Local data processing
File reads and writes happen entirely on your own device. Your project structure, source code and assets are not transferred to our servers.
We state plainly which data is processed and which is not. Your source code stays on your device; our servers hold usage metrics only.
File reads and writes happen entirely on your own device. Your project structure, source code and assets are not transferred to our servers.
Only usage metrics are kept on our servers: timestamp, model and quota consumed. Chat content is not stored or indexed. The sole exception is cross-device sync, which you enable yourself: if you turn it on, a copy of your chats is stored on the server.
Your chat messages are passed to the model provider for processing: DeepSeek or Anthropic infrastructure, depending on the Aros tier you choose. The provider's own retention policy operates independently of ours; the full list is in the privacy policy.
You can export your chat history as JSON or Markdown and close your account in a single step. No additional form or approval process is required.
We do not store your code. The text you send to the AI passes through our server, goes to the model, the reply comes back to you — and it ends there.Request and response content is not written to the usage log. The one exception is cross-device sync, which you enable yourself: with it on, a copy of your chats is stored on our server — in plain text unless you also enable encryption.
What we store is accounting: who, when, on which model, how many tokens. A counter, not content.
**Account information:** your email address or your wallet address. Only the one you use. We never store the password itself — only an irreversible hash of it.
**Usage record:** a timestamp, the model name and token counts for each request. To deduct from your balance and to be able to show you your usage chart.
**Payment record:** the plan you bought, the amount, the payment method and — for crypto payments — the transaction hash on the chain. Card details never reach us.
**Session record:** device name and approximate location (city level), so you can see and close your sessions in settings. Session tokens are stored only as hashes; even if the database leaks, the token itself is not exposed.
**Abuse prevention:** your IP address and device identifier are stored **not directly, but as an irreversible hash (HMAC)**. The purpose is one thing only: to stop the same person from opening unlimited accounts and getting around the quota. We cannot go back from the hash to the IP.
We do not store chat content, the files you send, or the code we produce.
We do not see the files on your computer; the application reads them on your device and sends them to the model only when you ask it to.
We do not use ad trackers, third-party analytics or cookie-based tracking.
We do not sell your data. Under no circumstances.
To carry out AI requests, your messages are sent to the model provider. Provider servers may be located outside Türkiye; this transfer is required for the service to work.
The model provider's own retention policy is independent of ours.
Where your messages go: Aros models run on DeepSeek (api.deepseek.com) and Anthropic (api.anthropic.com) infrastructure. Depending on the model you choose, your request goes to one of these two. Aros names are our product names; the provider behind them is the one named here.
Payment verification: If you pay with crypto, your wallet address and transaction ID are queried against the relevant chain's block explorer to verify the payment (Etherscan and the same family — Arbiscan, Basescan, BscScan, Polygonscan, Lineascan, Optimistic Etherscan; also Solscan and Tronscan). No such transfer occurs when you pay by card.
Email: For login codes and notifications, your email address is passed to the email delivery provider we use.
Sent directly from your device: If the agent searches the web, your search text goes to DuckDuckGo (or Brave or Tavily if you have configured a key); if it looks up a package or documentation, the query goes to docs.rs and registry.npmjs.org. These requests leave your computer directly, not our server: those services see your IP address, and we do not see the contents of these requests. If you disable the search tool, this transfer never happens.
Apart from the above we share your data with no one; we do not sell data. If a legal obligation arises, we will inform you to the extent the law permits.
If this list changes, this page is updated.
Account information: as long as your account is open.
Usage and payment records: 10 years, as required by accounting legislation. These are amounts and counts, not content.
Abuse hashes: 12 months.
When you delete your account, your account information and sessions are deleted; financial records subject to a statutory retention period are kept detached from your identity.
Under KVKK and GDPR: you have the right to access your data, to ask for it to be corrected, to ask for it to be deleted, to object to its processing and to receive your data in a portable form.
Inside the application, under **Settings → Privacy**, you can export your chats and delete your account — on your own, without filing a request.
For a written application: kvkk@jazaricode.com. We reply within 30 days at the latest.
Connections are encrypted end to end with TLS. Session tokens and abuse hashes are not kept in the database as plain text.
No system is flawless. If you notice a security flaw, write to us; we do not pursue good-faith reports legally.
If we update this policy we announce it inside the application and change the date above. For material changes we ask for your consent again.