Effective August 29, 2026

Privacy at garlic.ai

This notice explains what Garlic can see, what stays on your device, which service providers process data, and the choices available to you.

Browser chat

You can use browser chat without an account. Supported prompt and attachment content is encrypted in your browser before it crosses Garlic’s application edge. Garlic can still observe routing, timing, selected model, protocol metadata, and ciphertext size.

Saved chats are encrypted by your browser and stored in IndexedDB on the current device. Vanish chats remain in memory for the current tab. Garlic does not sync either transcript mode to its servers.

Information we process

  • Account information, such as your email address and profile details, when you choose to sign in.
  • API request metadata, including account or organization identity, credential identifier, endpoint, model, privacy mode, status, token totals, latency, and estimated cost. Garlic retains this ledger for up to 30 days.
  • Billing records needed to sell and administer prepaid API credits.
  • Coarse product events such as chat starts, response outcomes, model choice, and whether a feature was used. Analytics excludes prompts, responses, search queries and results, filenames, chat identifiers, URLs, referrers, raw errors, IP addresses, and browser user agents.
  • Messages you send to our contact address and the information needed to respond.

Search and rate limits

If you enable web search, the query text is sent through Garlic to Exa. Garlic drops cookies, user agent, referrer, and other request headers before that request and does not store or cache the query or results. Client IP addresses are used in memory for abuse limits and are not persisted by Garlic’s limiter.

Service providers

Garlic uses service providers for specific parts of the service:

  • Cloudflare for hosting, delivery, and network protection.
  • PrivateMode for confidential AI inference.
  • WorkOS for optional sign-in and API-key identity.
  • Autumn and Stripe for API billing and payment processing.
  • PostHog for the restricted, cookieless analytics described above.
  • Exa for optional web search.

Garlic does not sell personal information or use it for targeted advertising. Providers process information only for the functions described here and under their own privacy terms.

Your choices

  • Use browser chat without creating an account.
  • Keep web search off when you do not want a query sent to Exa.
  • Delete saved chats or clear Garlic’s site data in your browser.
  • Enable Do Not Track or Global Privacy Control to disable Garlic’s product analytics.
  • Ask to access, correct, or delete account information by emailingcontact@garlic.ai. We may need to verify your identity before acting on a request.

Retention, security, and changes

Account, billing, and support records are kept only as long as needed to provide the service, meet legal obligations, resolve disputes, and prevent abuse. Garlic uses technical and organizational safeguards, but no online service can guarantee absolute security.

Material changes will be reflected on this page with a new effective date. Questions about this notice can be sent tocontact@garlic.ai.