DarkVision

Privacy notice

Updated 18 September 2026. This is mostly a description of what we do not have. Where we do hold something, it says what, why, for how long, and what we can do with it — which in the case of your conversations is nothing at all.

Who this is about

The operator of this site is the controller of the little data described below. We do not ask who you are, so in most cases we hold no personal data about you in any usable sense: there is no name, no email address, no telephone number, no billing identity and no visitor log to attach anything to.

What we never ask for

No email address, telephone number, name or any other identifier. An account is a 16-digit code generated on the server from a cryptographic random source. What we store is a keyed hash of that code, so the code itself cannot be recovered from our database — not by us, and not by anyone who obtains a copy of it.

What we do not store at all

  • Access logs, request logs or visitors' IP addresses.
  • Prompts, replies, pictures or clips from the AI section in readable form.
  • Analytics, advertising identifiers, cross-site trackers or social buttons. There are none on this site.

What passes through and is then gone

Serving any request requires your IP address in memory for the lifetime of that request. It is used to reply to you and to enforce the daily limits on sign-in attempts and to notice abuse, then discarded. For those limits we keep a salted hash of the address with a counter, keyed to the current date, and that record expires by itself. The address is never written down in a form we could read back.

When a code is created, a keyed hash of the browser's device identifier and one of the network address are kept with the account for as long as the account exists. They are compared with nothing else and serve one purpose: when the automatic guard locks an account, the other accounts made from the same browser within the last thirty days are locked with it, so a lock cannot be shaken off with a fresh code. A lock on a browser or an address itself is kept for up to ninety days after it lifts, so that a repeat is recognised, and is then forgotten.

When you use the AI section, the request you wrote — together with the recent history of that chat and any file you attached — is transmitted in readable form, over an encrypted connection, to the independent provider of the model you chose, because that is the only way it can be answered. It travels under our own account with that provider, not under yours: we send no account identifier, no code and no hash of a code with it, so the request arrives unlinked to you. What that provider retains is governed by its own policy, not ours. When a question needs current information — a date, a price, the news — the assistant may run a web search through that same provider; the search terms it derives from your message then reach the provider's search engine as well, under our account and unlinked to you, and the pages it finds are listed under the answer.

One more thing can travel to a provider. If you ask for a clip to be made from a picture you attached and the request is about sex or violence, the picture alone — without your words — is first shown to a vision model at the provider with a single question: whether it clearly shows a child. A picture the model says shows one is refused. Nothing else is asked, and nothing from that check is stored.

Your conversations

Chats are kept so you can come back to them. Every message, chat title, picture, clip and voice note is encrypted with AES-256-GCM before it is written to the database or to file storage. The key is derived from your access code with scrypt when you sign in. It is not stored on our servers: it lives in an HttpOnly cookie in your own browser for the length of your session, and your browser presents it with each request. While a request is being handled, the service uses that key in memory to open the history the model needs and to seal what comes back, and then forgets it. Nothing is written down in readable form, and no log of the content is kept.

Two things follow, and it is important to be exact about both. At rest, your conversations are ciphertext to us: without your code we cannot read them, search them, analyse them, train anything on them, hand them to anybody, or restore them if you lose the code. This is not, however, end-to-end encryption in the sense a messenger uses the term. To answer a request, the text of your message and the recent history of the chat must exist in plain form for a moment on our server, and must be sent over an encrypted connection to the independent provider of the model you chose. That provider necessarily sees the content of what it is asked to answer; what it keeps is governed by its own policy. Pictures, clips and voice notes are encrypted the same way as text and are served back only to a request carrying your key. The "clear all chats" button in the AI section deletes every stored conversation under your code immediately and for good, together with the encrypted files behind it. Deleting a single chat does the same for that chat.

The Services section and other sites

This notice describes this site and nothing else. The Services section, and any other outside address on the site, leads to services run by other people. Following one takes you somewhere this notice does not reach: what that service collects, logs, infers or passes on about you is governed by its own privacy policy and by the law that applies to it, not by anything written here. Read that policy before you give the service anything that matters to you. We have no control over it and cannot answer for it.

