Privacy Policy
Last updated: August 24, 2026
This Privacy Policy explains how ISH Chat Ltd ("ISH", "we", "us") handles personal data when you use ish.chat, api.ish.chat, and related services.
1. Information we collect
- Account information: your GitHub account identifier, name, email address, avatar, and authentication records.
- Chat and API content: prompts, responses, model choices, system instructions, tool activity, and API request content.
- Files and memories: attachments you upload and preferences or facts you save, or allow ISH to save, for future chats.
- Plugin and API information: MCP server settings, authorization records, API key names and prefixes, and hashed API keys. Raw API keys are shown only when created.
- Usage and balance records: model, token and cost measurements, balance changes, request status, and related audit logs.
- Payment records: purchase amount, currency, payment status, payment method, and transaction identifiers. Card and bank credentials are collected and processed by Razorpay, while crypto checkout details are processed by Infini. Payment credentials and wallet private keys are not stored by ISH.
- Technical data: IP address, browser, device, operating system, timestamps, cookies, and diagnostic or security events.
2. How we use information
We use this information to:
- authenticate you and provide the chat and API services;
- send requests to the model and tools you select;
- personalize chats when memory is enabled;
- measure usage, maintain balances, and investigate billing issues;
- secure the service, prevent abuse, and diagnose failures;
- maintain and improve product reliability and usability;
- comply with legal obligations and enforce our Terms.
3. Legal bases
Where applicable law requires a legal basis, we process data to perform our contract with you, for legitimate interests such as security and service improvement, with your consent where requested, and to comply with legal obligations. You may withdraw consent without affecting processing that already occurred.
4. AI providers and plugins
To answer a request, ISH sends the necessary prompt, conversation context, files, and settings to Rootnull and the model made available through it. If you invoke web search, an MCP server, or another plugin, the data needed for that action is sent to that service. Those providers process data under their own terms and privacy policies. Only enable plugins you trust.
5. When information is shared
We may share information:
- with infrastructure, security, analytics, and support providers;
- with AI and plugin providers as described above;
- with Razorpay or Infini to securely process the payment method you choose, prevent fraud, confirm settlement, and handle disputes or refunds;
- when you deliberately create a public chat link;
- to comply with law or protect the rights and safety of ISH or others;
- as part of a merger, financing, acquisition, or sale of assets.
A public share can be viewed by anyone with the link until you make it private. Review a conversation before sharing it publicly.
6. Storage and security
We use reasonable technical and organizational measures to protect information. API keys are stored as hashes, and sensitive connector credentials are protected in storage. No internet service can guarantee absolute security, so protect your account and revoke credentials you no longer use.
7. Retention
We keep account data, chats, files, and memories while they are needed to provide the service or until you delete them. Usage, balance, security, and audit records may be retained longer when reasonably necessary for accounting, fraud prevention, dispute resolution, or legal compliance. We may retain limited backups for a reasonable period.
8. Your choices and rights
ISH lets you delete chats and memories, disable memory, revoke API keys, disconnect plugins, and make shared chats private. Depending on where you live, you may also request access, correction, deletion, restriction, objection, or portability of your personal data, or lodge a complaint with your local data protection authority.
9. International processing
ISH and its providers may process data in countries other than your own. Where required, we use appropriate safeguards for international data transfers.
10. Children
ISH is not directed to children under 13, and we do not knowingly collect their personal data. Contact us if you believe a child has provided personal data.
11. Changes and contact
We may update this Policy as ISH changes. The date above shows the latest revision. Questions or privacy requests can be sent to [email protected].
See our Terms of Service for the rules that apply when you use ISH.