LibreChat Demo
Privacy Policy
Effective Date: March 12, 2026 · Last Updated: March 12, 2026
This Privacy Policy explains how the LibreChat Project, maintained by Danny Avila (“we”, “us”, “our”), collects, uses, stores, and protects your personal data when you use the LibreChat Demo (“Demo”, “Service”), accessible at chat.librechat.ai. We are committed to protecting your privacy and processing your data in accordance with Regulation (EU) 2016/679 (the General Data Protection Regulation, “GDPR”) and other applicable data protection laws.
1. Data Controller
The data controller for this Service is:
The LibreChat Project
Maintained by: Danny Avila
Email: [email protected]
GitHub: github.com/danny-avila/LibreChat
If you have questions or concerns about how your data is handled, you may contact us at the address above.
2. What Data We Collect
2.1 Account Data
When you create an account, we collect:
- Email address — provided directly by you during registration or obtained via a social login provider.
- Display name — provided by you or obtained from your social login profile.
- Avatar image — obtained from your social login provider, if applicable.
- Authentication identifiers — such as your Google or GitHub user ID, if you use social login.
2.2 Usage Data
When you use the Service, we process:
- Conversation messages — the text you submit to the AI and the AI-generated responses.
- Uploaded files — any files you attach to conversations (documents, images, etc.).
- Technical metadata — including your IP address, browser user agent, timestamps of requests, and session identifiers.
2.3 Data We Do Not Collect
- We do not use analytics services or third-party tracking tools on the Demo.
- We do not use advertising cookies or tracking pixels.
- We do not collect payment information (the Demo is free).
3. How We Use Your Data
We process your personal data for the following purposes and on the following legal bases:
| Purpose | Data Involved | Legal Basis (GDPR Art. 6) |
|---|---|---|
| Providing the Service (account creation, authentication, AI chat functionality) | Account data, conversation messages, uploaded files | Performance of contract (Art. 6(1)(b)) |
| Maintaining security and preventing abuse (rate limiting, ban enforcement, fraud detection) | IP address, user agent, usage patterns | Legitimate interest (Art. 6(1)(f)) |
| Complying with legal obligations (responding to lawful requests, DSA compliance) | Account data, content data, technical metadata | Legal obligation (Art. 6(1)(c)) |
| Improving and debugging the Service | Aggregated, anonymized usage statistics | Legitimate interest (Art. 6(1)(f)) |
We do not use your data for profiling, automated decision-making, or direct marketing.
4. Third-Party AI Model Providers
The Demo connects to third-party AI model providers (such as OpenAI, Anthropic, Google, and others) to process your conversation messages. When you send a message, the text of your message (and any attached files, where supported) is transmitted to the selected AI provider for processing.
Each AI provider processes your data in accordance with their own privacy policies and terms. We encourage you to review the privacy policies of the AI providers you use through the Service. We are not responsible for the data practices of third-party AI providers.
5. Third-Party Authentication Providers
If you use social login (such as Google or GitHub), the authentication provider may share your name, email address, and profile picture with us in accordance with the permissions you grant during the login process. We receive only the data necessary for account creation and do not access your contacts, files, or other account data from those providers.
6. Data Sharing and Sub-Processors
We do not sell, rent, or trade your personal data. We share your data only with the following categories of recipients, and only to the extent necessary:
- Hosting provider — Hetzner Online GmbH (Gunzenhausen, Germany). Servers are located in the EU (Falkenstein, Germany).
- AI model providers — as described in Section 4, your conversation data is transmitted to the AI provider selected for each interaction.
- Social login providers — Google LLC, GitHub Inc., as applicable, for authentication purposes only.
- Law enforcement or regulatory authorities — where required by law, court order, or binding regulatory request.
All sub-processors that handle personal data on our behalf are contractually bound to process your data only on our instructions and to implement appropriate technical and organizational security measures.
7. International Data Transfers
Your data is primarily stored on servers located in the European Union (Germany). However, when you use AI model providers whose servers are located outside the EU (such as in the United States), your conversation data is transferred to those jurisdictions.
Where personal data is transferred outside the EU/EEA, we rely on:
- The European Commission's adequacy decisions, where available.
- Standard Contractual Clauses (SCCs) approved by the European Commission.
- Other appropriate safeguards as required by the GDPR.
8. Data Retention
We retain your data for the following periods:
| Data Type | Retention Period |
|---|---|
| Account data (email, name, avatar) | Until you delete your account, or until we perform periodic Demo cleanups |
| Conversation messages | Until you delete them, until your account is deleted, or until periodic Demo cleanups |
| Uploaded files | Up to 30 days, subject to automatic deletion |
| Technical logs (IP, user agent) | Up to 30 days |
| Rate limiting and ban records | Up to 90 days |
As this is a demonstration service, we may perform periodic database cleanups that result in the deletion of all user data. We do not guarantee long-term persistence of any data on the Demo.
9. Your Rights Under the GDPR
If you are located in the European Economic Area (EEA), you have the following rights regarding your personal data:
- Right of Access (Art. 15) — You may request a copy of the personal data we hold about you.
- Right to Rectification (Art. 16) — You may request that we correct inaccurate or incomplete data.
- Right to Erasure (Art. 17) — You may request that we delete your personal data (“right to be forgotten”).
- Right to Restriction of Processing (Art. 18) — You may request that we restrict the processing of your data in certain circumstances.
- Right to Data Portability (Art. 20) — You may request to receive your data in a structured, commonly used, machine-readable format.
- Right to Object (Art. 21) — You may object to processing based on legitimate interests.
- Right to Lodge a Complaint — You have the right to lodge a complaint with a supervisory authority. If you are located in Italy, the competent authority is the Garante per la protezione dei dati personali (garanteprivacy.it).
To exercise any of these rights, contact us at [email protected]. We will respond within 30 days.
10. Cookies and Local Storage
The Demo uses only strictly necessary cookies for:
- Session management (maintaining your login state).
- Security (CSRF protection tokens).
We do not use analytics cookies, advertising cookies, or any form of cross-site tracking. No cookie consent banner is required as we rely solely on cookies that are exempt under Article 5(3) of the ePrivacy Directive (Directive 2002/58/EC) because they are strictly necessary for the provision of the Service.
11. Security Measures
We implement appropriate technical and organizational measures to protect your personal data, including:
- Encryption in transit (TLS/HTTPS for all connections).
- Access controls and authentication for server infrastructure.
- Regular security updates and monitoring.
- Firewall rules restricting access to internal services.
However, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security and are not liable for breaches resulting from circumstances beyond our reasonable control.
12. Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will:
- Notify the competent supervisory authority within 72 hours of becoming aware of the breach, as required by GDPR Art. 33.
- Notify affected users without undue delay where the breach is likely to result in a high risk to their rights and freedoms, as required by GDPR Art. 34.
13. Children's Privacy
The Service is not directed at children under the age of 16. We do not knowingly collect personal data from children under 16. If we become aware that we have collected personal data from a child under 16, we will take steps to delete that data promptly. If you believe a child under 16 has provided us with personal data, please contact us at the address in Section 1.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. Material changes will be communicated through the Service interface. Your continued use of the Service after the effective date of any changes constitutes your acceptance of the updated Privacy Policy.
15. Contact Us
For any privacy-related questions, data subject requests, or concerns, please contact:
The LibreChat Project
Maintained by: Danny Avila
Email: [email protected]
GitHub: github.com/danny-avila/LibreChat
By using the LibreChat Demo, you acknowledge that your data is processed as described in this Privacy Policy.