Legal

Privacy Policy

Last updated: September 18, 2026

Who we are

GPULogy AI LLC, a Texas limited liability company, makes LetThemBuild (the desktop app, command-line tool and editor extensions) and LetThemChat (its web app at letthemchat.com and the app for iPhone). GPULogy is the data controller for the information described here. Contact us at [email protected].

What the products do with your data

The products run group discussions between AI assistants (Claude, ChatGPT, Gemini, Grok) on your behalf. We aim to hold as little as possible, and how much passes through us depends on whose keys run a discussion:

  • Your own keys, or a coding CLI you already pay for (desktop): the discussion goes straight from your machine to the AI provider. The desktop app keeps the discussion on your machine, and syncs it to your account only if you are signed in.
  • Our Keys: the content passes through our servers so we can send it to the provider and charge your credit.

Data we store

  • Account: your email address, name and profile picture as provided by the sign-in provider you choose (Google, Microsoft or Apple).
  • Discussions: the messages you send and the AI responses generated in your discussions, including files you attach, so you can revisit them on every device.
  • AI credentials: API keys or OAuth tokens you connect for AI providers, encrypted at rest (AES-256-GCM). They are used only on our servers to run your discussions and are never shown to other users, shared or sold.
  • Team data: if you create or join a team, its name, the email addresses and roles of its members, invitations sent and their status, the discussions members share with the team, and any provider keys an owner or admin adds for the team, encrypted like your own.
  • Billing: if you subscribe or buy credit, payment is processed by Paddle.com, our Merchant of Record. Paddle collects your payment and billing details directly under their privacy policy. We store your plan, the number of seats, your credit balance, a usage ledger (which model ran, when, and what it cost) and a Paddle customer reference — never card numbers, which never reach our servers.
  • Connected apps: if you connect the Service to another app (for example ChatGPT, or the desktop app to your account), we store the grant and its tokens so that app can act for you until you revoke it.
  • Operational records: your IP address and the request path, kept for one hour to limit abusive traffic; a record of each sign-in — the browser or app, the address it last came from and when — kept up to 90 days without use, and shown under Account so you can end one; a log of administrative actions taken on your account; and receipts of the billing events Paddle sends us.
  • Support: emails you send us, kept as long as needed to resolve them.

Where your data goes

  • AI providers: discussion content is sent to the providers you have connected (Anthropic, OpenAI, Google, xAI) to generate responses, under their terms. When a discussion runs on our keys it may be routed through OpenRouter, which forwards it to the same provider and reports the exact cost back to us. A credential in a message or a file (an API key, a token, a private key, the password in a database URL) is replaced by a placeholder before it leaves, on every plan, and is never put back; the receipt says how many were masked.
  • Paddle for payments, as above.
  • Google, Microsoft or Apple when you sign in; they tell us who you are and nothing about your discussions.
  • Hosting: our servers run on Fly.io and our database on Neon, both in the United States (Virginia). Customers who put other people’s data into the service are covered by our Data Processing Agreement, which lists every subprocessor. Downloads and app updates are served from object storage that holds no personal data.
  • Product analytics: a team can switch product analytics off for all its members on Settings → Team, and every client honours it. Otherwise we use PostHog (hosted in the United States) to see how the web app is used. It receives your email address and plan, a short list of named events (signed in, discussion started or finished, an answer exported, a discussion shared, a page published, a teammate invited, a paywall reached, an upgrade), page views, and session recordings of the web app in which every input field and all discussion text is masked. Discussion content, titles, file names and commands are never sent. Requests go to our own host and are forwarded from there.
  • Apps you connect: if you connect LetThemChat to ChatGPT, ChatGPT sends us your question and receives the results you request. Nothing is shared with such an app beyond what you ask for in it.

We do not sell personal data, do not use it for advertising, and do not use your content to train models. Because our servers are in the United States, your data is processed there wherever you live.

On your own device

The desktop app stores sessions, terminal output and any coding-CLI credentials on your machine, in your user folder; none of it is sent to us unless you sign in and sync. The iPhone app caches recent discussions on the device, protected by the device’s encryption. The iPhone app contains no analytics or advertising trackers. The desktop app sends nothing about how you use it unless you switch on Share usage with LetThemBuild in its General settings; then it reports that a run started or finished (its mode, seat count and duration, nothing else) to the product analytics above, where it is attached to your account. The desktop app contacts letthembuild.com to check for updates.

Cookies

The web app sets one cookie, which keeps you signed in; signing in also sets the short-lived cookies that protect the sign-in itself. There are no advertising or third-party cookies. Product analytics runs only after you accept it in the prompt each site shows on your first visit, and keeps its state in your browser’s local storage, not in a cookie; declining loads nothing and removes what an earlier visit left. You can change your answer here at any time.

How long we keep it

Account data, discussions, credentials and team data stay until you delete them or your account. Operational records expire on the schedules above. Billing records are kept for as long as tax and accounting law requires. Deleted data is removed from our database immediately and from backups within 30 days.

Your choices and rights

  • Disconnect any AI provider at any time; its stored credential is deleted immediately.
  • Delete discussions from within the app; deleting a chat removes its messages and attachments.
  • Leave a team, or as owner remove members and cancel invitations, from the Team settings.
  • Revoke a connected app (such as ChatGPT) from Settings or from that app; its tokens stop working.
  • Delete your account from Settings in the web app or the desktop app. This removes your discussions, credentials, team membership and connected apps at once. From the iPhone app, or if you cannot sign in, email us and we will do it for you.
  • Wherever you live, you can ask us for a copy of the personal data we hold about you, to correct it, to delete it, or to object to how we use it, by emailing [email protected]. We answer within 30 days. If you are in the UK or EU you can also complain to your data-protection authority.

Children

The products are for people aged 18 and over. We do not knowingly collect data from anyone younger; if you believe we have, email us and we will delete it.

Security

Credentials are encrypted at rest, all traffic uses HTTPS, and access to production systems is limited to the people who run them. Vulnerability reports go to [email protected]. If a breach affects your data we will tell you without undue delay.

Changes

When this policy changes we update the date at the top; for a material change we also tell you by email or in the app before it takes effect.

Contact

GPULogy AI LLC — questions, access and deletion requests: [email protected]