Privacy policy
Version 1.0 · in effect 30 July 2026
The short version
LLMap has no accounts and no sign-in. You can read every page without telling us anything. Three things are optional and you choose each one: asking the assistant a question, subscribing to the digest, and requesting an API key.
Analytics are off until you allow them. There is no advertising, no profiling, no session recording, and nothing here is sold or shared for anyone else's marketing.
1. Who is responsible
LLMap is built and run by Kōdō Studio. In data-protection law we are the "controller" for everything described here: the party that decides what is collected and why, and the one you can hold to account.
LLMap is offered to people in the EU and the UK, so the GDPR applies to your data and you keep every right it gives you. For anything at all about your data — a question, a correction, or a deletion — write to hello@llmap.ai.
2. What we store
This is the complete list. Most of it never happens unless you choose to do something.
Nothing at all, if you only read. Browsing models, hardware, providers, benchmarks and guides stores nothing about you on our servers.
Your questions to the assistant. If you use the chat, we hold the conversation — your questions, the answers, and the archive data the assistant looked up — so that a follow-up like "which of those is cheapest?" means something. The conversation is identified by a random id plus a secret key that stays in your browser tab; we have no way to connect it to you, and anyone without that key cannot read it, including us in any practical sense. It is deleted 24 hours after it starts, measured from the first message and never extended.
A conversation you deliberately share. If you use the share button, we store a read-only copy and give you a link. That copy is public to anyone with the link and is kept for 180 days. Do not share a conversation containing anything you would not post publicly.
A one-way scramble of your IP address, for fair use. The assistant costs real money per question, so we cap how much any one visitor can use per day. To count without identifying, we hash your IP address — a one-way scramble that cannot be turned back into the original — and keep only the hash and a counter, for about a day.
Your email, if you subscribe to the digest. The address, whether you confirmed it, and when. We also record the IP address you confirmed from, as evidence that the subscription was genuinely requested. That one is stored as an ordinary IP address rather than a hash.
Your email and name, if you request an API key. Plus what you told us you intend to build and how much traffic you expect, because we approve keys by hand. The key itself is stored only as a hash, so we cannot recover it and neither can anyone reading our database.
Choices kept in your own browser, not on our servers. Your saved hardware profile, whether you prefer cards or rows, your light or dark theme, your analytics decision, and the key to your current chat. These sit in your browser's local storage and never reach us except the chat key, which you send back when you ask a follow-up. Clearing your browser data removes all of them. Thecookies page lists each one.
We do not buy data about you, we do not track you across other sites, and we build no profile of you.
3. Why we are allowed to
The law wants a specific reason for each thing, so here they are separately.
Running the assistant and keeping it affordable. Holding your conversation for a day so follow-ups work, and counting hashed IPs so one visitor cannot spend the whole budget. Both rest on our legitimate interest in providing and protecting a free service (Art. 6(1)(f)). We have kept each to the minimum that works: a day, not a year, and a hash, not an address.
Sharing a conversation. Only when you press the button, so that is your consent (Art. 6(1)(a)).
The digest. Your consent, given by confirming the address (Art. 6(1)(a)). Every email carries a one-click unsubscribe.
An API key. Necessary to provide the access you asked for (Art. 6(1)(b)).
Analytics. Only if you allow them (Art. 6(1)(a)). Off by default, and the site behaves identically either way.
4. Who else sees it
Short list, named rather than hidden behind "trusted partners". These are processors: they handle data on our instructions, under contract, for nothing else.
| Who | What they handle | Where |
|---|---|---|
| Fireworks AI | Runs the language model behind the assistant, so it receives the text of your chat questions. Zero data retention is switched on for our account, so it processes your question and keeps nothing. | United States |
| Cloudflare | Serves the website and filters abusive traffic. Sees IP addresses at the edge. | Global edge network |
| DigitalOcean | Hosts the database and servers, so everything in section 2 is stored here. | EU region |
| Resend | Sends the digest and API-key emails. Sees your email address. | EU region |
| PostHog | Counts page views and load speed, only if you allow analytics. | EU (eu.i.posthog.com) |
Being straight about the assistant. LLMap publishes a register of which inference providers offer zero data retention, so we owe you the same standard about ourselves. Two things are true at once and both matter.
Your question is not kept. Zero data retention is enabled on our Fireworks account: the model reads your question, writes an answer, and nothing is stored at their end or used to train anything.
It does still travel. Zero retention means "not kept", not "never sent" — the text has to reach the model to be answered, and that model runs in the United States. So if you are working on something genuinely confidential, the honest advice is the same as for any hosted assistant: do not paste it in. We would rather show you where the line is than let "zero retention" sound like the text never left your machine.
Nothing is sold, and nothing is shared for anyone else's advertising.
5. Where it goes
The database and the email sender are in the EU. Analytics are on PostHog's EU host. Cloudflare serves the site from whichever of its locations is nearest you.
Chat text goes to the United States, because that is where our inference host runs. The US has no general adequacy decision, so this transfer relies on the safeguards in that provider's data-processing terms — the European Commission's Standard Contractual Clauses being the usual mechanism — together with the zero-retention setting above, which means nothing remains there once your answer is written. This is the one transfer worth knowing about, and it happens only if you use the assistant.
6. How long we keep things
- Chat conversations — 24 hours from the first message, then deleted.
- Shared conversation links — 180 days. Public for that whole period.
- Hashed IP counters — about a day, then they expire.
- Digest subscription — until you unsubscribe. Unsubscribing keeps a record that you did, so we do not mail you again by accident.
- API keys — while the key is active, and for as long as we need the usage record for abuse handling.
- Analytics — per PostHog's retention on our account.
7. Your rights
You can ask for a copy of your data, correction, deletion, or restriction, and you can object where we rely on legitimate interest. Write tohello@llmap.ai and we will respond within one month. There is no charge.
The honest practical note. For most of what we hold, there is nothing to look up: we have no account for you, and a chat conversation is not linked to your identity, so we could not find "your" conversations even if asked. What we can act on is an email address — unsubscribing you, deleting a subscription record, or revoking an API key — and a shared conversation link, which we will delete on request if you send us the link.
Withdrawing analytics consent takes one click on thecookies page, and is as easy as giving it.
8. Security
- API keys and email-confirmation tokens are stored only as one-way hashes.
- A chat conversation can only be read by someone holding its secret key.
- IP addresses used for rate limiting are hashed, not stored.
- Traffic to the site is encrypted in transit.
- Administrative routes require a separate credential and are not publicly reachable.
We will not claim perfect security, because nobody honestly can. What we will say is that the surface is deliberately small — no accounts means no passwords to leak — and that we fix things when we find them.
9. Children
LLMap is a technical reference aimed at adults and is not directed at children. We do not knowingly collect anything from anyone under 16.
10. Changes
The version and date at the top of this page change whenever this does. A material change — a new processor, a longer retention window, a new category of data — will be described here before it takes effect, and digest subscribers will be told by email.
11. Complaining
If you think we have handled your data badly, tell us first athello@llmap.ai and we will try to put it right. You do not have to, and you can complain directly to the data-protection regulator where you live or work.
Questions about any of this, or want your data removed? Write tohello@llmap.ai. A person reads it.