ollama, LM Studio and oMLX are optional local providers. When you select one, the browser sends the request directly to the loopback endpoint on your own computer—never through the pui.ai server. No token is required when the local runtime permits unauthenticated access; if you save its optional token, the browser sends that token directly to the same local endpoint. Modern browsers ask you to grant pui.ai Local Network Access before that connection begins. The local runtime must be running, expose an OpenAI-compatible API and explicitly allow the https://pui.ai browser origin. If you change a local endpoint to another host, that host receives the request under its own privacy and retention rules.
Web search v1 works only with an OpenRouter chat and a visitor-owned OpenRouter key, and remains off until you enable it for that chat. It is blocked with the public free fallback because search can add charges. When you send a message with search enabled, the browser sends the prepared chat request and your personal OpenRouter key directly to OpenRouter with its bounded web-search server tool. There is no pui.ai search gateway. OpenRouter, the search engine it selects and the selected model may process the search query and relevant chat context needed to answer it. Their privacy, retention, quota and billing rules apply. The result limit defaults to 5 and cannot exceed 10.
When you manually call or approve an assigned MCP tool, the browser connects directly to its reviewed HTTPS endpoint. Public internet is the default; an explicitly confirmed Trusted LAN server may instead use one exact private HTTPS address. Exa Search is the only reviewed MCP template installed and enabled in a new workspace; it exposes bounded web-search and public-page tools, works with limited free access or an optional visitor-owned Exa key, and can be removed completely from that workspace. Removing it also clears its local assignments, approvals, device check and scoped credential; the optional template remains available for a deliberate reinstall. A custom server receives only the exact bounded JSON input approved for that call and any authentication credential you saved for that exact authority. Supported rich output can create a browser-local response file after validation; safe HTTPS resource links are displayed without prefetch and open only on your click. pui.ai has no MCP proxy, shared MCP key or public user-file store. The remote server receives ordinary connection data such as your IP address, and its privacy, retention, quota and billing terms apply.
If you activate a model route, the browser may send the same prepared request—including any processed one-message images—to later providers in the explicit route, up to the attempt ceiling you chose. A fallback is allowed only after a temporary failure that produced no text. Response Comparison sends one independent request to every selected model and retains each model's own lane history; changing the Primary answer is local and sends nothing. Council sends processed images independently to every selected candidate; its judge synthesis request contains candidate text only. Saved route, comparison and Council trails contain model selections, timings, bounded outputs and safe error categories, never API keys, image data or raw provider error bodies.
When you explicitly import a public URL into Knowledge, your browser connects directly to that host. The request omits application cookies, credentials and the referrer and does not follow redirects, but the host and its network provider still receive ordinary connection data such as your IP address and time. Browser CORS must permit access. HTTPS protects the response in transit; an HTTP source does not.
When you use the optional private **Automations** control plane, your browser sends bounded scheduler commands directly to the exact reviewed owner MCP endpoint. An activated AI job later sends its reviewed prompt and optional Brave News query from the always-on private host to the separately configured search and model providers; their privacy and retention rules apply. Browser provider keys, browser MCP approvals, chat transcripts and cookies are not uploaded for scheduler execution. A reminder performs no model or search request.
What the site does not include
- No shared OpenAI account. OpenRouter has only an intentionally public, free-model-only fallback with no paid balance.
- No OpenAI gateway, ChatGPT OAuth session or server-side provider-key persistence.
- No pui.ai web-search relay, Brave Search token or server-side search credential.
- No public multi-tenant MCP endpoint, shell, browser-automation, LAN gateway or filesystem access. Explicit public or Trusted LAN MCP connections are browser-direct; an owner may separately operate the private scheduler described above.
- No server-side chat database, advertising SDK or analytics SDK.
- No cookies created by the application.
- No automatic discovery of LAN services. Built-in local-model connections target loopback on the visitor's own device.
OpenAI API keys are not ChatGPT accounts
An OpenAI Platform API key is separate from a ChatGPT login or subscription. A ChatGPT plan does not provide API credentials or include API usage; the visitor's own OpenAI API project determines billing, quota and model access.
Direct browser BYOK means an automatically available or unlocked key can be used by application code running on this origin. A non-extractable device key prevents raw key export through Web Crypto, but same-origin code can still ask the browser to decrypt and use the credential; privileged or malicious extensions may also be able to observe or use it. The automatic browser-bound vault therefore protects persistent data at rest, not a compromised browser profile, and it does not sync to another browser, profile or device. Use pui.ai only from a trusted browser profile and device, prefer a restricted and revocable project key, and revoke it at the provider if the device or origin may have been compromised.