Cookies

Three cookies, all strictly necessary for the service to function, all HttpOnly and SameSite. A signed session cookie says which account is signed in, and the content key described above travels beside it; both expire after 14 days and are removed when you sign out. The third is a random device identifier kept for a year. It names your browser and nothing else — it is not tied to a code, never appears in a log and is never sent to anyone — and it exists for one purpose: to stop the same browser claiming the same promo code under several accounts. When a code is activated, a keyed hash of that identifier and of your network address is kept with the activation record, and only compared against later activations of the same code. There are no analytics or advertising cookies, so there is nothing to consent to and no banner to dismiss. Your choice of language is kept in local storage on your own device and is never sent to us.

Two more cookies exist, but visitors never receive them: a partner signed into a partner cabinet, and the operator signed into the console, each carry one signed session cookie scoped to those private pages.

Payments

Top-ups are handled by an independent payment processor. We send it an amount and an internal order reference; it sends back a payment status. We never receive or hold wallet addresses, transaction hashes, card details, bank details or identity documents. That processor handles your payment under its own privacy policy, as a separate controller.

How long things are kept

Balance, top-up and promo-code records are kept while the code exists, because they are the proof of your balance. Encrypted conversations are kept until you clear them. Rate-limit and abuse counters are removed after two days; locks on a browser or address, with their count of repeats, up to ninety days after the lock ends; the hashes recorded when a code is created go with the account when it is deleted. The "delete account" button in your account removes everything at once — conversations, files, the payment ledger and the code's own record — so nothing in the database says the code ever existed. If you simply stop using a code, the account becomes unreachable and nothing attached to it identifies you.

Partner cabinets

Partners who hand out promo codes may be given a cabinet (see the Terms, section 15). About a partner we keep the name or label we gave them, an internal note, the random address of the cabinet, a keyed hash of its password and the time of the last sign-in — nothing that identifies a visitor. The cabinet shows aggregate figures about the codes attached to it: how many times they were activated, what was credited, the number and total of top-ups later made by the accounts that used them, and the commission computed from those totals. It never shows an account, a code holder, an amount for one person, the time of one activation or anything else about an individual visitor, and it cannot: the figures are counts and sums over the same ledger described above.

Legal basis, if you need one named

Where data-protection law applies, we process the minimal data above to perform the agreement with you (running the account and the paid relay) and on our legitimate interest in keeping the service available and unabused (the hashed rate-limit counters). We do not process special categories of data, we do not profile you, and we do not make automated decisions with legal effect about you.

Your rights, and their honest limits

You may ask what we hold, ask for a copy, ask for correction or erasure, or object to processing. In practice the answer is short: a keyed hash of your code, a balance, top-up amounts, and ciphertext we cannot decrypt without your code. Because we cannot verify that a person asking is the holder of a given code, and because we deliberately hold nothing that would let us check, we cannot disclose anything about a code to whoever asks for it — that limitation protects you. Erasure you can perform yourself: the clear-chats button removes every conversation, and the delete-account button removes the account and everything under it.

Disclosure and demands

We can only ever produce what we have: hashed codes, balances, transaction amounts and ciphertext without a key. We do not have visitor IP addresses, and we hold chat content and your files only as ciphertext that cannot be opened without your code. If we receive a lawful demand, those limitations are the whole of the answer we are able to give. We will not add logging in order to be able to answer such a demand in future.

Contact

For help, questions, payment trouble and bugs, write to contact@darkvision-sec.com or to our Telegram channel, @darkvisionsec, which accepts direct messages. Telegram is a separate service run by its own operator under its own privacy policy: what you write there is visible to Telegram, and the account you write from is yours, not ours. Legal notices, complaints from rights holders, demands from authorities and requests under this notice are accepted by email only. We never ask for your access code, anywhere; anyone who does is not us.