Privacy Policy

Last updated: 16 September 2026

byself is built so that your conversations stay with you. Your chat history is kept on your own device, your prompts are sent only to a fixed list of vetted providers, and we collect as little about you as we can while still running the service.

This Privacy Policy explains how byself AI Limited ("byself", "we", "us") collects, uses and protects personal data when you use the byself desktop application and the byself.ae website (together, the "Service"). We are established in the Dubai International Financial Centre (DIFC) and act as the Controller of the personal data described below. Where the DIFC Data Protection Law No. 5 of 2020 (the "DPL") applies, we process personal data in line with it. Other data-protection laws may also apply depending on where you are located.

1.Our approach in short

2.Who we are & how to contact us

The Controller is byself AI Limited, Innovation One, DIFC, Dubai, United Arab Emirates, P.O. Box 507211. For any data-protection question, or to exercise your rights, contact us at hello@byself.ae.

3.Information we collect

Account information

Your name, email address and, for corporate accounts, your organisation and role (for example, administrator), together with authentication data needed to sign you in.

Billing information

Payments are handled securely by our third-party payment provider. We receive confirmation of transactions and records such as credits purchased and consumed, plan, seats and status. We do not store your full payment-card details.

Prompts, answers and files

The prompts you write, any files you attach and the answers returned by the models are stored locally on your device. To obtain answers, the content of a prompt is transmitted to the AI providers you selected for that request (see section 5). We do not retain your prompt or answer content on our own servers.

Voice input

If you dictate a prompt, the audio is transcribed on your device and the recording is not uploaded to us.

Technical information

Limited technical information needed to operate and secure the Service, such as application version, operating system and diagnostic or error logs. We do not use this to build advertising profiles, and we do not carry out solely automated decisions that produce legal or similarly significant effects on you.

4.Why we process it, and our legal basis

Under the DPL we rely on the following lawful bases:

5.How your prompts are routed

byself does not train AI models. When you send a prompt, it is passed through our routing layer (provided by OpenRouter) to a fixed allowlist of vetted inference providers, chosen for their data-handling commitments. Prompts are not sent to hosts outside this allowlist.

Our PrivacyPlus feature shows each model's data-retention status before you send, and lets you exclude data-retaining models so they never receive your prompt. Once a prompt reaches a provider, that provider's own privacy terms also apply to its processing. Corporate customers who bring their own provider key route requests through their own provider account, under that provider's agreement with them.

6.Who we share information with

We do not sell your personal data. We share it only as needed to run the Service, with these categories of recipient (processors):

Where we engage processors, we put in place contracts requiring them to protect personal data in line with applicable law.

7.Transfers outside the DIFC

Because our AI providers and some other processors operate in various countries, personal data — including the content of a prompt you choose to send — may be transferred to and processed outside the DIFC, including in jurisdictions that may not have been assessed as providing an equivalent level of data protection. Where we make such transfers, we rely on an appropriate basis under the DPL and take reasonable steps to safeguard the data, and PrivacyPlus lets you limit which providers receive your prompt.

8.Data retention

Chat history remains on your device until you delete it. We keep account and billing records for as long as your account is active and thereafter only as long as needed for legitimate business and legal purposes, after which they are deleted or anonymised.

9.Security

We use appropriate technical and organisational measures to protect personal data under our control. No method of transmission or storage is completely secure, but keeping your conversation history on your own device by design reduces the data exposed to us.

10.Personal data breaches

If a personal data breach occurs that affects your data, we will notify the DIFC Commissioner of Data Protection as soon as reasonably practicable, and we will inform you where the breach is likely to result in a high risk to your rights.

11.Your rights

Subject to applicable law, including the DPL, you have the right to: access your personal data; have inaccurate data corrected; have data erased; restrict or object to certain processing; receive your data in a portable form; and withdraw consent where processing is based on it. We will respond within the timeframe required by law. To exercise any right, contact hello@byself.ae. You also have the right to lodge a complaint with the DIFC Commissioner of Data Protection.

12.Children

The Service is not directed to children and is intended for users aged 18 or over. We do not knowingly collect personal data from children.

13.Changes to this Policy

We may update this Policy from time to time. We will post the updated version here and revise the "Last updated" date above. Significant changes will be notified where appropriate.

14.Contact us

For any questions about this Policy or your personal data, contact us using the details below.


byself AI Limited

Innovation One, DIFC, Dubai, United Arab Emirates · P.O. Box 507211

Email: hello@byself.ae