Simon Aitchison
Paintscape.Photography AiRT+
Back Ai+RT Lounge
Transparency Report — May 2026

Your data.
Your control. Always.

We built AiRT with one rule: you should be able to see exactly where every piece of information goes, who can see it, and how to get it all back at any time.

Section 1

What happens when you type something?

Here is the exact path your message takes — from your keyboard to the AI and back. Nothing hidden.

Your Message Flow — Step by Step
⌨️
You Type
Your device only
🔒
HTTPS Encrypt
TLS 1.3 — locked in transit
🤖
AI Model
OpenAI / Claude / Gemini / Grok (xAI) API
💬
Response
Back to your screen
🗑️
Session Ends
Conversation cleared
AiRT does not store your conversation content. When your session ends, it's gone from our system.
What AiRT Stores vs. What It Doesn't
Data Type Stored? Where Who Can See It
Your conversation content Not Stored Nowhere — session only Nobody
Your name or email Not Stored Not collected Nobody
Your AI API key (if you add one) Your Browser Only Local storage — never sent to our server Only you
Page visit (anonymous) Anonymous Only Our server — no personal ID Simon (site owner) only
Your device type / browser Anonymous Only Analytics DB — no name attached Simon (site owner) only
Payment information Never Touched Processed by Stripe only — we never see it Stripe (third party) only
Contact form messages Stored Encrypted on our server Simon (site owner) only
Section 2

How secure is this, really?

We measure security across 8 categories. Here is our current score — updated in real time.

HTTPS / Encryption
100%
No Personal Data Stored
100%
Brute Force Protection
100%
SQL Injection Blocking
100%
Rate Limiting
96%
Security Headers
92%
API Key Isolation
100%
Payment Security
100%

Overall Security Score

Data Stored vs. Not Stored

⚠️ Important Note: AiRT uses four AI providers: OpenAI (GPT-4.1), Anthropic (Claude), Google (Gemini 2.5 Flash), and xAI (Grok). While we do not store your conversations, these providers have their own data policies. We strongly recommend using the Clear Memory function after sensitive conversations, and reviewing OpenAI's privacy policy, Anthropic's privacy policy, Google's privacy policy, or xAI's privacy policy if you have concerns. You can always use your own API key (BYOK) for maximum control.

Section 4

Our pledge to you.

The AiRT Privacy Pledge — May 1, 2026

We will never sell your data. Not now, not ever. Your information is not a product. AiRT makes money from sessions, not from you.
We will never store your conversations. What you say in an AiRT room stays in that session. When you close it, it's gone from our system.
We will always tell you what changed. If our privacy practices ever change, you will receive an email before the change takes effect.
You can always get your data out. Your backup file is always available. You are never locked in.
We will proactively report security concerns. If we ever detect anything unusual, you will be notified immediately — not after the fact.