Privacy Policy

How Instachat handles your data. Last updated 17 September 2026.

Who we are

Instachat and the Instachat Browser extension are operated and published by SoulfulAI OĂś (registry code 16571650), registered in Estonia. For any privacy question or request, write to [email protected]. This policy covers the Instachat web app, desktop app, iOS app, the Instachat bots on Telegram and WhatsApp, and the Instachat Browser extension.

What we collect

  • Account data — your email address, a display name if you give one, and an account identifier. If you sign in through Telegram, we receive your Telegram user id and username.
  • Conversations — the messages you send to the assistant and its replies, so a conversation can continue across your devices.
  • Voice — when you use voice or the glasses, your speech is transcribed to text so the assistant can answer. If you explicitly start a recording, the transcript of that recording is saved to your workspace, and the audio may be uploaded to produce a better transcript.
  • Photos and camera images — only when you take a photo or turn the camera on, and only to answer the question you asked about it.
  • Things you ask us to remember — facts you tell the assistant to keep, stored as notes in your own workspace.
  • Calendar, reminders and clipboard content — only when you ask the assistant to do something with them (“what is on my calendar”, “remind me to…”). The app asks your device for permission first, and only the item in question is processed.
  • Technical data — basic logs needed to run and secure the service, such as request timing, errors, and rate-limit counters.

Location is used only if you allow it, and only in the moment: to attach a place to a note you are making, or to answer a question that depends on where you are. It is never collected in the background, and you can refuse or withdraw the permission at any time in your device settings.

We do not track you across other apps or websites, we do not show advertising, and we do not sell or rent your data to anyone.

Why we use it

To answer you, to keep one conversation consistent across your devices, to remember what you asked us to remember, to enforce usage limits and prevent abuse, and to keep the service running and secure. We do not use your conversations to train our own models.

Where it lives

Your conversations, recordings, and saved notes are stored in a workspace that belongs to your account and is not shared with other users. Our infrastructure runs in the European Union. Some processors we rely on (below) operate outside the EU; where that is the case, transfers are made under the European Commission's standard contractual clauses.

Who else processes it

We use a small number of specialist providers to deliver the product. They process your data only to provide their part of the service, under contract, and none of them may use it for their own purposes:

  • AI model providers — your messages are sent to AI models through OpenRouter (our model gateway) and the model providers it routes to — currently Google (Gemini) and Novita — to generate replies, including real-time voice conversations.
  • Speech-to-text and text-to-speech providers (Deepgram, Groq, and Google) — to transcribe what you say and to speak replies aloud.
  • Firecrawl — when the assistant searches the web for you, the search query is sent to this search provider. Your identity is not.
  • Apple — if you ask what song is playing, a short acoustic fingerprint of the audio is sent to Apple's music recognition service. No recording is kept.
  • Spotify — only if you connect your Spotify account in Settings. We then use Spotify's Web API on your behalf to play, like, or control music and see what is playing. It is never active until you connect it, and never runs in the background.
  • Cloudflare — hosting and network protection.
  • Telegram or WhatsApp — only if you choose to talk to us there, and then under their own privacy policies as well as this one.
  • Stripe — if you buy a subscription. We never see or store your full card number.

Instachat Browser extension

Instachat Browser connects a Chrome profile to a local MCP app that you choose. Control starts only after you click Connect and give that app the current pairing key. Stop invalidates the connection and the key; an action already sent to a page may still finish. The extension has no Instachat account sign-in and stores no account token. Its chat link opens the Instachat website in a separate tab, where this policy and the website sign-in apply.

What the tools can access

While connected, requested tools can read supported tabs' addresses, titles, page structure and content, screenshots, and recent console and network summaries. They can type text, run page JavaScript, navigate, and create, select and close tabs and windows, inside the website sessions you are already signed in to. This can expose personal or sensitive information shown on those pages, including what you type into forms. Incognito and restricted Chrome pages are not supported. There is no cookie export feature, but page scripts run by the tools can reach data available to that page.

Where information goes

Commands and results travel through Chrome native messaging and a local socket to the app you paired. The extension and its bridge do not upload browsing data to Instachat, an analytics service or a model provider, and contain no advertising or telemetry. Your MCP app may send tool results, screenshots and prompts to its own model provider or other services under that app's settings and policies. Browser actions can also send requests to websites, submit forms or run page scripts, so we do not promise that nothing leaves your computer. Opening the chat link connects to the Instachat website, and Chrome Web Store installs and updates run under Google's policies.

If the app you pair is Instachat Desktop, its Browser Assistant sends your prompts and the tool results you allow, including page content and screenshots, to Instachat Brain under your signed-in account so the Yin and Yang models can answer. That processing is covered by the rest of this policy.

Storage and retention

The pairing key and connection state are held in memory for the active connection and are invalidated by Stop or when the connection is lost. Your MCP app's configuration may keep a copy; remove old keys. Anyone with a valid key who can reach the local socket can use the connection, and programs running as the same computer user are not strongly isolated from each other. Requested screenshots are saved as private files in ~/.instachat/browser-bridge/screenshots until you delete them. Recent console and network summaries are kept in limited memory buffers and cleared when the connection or tab closes. Your MCP app may keep its own transcripts, results and screenshots.

Sharing, deletion and choices

The extension and bridge do not sell browsing information, use it for advertising, or use it to train models. This does not cover independent MCP apps or model providers. To remove the integration, stop browser control, disable the MCP server, uninstall the extension and its bridge, and delete the saved local files. Stopping the extension does not revoke a separate Chrome DevTools connection or sign you out of websites.

The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.

Questions: [email protected].

How long we keep it

Conversations, recordings, and notes are kept in your workspace until you delete them or close your account. Operational logs are kept for a short period for security and debugging, then discarded. When you close your account we delete your workspace and the personal data in it, except anything we are legally required to retain (for example, invoices for tax purposes).

Your rights

Under the GDPR you can ask us for a copy of your data, ask us to correct it, ask us to delete it, ask us to restrict or stop a particular use, and ask for your data in a portable form. Write to [email protected] and we will respond within one month. You may also complain to your national data protection authority.

Recording other people

If you record a conversation, you are responsible for doing so lawfully where you are. Laws differ: some places require only your own consent, others require everyone's. Please tell the people around you when you are recording.

Children

Instachat is not intended for children under 16, and we do not knowingly collect their data. If you believe a child has given us personal data, write to us and we will delete it.

Changes

If we change this policy we will update the date at the top of this page, and we will tell you in the app before any change that materially affects how your data is used.