By default, Duck.ai does not record or store any of your chats, and your conversations are not used to train chat models by DuckDuckGo or the underlying model providers (for example, Open AI and Anthropic). You can choose to share a conversation with us when providing feedback, in which case we store and review it to improve our products. And if you use Sync & Backup, or certain other optional features, your chats are stored in an end-to-end encrypted format that we can’t read.
All chats are anonymized by DuckDuckGo. Metadata that contains personal information (for example, your IP address) is completely removed before prompting the model provider. This means requests to Anthropic, OpenAI, Mistral, Azure, and Tinfoil appear as though they are coming from DuckDuckGo rather than individual users.
In addition, we have agreements in place with all model providers that further limit how they can use data from these anonymous chats.
All Duck.ai model providers agree to:
- Delete your prompts and responses immediately after generating a reply (called Zero Data Retention or ZDR)
- Never use your Duck.ai conversations to train their models
- Never share your data with third parties who may use it for their own commercial purposes (this does not include subprocessors acting on behalf of the model provider)
We allow limited, clearly defined exceptions to these requirements, and we document all of them here.
Provider | Models Available | ZDR | Training Prohibited | Retention Exceptions* |
Tinfoil | · GPT-oss 120B (free) · Gemma 4 31B (free) | ✔️+ | ✔️+ | None |
Mistral | · Mistral Small 4 (free) | ✔️ | ✔️ | None |
Azure | · OpenAI models (backup) · Anthropic models (backup) | ✔️ | ✔️ | None |
OpenAI | · GPT-5.4 (Plus) · GPT-5.4 nano (free) · GPT-5.4 mini (free) | ✔️ | ✔️ | · Prompt caching: Chats may be held in short-term memory for up to 1 hour to reduce token costs and speed up responses; never written to disk · For voice chats, see Voice Chat and Dictation Privacy |
Anthropic | · Claude Opus 4.8 (Pro) · Claude Sonnet 4.6 (Plus) · Claude Hailku 4.5 (free) | ✔️ | ✔️ | · Prompt caching: Chats may be held in short-term memory for up to 1 hour to reduce token costs and speed up responses; never written to disk · Chats may be retained where required by law or as necessary to combat malicious use |
* All uploaded images and files are scanned for child sexual abuse material (CSAM) by a third-party content moderation provider and, in some cases, the model provider. Images and files are not retained unless flagged as CSAM, in which case they are retained and reported to the relevant authorities (see section below for more details).
+ Tinfoil has the added benefit of using a Trusted Execution Environment, so we are able to ensure, via technical means, that they are unable to read, retain, share, or train on your prompts, responses, or uploads.
Zero provider visibility chat models
Requests to Tinfoil (which hosts gpt-oss-120b and Gemma 4 31B on their servers) are anonymized and, additionally, are processed in a Trusted Execution Environment such that Tinfoil cannot see your prompts or the model’s response. Chat models that support this (currently, gpt-oss-120b and Gemma 4 31B) are labeled "zero provider visibility" in Duck.ai.
You can read the Duck.ai Privacy Policy and Terms of Use here.
How we analyze anonymous chat data
We never store your prompts or any information that could reveal the contents of your conversations (except when you explicitly choose to share a conversation with us when providing feedback). Instead, we use a privacy-preserving system to store anonymous data that allows us to analyze aggregate patterns in Duck.ai chat activity to help understand how the product is being used and where we can improve it.
When you send a message, our servers compute a mathematical representation of it (called an embedding). We use that to match your prompt to a representative prompt from an open-source dataset of chatbot conversations. The embedding of your prompt is held in memory only—never written to disk—and discarded immediately after matching. The matched open-source prompts are what we retain long-term and use to understand aggregate patterns in chat activity.
We also collect aggregate statistics about chat interactions, such as the number of messages in a session, tokens used, or features used. We use this data to monitor performance and understand how Duck.ai is being used. This data is fully anonymized and cannot be connected to any individual user.
How we moderate uploaded images and files
To detect child sexual abuse material (CSAM), images and files you upload are anonymously checked by a third-party content moderation provider, and in some cases, the model provider. No identifying information, other than what might be contained in the uploaded image or file itself, is shared with the content moderation provider (for example, your IP address is not shared). Only uploaded images and files are processed in this way, not text prompts or model responses. Uploaded images and files are not retained unless they are flagged as CSAM, in which case they are retained and reported to the relevant authorities.
This process applies to all models, including those served through Tinfoil. Tinfoil processes prompts and generates model responses in a Trusted Execution Environment, which prevents them from viewing prompts, responses, or uploaded images and files. To perform content moderation in this architecture, your uploaded images and files are sent to the third-party content moderation provider outside of the encrypted channel.