Why Brave Search is not offered directly
The public application cannot safely call the Brave Search API from the browser: the required authenticated request does not provide the cross-origin browser contract this deployment needs, and Brave advises customers not to expose its subscription token in client-side code. pui.ai does not work around that boundary with an operator relay. Web search v1 therefore requires a visitor-owned OpenRouter key; it does not accept or store a Brave token and does not use the public OpenRouter fallback.
Hosting logs
The hosting and network providers may process normal technical request data such as IP address, timestamp and requested page for security and delivery. Chat content and provider/MCP keys do not pass through the pui.ai application server.
Payments and sales contact
The pricing page does not collect card details. While payment onboarding is pending, support buttons open an ordinary email enquiry. Once public checkout links are enabled, selecting a paid option sends you to the named payment provider, which processes contact, billing, tax and payment information under its own terms. pui.ai does not receive or store full card data.
Email enquiries and payment-provider records are not part of the browser-local workspace and are not included in its exports or reset controls. The current public site has no paid entitlement tracker, account system, advertising tracker or application-level IP profiling. Before checkout is activated, the payment provider and the legally responsible seller will be identified on the pricing and legal pages.
Your controls
Workspace JSON (metadata only) creates a versioned local workspace-record copy without keys, Knowledge passages or Asset Vault payloads. Reusable saved conversation views are portable, but private recent-search history is always removed from exports and ignored on import. A query is remembered only after you open a conversation result, can be cleared in the Command Center and is never sent to an analytics service. Importing that JSON as a new workspace detaches browser-local Knowledge and Asset Vault references instead of pretending unavailable local content moved with the file.
Protected device transfer contains the workspace record, the entire local Knowledge index and every verified Asset Vault file, including generated response files. Before encryption, a secret-free inventory names every readable, missing, locked or damaged provider/MCP credential; an unreadable stored credential blocks export and a required missing credential needs explicit confirmation. The protected package includes the confirmed readable credentials and may include an authenticated envelope of exact MCP allow/deny and server-wide approval preferences. It never includes the backup passphrase, a strict-vault passphrase, source browser-vault ciphertext or source device key. The backup passphrase exists only for the active encrypt or unlock operation and is never stored, sent to pui.ai or included in the package. Plaintext remains a separate advanced choice, never contains credentials or portable approval authority, and anyone who obtains it can read its workspace content.
Protected and plaintext complete backups use the same strict local content review and fresh-workspace restore boundary. A wrong passphrase, modified package or damaged package writes nothing. A verified restore validates every credential against its exact connection authority, encrypts it under the destination browser's new vault key, reads it back and publishes the isolated workspace only after every workspace, Knowledge, Asset Vault and credential write succeeds. Imported plugins and custom MCP servers start disabled with no grants. Exact MCP preferences selected in a protected restore are saved in a paused state and cannot authorize a call until the destination browser verifies the identical endpoint and tool catalog; a changed authority never inherits them. Private-CA trust and Local Network permission remain device-specific. Creating, unlocking or restoring a complete backup does not contact an AI provider, MCP server or pui.ai backend.
A protected `.pui-chat` export encrypts only the visible complete user/assistant text from the active branch and excludes provider/model data, usage, system messages, IDs and attachments before encryption. Its passphrase exists only in the open dialog; send the file and passphrase separately.
Moving a chat, project or folder to Trash does not erase it. The item, its relationships and project knowledge references remain in browser storage and workspace exports until you restore it or confirm permanent deletion. Trash search uses names and organizational labels only, never message bodies or indexed passages. Permanent project purge removes only local indexes that are no longer referenced by a retained project. These controls cannot delete copies already sent to a cloud provider.
A Knowledge Hub `.pui-knowledge.json` export is different: it deliberately contains the selected indexed passages in plaintext so they can be restored locally. It removes URL provenance and carries no permissions, but it is not encrypted. Review it and store or share it as carefully as the source material. Import is inspected locally, requires an explicit target project and confirmation, and creates fresh IDs.
Portable agent and prompt packages are checked locally for credential-like fields and values. They omit plugin/MCP assignments, permissions, local documents and broad knowledge access; imported items receive fresh IDs and bundled skills remain disabled until you review them.
Automation definitions and Inbox results are controlled and backed up on the separate private scheduler host. Browser export, restore, workspace reset and workspace deletion do not change that host authority. Use the Automations page to pause or delete a job, and the scheduler's root-only online-backup and restore procedure for disaster recovery.
Unlocking a protected package happens locally and shows a metadata preview before anything is saved. Import creates fresh local IDs. An expiry prevents later unlocks but cannot revoke a copy already imported or decrypted by its recipient. Use Trash & recovery for selective deletion, or Privacy & security → Reset current workspace to remove its chats, projects, Trash, settings, Knowledge index, Asset Vault and scoped provider/MCP keys from this browser. Deleting a workspace also clears those scoped stores on a best-effort basis.