Privacy Policy
byself is built so that your conversations stay with you. Your chat history is kept on your own device, your prompts are sent only to a fixed list of vetted providers, and we collect as little about you as we can while still running the service.
This Privacy Policy explains how byself AI Limited ("byself", "we", "us") collects, uses and protects personal data when you use the byself desktop application and the byself.ae website (together, the "Service"). We are established in the Dubai International Financial Centre (DIFC) and act as the Controller of the personal data described below. Where the DIFC Data Protection Law No. 5 of 2020 (the "DPL") applies, we process personal data in line with it. Other data-protection laws may also apply depending on where you are located.
1.Our approach in short
- Local by default. Your prompts and the models' answers are stored in a database on your own computer, not on our servers.
- Direct, vetted routing. When you send a prompt, it is transmitted to the AI providers you selected through our routing layer, to fulfil your request. We do not route prompts to unlisted providers.
- Minimal account data. We keep only the limited information needed to run your account, billing and support.
2.Who we are & how to contact us
The Controller is byself AI Limited, Innovation One, DIFC, Dubai, United Arab Emirates, P.O. Box 507211. For any data-protection question, or to exercise your rights, contact us at hello@byself.ae.
3.Information we collect
Account information
Your name, email address and, for corporate accounts, your organisation and role (for example, administrator), together with authentication data needed to sign you in.
Billing information
Payments are handled securely by our third-party payment provider. We receive confirmation of transactions and records such as credits purchased and consumed, plan, seats and status. We do not store your full payment-card details.
Prompts, answers and files
The prompts you write, any files you attach and the answers returned by the models are stored locally on your device. To obtain answers, the content of a prompt is transmitted to the AI providers you selected for that request (see section 5). We do not retain your prompt or answer content on our own servers.
Voice input
If you dictate a prompt, the audio is transcribed on your device and the recording is not uploaded to us.
Technical information
Limited technical information needed to operate and secure the Service, such as application version, operating system and diagnostic or error logs. We do not use this to build advertising profiles, and we do not carry out solely automated decisions that produce legal or similarly significant effects on you.
4.Why we process it, and our legal basis
Under the DPL we rely on the following lawful bases:
- Performance of a contract — to create and run your account, provide the Service, and process your credits, subscription and payments.
- Our legitimate interests — to secure the Service, prevent fraud and abuse, provide support, and maintain and improve the product, balanced against your rights.
- Compliance with a legal obligation — to meet tax, accounting and other legal requirements.
- Consent — where we ask for it, for example for any optional communications; you may withdraw consent at any time.
5.How your prompts are routed
byself does not train AI models. When you send a prompt, it is passed through our routing layer (provided by OpenRouter) to a fixed allowlist of vetted inference providers, chosen for their data-handling commitments. Prompts are not sent to hosts outside this allowlist.
Our PrivacyPlus feature shows each model's data-retention status before you send, and lets you exclude data-retaining models so they never receive your prompt. Once a prompt reaches a provider, that provider's own privacy terms also apply to its processing. Corporate customers who bring their own provider key route requests through their own provider account, under that provider's agreement with them.
6.Who we share information with
We do not sell your personal data. We share it only as needed to run the Service, with these categories of recipient (processors):
- AI routing and model providers — our routing provider (OpenRouter) and the AI providers it connects to, to deliver the answers you request;
- Payment provider — to process your payments;
- Hosting and infrastructure providers — who host our website and account systems;
- Legal and safety — where required by law or to protect rights, safety and the integrity of the Service.
Where we engage processors, we put in place contracts requiring them to protect personal data in line with applicable law.
7.Transfers outside the DIFC
Because our AI providers and some other processors operate in various countries, personal data — including the content of a prompt you choose to send — may be transferred to and processed outside the DIFC, including in jurisdictions that may not have been assessed as providing an equivalent level of data protection. Where we make such transfers, we rely on an appropriate basis under the DPL and take reasonable steps to safeguard the data, and PrivacyPlus lets you limit which providers receive your prompt.
8.Data retention
Chat history remains on your device until you delete it. We keep account and billing records for as long as your account is active and thereafter only as long as needed for legitimate business and legal purposes, after which they are deleted or anonymised.
9.Security
We use appropriate technical and organisational measures to protect personal data under our control. No method of transmission or storage is completely secure, but keeping your conversation history on your own device by design reduces the data exposed to us.
10.Personal data breaches
If a personal data breach occurs that affects your data, we will notify the DIFC Commissioner of Data Protection as soon as reasonably practicable, and we will inform you where the breach is likely to result in a high risk to your rights.
11.Your rights
Subject to applicable law, including the DPL, you have the right to: access your personal data; have inaccurate data corrected; have data erased; restrict or object to certain processing; receive your data in a portable form; and withdraw consent where processing is based on it. We will respond within the timeframe required by law. To exercise any right, contact hello@byself.ae. You also have the right to lodge a complaint with the DIFC Commissioner of Data Protection.
12.Children
The Service is not directed to children and is intended for users aged 18 or over. We do not knowingly collect personal data from children.
13.Changes to this Policy
We may update this Policy from time to time. We will post the updated version here and revise the "Last updated" date above. Significant changes will be notified where appropriate.
14.Contact us
For any questions about this Policy or your personal data, contact us using the details below.
byself AI Limited
Innovation One, DIFC, Dubai, United Arab Emirates · P.O. Box 507211
Email: hello@byself.ae