Who to contact
This notice covers the WormGPT website, accounts, chat and frontend projects. For privacy questions or requests, contact the WormGPT operator through @mrzxn on Telegram. Website accounts and the Telegram bot use separate account stores. Telegram use is also subject to Telegram’s own privacy practices.
Information processed
The service stores an account identifier, account creation time, a Telegram identity link, hashes of legacy login keys and one-time login proofs, session records, plan status and prompt allowances. It processes chat messages, AI replies, uploaded text or images, generated files, saved projects and request metadata such as status, timestamps, token usage and reported provider cost. Security and operational information can include IP addresses, browser request details, rate-limit records and administrator audit entries. You do not need to provide an email address or password to create a website account.
Why it is used
Information is used to authenticate your account, generate replies and files, preserve conversations and projects, enforce plan limits, activate purchased keys, troubleshoot failures, prevent abuse and respond to support requests. Where applicable privacy law requires a legal basis, service delivery relies on providing the service you request; security and operational processing serves legitimate interests subject to your rights; legal obligations or valid consent may apply to specific processing.
AI providers and other recipients
Prompts, relevant conversation context and attachment content are sent to the AI provider configured by the operator. The app supports OpenRouter, Hugging Face and Notrack; an OpenRouter request may also be handled by its selected model provider. Provider retention and use of submitted content depend on the selected provider and its terms; this service does not promise zero retention or that third parties never use content for training. Avoid sending secrets or personal information you do not need to share. Hosting operators process network traffic and may maintain logs. Public signup/login uses Cloudflare Turnstile for abuse prevention. Google Fonts loads the site’s typefaces and receives connection information. Telegram processes bot sign-in messages and one-time codes. The service uses the authenticated Telegram user ID to connect website and bot accounts; the bot may also retain the username, first name and last name supplied by Telegram. After sign-in, the website fetches your available Telegram profile photo, stores an encrypted resized copy, and displays your Telegram name, username and photo in your own workspace. Photos are refreshed at sign-in and removed with website content deletion. If a photo is unavailable, your initial is shown. The website never requests your Telegram password or phone number. Providers may process information in other countries; contact the operator for the current provider and processing locations.
Web research and image analysis
When you use Pro web research, the query is sent through OpenRouter to its search provider. Pro image analysis sends the uploaded image to the configured vision provider. Results and extracted references may be saved in your conversation. Only attach content you intend to share with these services.
How long information remains
Saved website conversations and projects remain until deleted by you or the operator; there is no automatic chat-history expiry in the website. Uploaded attachment records expire after 24 hours and are cleaned up on subsequent uploads; excerpts already saved in a chat remain with that chat. Generated previews expire after ten minutes or replacement. Login sessions expire after seven days; security-check and owner-session lifetimes are listed in the Cookie Policy. Usage, license and audit records may persist for account administration and security. Deleting a website account removes its website chats, sessions, uploads and projects. The shared Telegram identity link, subscription, usage reservations and security ledger remain for billing and abuse prevention; recreating a website account does not reset the Free allowance. Contact the operator about identity or retention requests. Hosting logs, backups and independent provider copies may follow separate retention arrangements; ask the operator about those arrangements.
Your controls and requests
Account settings let you export conversations and saved projects, connect Telegram, switch an active Pro subscription between Free and Pro modes, and delete your website content. Individual chats and saved projects can also be deleted. Browser settings control local storage and cookies. Depending on applicable law, you may have rights to access, correct, delete, restrict or object to processing, obtain portable data, withdraw consent where processing depends on consent, or complain to your local data-protection authority. Send other requests to @mrzxn on Telegram; account ownership may need to be verified. Never send your full login key in a support message.
Security and limitations
Login keys and session tokens are hashed in the server database. HTTPS is required for public hosting, and account data is protected by authentication and access checks. Website chat content, saved project content, uploaded content and preview documents are encrypted at rest. Retained bot conversation bodies and saved replies are also encrypted at rest. Account and usage metadata remains available for administration. This is not end-to-end encryption; authorized service operators and processors may be able to access them. No system or transfer is guaranteed to be completely secure. Keep downloaded keys and exported files private.
Changes to this notice
We update this notice when the website’s practices change and show the revision date above. Contact the operator before sharing information if you need clarification about a provider, retention period or privacy right.
Connected account access
New website accounts sign in through our Telegram bot with a browser-bound, one-time code. Login challenges expire after ten minutes and are cleaned up when new challenges are created. Where legacy key login is enabled, existing account keys can open an unlinked account until it is connected to Telegram. The standard VPS setup requires Telegram sign-in. Afterwards, Telegram sign-in replaces key-based login. Five Free prompts per 24 hours are shared between the website and bot; paid access and administrative blocks also apply to both.