Open Thermal AI

Privacy & data management

What stays in your browser, what may reach the Copilot proxy, and how to delete data — without over-claiming.

Effective date: 2026-07-26 · Last updated: 2026-07-27

Privacy / data requests: jingyanrong@126.com. General engineering contact: jingyanrong548@gmail.com.

What is stored locally

Project Center projects, analysis versions, reports, and Workspace context are stored in this browser (localStorage). Clearing site data can permanently delete them. This is not cloud storage.

What may be sent to the LLM proxy

When you use live Copilot, brief text and related project parameters may be sent to our server-side proxy, which calls the configured LLM provider (currently DeepSeek in the test phase; additional providers such as Qwen, OpenAI, or Claude may be enabled later). Deterministic engineering numbers come from registered calculators — not from the model inventing results. API keys never leave the server.

What is stored on our server

The proxy may keep short-lived operational logs (request id, mode, status, latency, error type — not API keys and not full project descriptions by default) and in-memory daily usage counters for rate limits. Request/usage counters are retained for no longer than 14 days in the current proxy process memory and are cleared on process restart or routine maintenance. Longer retention may occur only when required for security investigation or legal compliance. We do not claim a durable project database on the server in this phase.

Third-party services

LLM providers via server-side proxy (currently DeepSeek; architecture supports Qwen / OpenAI / Claude when enabled): Copilot chat and parameter extraction when you use live Copilot. Hosting: GitHub Pages and Alibaba Cloud Lightsail / Nginx for the static site and API proxy (primary production host). The current production build does not use third-party web analytics. Hosting logs, security logs, and API operational logs may still be retained by hosting and API providers under their own terms and retention policies. Opening the contact modal may load a QR image from api.qrserver.com for vCard download. A Baidu URL-submission script may run for search indexing (not visit analytics). We do not operate a separate error-monitoring SaaS in this phase. Contact forms open your email client — no third-party form SaaS is required. Verify each provider’s current terms. Last reviewed: 2026-07-29.

Conversations

Chat history shown in Workspace is primarily local to the browser session / project. Do not paste secrets, passwords, or regulated personal data into briefs.

Files

Project files can be attached locally in this browser (IndexedDB). Sending file text/metadata to AI requires explicit user confirmation per file. There is no permanent cloud file vault yet — clearing site data removes local files. Secure multi-user cloud storage remains Planned.

Model training

We do not claim that provider models never use API traffic for training. Check each enabled provider’s current API terms (DeepSeek today). Prefer redacting customer names and proprietary process details when possible.

How to delete data

  • In Project Center → project Settings: export, then delete the project.
  • Or clear this site’s data in your browser settings.
  • Export important projects regularly — local data can be lost.

Engineering disclaimer

Screening reports and calculators are illustrative aids. They are not PE-stamped design, procurement documents, or legal advice. Have qualified engineers review before investment.