Privacy
What happens to your question
People ask this app things they would not say out loud. That earns a straight answer about where those questions go — including the parts that are not reassuring. Everything below was checked against Microsoft's published terms and against our own live configuration on 16 August 2026, and anything we could not verify has been left off the page rather than softened into something vaguer.
This page is about the questions you ask. The company-wide policy covering accounts, payments, and your legal rights is at deepanchorstudio.com/privacy.
Where your question goes
Your question is sent to Microsoft's Azure OpenAI service, running in Microsoft's own Azure environment. It is not sent to OpenAI, and it never touches ChatGPT or the OpenAI API.
Your questions are processed in the United States, in Microsoft's East US region.
We authenticate to that service with a managed identity — there is no shared API key sitting in configuration that could leak.
It is not used to train AI
Microsoft does not use your questions or the answers to train or improve any AI model — not OpenAI's, not Microsoft's.
The model itself is stateless. It does not remember your question after it answers it.
What can be stored, and who can read it
This is the part most apps leave out, so read it carefully rather than skipping to the end.
Microsoft runs automated abuse monitoring on the service. If its systems flag a question or an answer as potentially abusive, a sample can be stored and reviewed — by automated systems first, and in some cases by authorized Microsoft employees. That store sits in the same US geography, is separated by customer, and reviewers can only reach content that has already been flagged, through audited just-in-time access.
We have not applied for, and do not have, Microsoft's "modified abuse monitoring" exemption, which would turn that storage off.
What matters most about that storage is what is not in it. We do not attach anything to your question that identifies you — not the name on your account, not your email address, not your device, not any account identifier. There is nothing in what we send that ties a question back to you, or that links two questions to the same person. What travels with your question is the profile detail used to write the answer — a first name if you entered one, an age range for a child, the faith background you chose — and a first name you typed yourself is not an identity.
So the honest summary is not "nothing is ever stored." It is: nothing you ask is used to train anything, nothing goes to OpenAI, nothing we send identifies you, and a flagged sample can be stored and read under those specific conditions.
What we are not claiming
A privacy page is only worth reading if the things it does not say are as deliberate as the things it does. These are claims we could easily have made and did not:
- We do not publish a deletion timeline. You will see "deleted after 30 days" on a lot of pages like this one. We could not verify a figure we would be willing to stand behind, so we do not print one — and we are not printing "briefly" or "temporarily" either, which is the same unverified claim with the number taken off.
- We do not claim "zero data retention." We do not have the arrangement that phrase would refer to. See the section above.
- We do not claim your questions are never seen by a human. Human review is conditional, not impossible, and saying otherwise would be false.
If we obtain a documented answer on retention, it goes on this page with its date, and this section shrinks.
Voice conversations, and what happens to the audio
A voice conversation sends your microphone audio, live, to two services: LiveKit, which carries the call, and Microsoft Azure Speech, which turns speech into text so the same answer engine described above can read it. The text of what you said is then handled exactly like a typed question — everything in the sections above applies to it unchanged.
We do not record your voice. The app has no recording feature, and nothing in our service writes the audio to a file, a database, or storage of any kind. There is no recording to keep, and so there is nothing for us to retain: our retention period for voice audio is none, because we never hold a copy. The audio is processed as it streams and is gone when the conversation ends. What can outlive the call is the text transcription, under the conditions described in What can be stored, and who can read it — the same conditions that apply to a typed question, and no others.
Nobody's voice is identified, matched, or enrolled. We do not create a voiceprint. We do not use speaker recognition, speaker identification, or speaker separation, and we do not attempt to work out who is speaking, their age, their gender, or their emotional state from how they sound. Your audio is used to work out what was said, and for nothing else. This is a property of how the system is built, not a promise about how we intend to behave: the capability is not enabled anywhere in our voice path.
Voice is never available on a child profile. If a question is being asked about a child, the app does not offer a voice conversation — and if a request for one arrives anyway, our server refuses it before any microphone stream can begin. That refusal is not a setting a parent can turn off, and it is not something a subscription unlocks. A child's voice is never captured by this app, so the question of how long we keep it does not arise.
As with the rest of this page, the parts we cannot verify are named rather than smoothed over: what we control is that we take no copy, and that no voice is ever identified or matched. What LiveKit and Microsoft do inside their own systems is governed by their terms, and we do not publish a number for it that we have not been able to confirm.
What stays on your phone
Your saved answers and the profiles you set up — for yourself, a child, or a friend — are stored on your device, under a key scoped to your account. They are not uploaded to a server of ours, and signing out clears them from the device.
The one other thing we send
Along with your question, the app sends your device's language-and-region tag — for example "en-US" or "en-GB". It is used for exactly one purpose: choosing the right crisis helpline to show if a question is classified as a safety concern. The app does not request or use your location. That is described in full in our crisis protocol.
When this page changes
The claims above are true of a specific configuration, not of "AI" in general, so they are re-checked when that configuration changes — a different model or region, a change to how the service is authenticated, or a change in Microsoft's published terms. The verification date at the top of this page is the date of the last check, and it moves only when a check is actually done.
Questions about any of this go to support@deepanchorstudio.com.