Skip to content
After2AM
โ† After2AM

Privacy Policy

Last updated: July 29, 2026

1. Services currently public

AI chat and account features are public. Premium billing and newsletter delivery are not enabled. Drafts without human approval stay outside search.

2. Chat and account data

Ordinary chat messages are sent to the configured DeepSeek model service to generate a reply. The crisis-keyword branch returns a local safety response from this server and does not call the model service.

Recent conversations are stored in Redis on this server to provide context. The default maximum retention is 24 hours for visitors and 7 days for registered users. Long-term Memory is currently disabled.

When an explicit crisis phrase is detected, a signed safety token containing no chat text or user ID is stored in this browser's sessionStorage for at most 45 minutes, so ambiguous follow-ups from the same browser continue to receive safety guidance. Recent chat text is not displayed automatically; the user chooses to continue or clear it.

Accounts store an email address, a bcrypt password hash, and secure session state. Users can delete their own account, which also clears user-level cached data.

3. Analytics choices

Umami hosted on this server loads only after you explicitly accept. It does not load if you reject or enable Do Not Track. You can reopen the setting from the footer. Analytics data is deleted after at most 180 days.

Only after a registration-complete event was actually sent with consent, this browser stores a schema version, the UTC registration day, and D1/D7 sent flags. Only on the next UTC day (D1) or days 6โ€“8 (D7), the browser checks sign-in status through same-origin /api/me and sends one retention_return event for that window if authenticated. No retention event is sent outside those windows.

  • Self-hosted Umami processes anonymized pageviews and fixed events, plus anonymous technical statistics such as browser family, operating system, device type, and coarse country. The source IP may be used to derive location but is not stored by Umami; we do not add email, user IDs, or other personally identifying data.
  • Page URLs are reduced to the groups home, chat, premium, account, articles, trust, or other, and Nginx strips the Referer. We do not send searches or query strings, article slugs, chat text or length, sensitive classifications, or free-text input.
  • After consent, chat measurement is limited to fixed events for ready, send, first-token time bucket, completion, failure category, third completed turn, stop, and temporary-session continue/clear. It contains no text, length, topic, or safety classification.
  • There is no retroactive tracking before consent, advertising signal, or identifying session ID.
  • The local retention record and event contain no email, account or user ID, article slug, search query, chat content or length, health information, or crisis information. The local record contains only its schema version, UTC cohort day, and D1/D7 sent flags. It is cleared when consent is withdrawn, Do Not Track is detected, or on the next check after the measurement window.

4. Technical and security logs

Hosting and security systems may process standard operational logs such as request time, requested path, browser information, and network information needed to operate and protect the service.

5. Contact channel

After2AM does not currently publish a dedicated privacy contact channel. Until a verified form or email address is listed here, do not submit passwords, session tokens, payment information, health information, or other sensitive data to this site.