The rules we won’t change quietly.
Four principles about how we handle your data, plus the specific subprocessors we rely on and what they see. If any of this changes we’ll tell you first — before we update this page.
Chats are never used for training.
Not opt-out, not conditional, not 'up to'. Off by default for every subscriber on the Anthropic API tier we use. If this ever changes, we tell you first and offer to cancel with a pro-rata refund.
We store the minimum.
Your email, hashed password, and Stripe customer ID. Your chat history, server-side encrypted at rest so you can find it in the sidebar. No phone number, no address, no birthday. No third-party analytics, no marketing pixel, no A/B testing cookies.
Cancel and it's gone.
Cancel your subscription and email us — we delete the account, the chat history, and any residual logs within 30 days. Anthropic's separate retention window on API traffic applies to inference; check their published policy for that timeline.
We publish incidents.
If we have a security issue that touches customer data, we'll publish it on the blog with what happened, what we did about it, and what we changed. Not a template response — an actual write-up.
Where your chat actually goes.
A single chat message travels through three companies before you see the response. Every hop is TLS. Your message and the response are stored server-side in our Postgres (encrypted at rest) so you can find the chat later; Anthropic’s inference infrastructure sees the message ephemerally.
We do not run our own AI models. There is no scenario where the message you send us gets used to train a “LADLE model” because no such model exists. Anthropic’s policy on their API tier is that customer data is not used for training. If Anthropic ever changes that, we surface it here first and offer cancellation.
For everything else — payment, email, static hosting — see the subprocessor list below.
Every company that touches your data.
What we defend against — and what we don’t.
- ●Account takeover (credential-stuffing, session-hijacking)
- ●Data leakage between subscribers (IDOR, misconfigured RLS)
- ●Server-side injection / XSS in our web app
- ●Compromise of our infrastructure via a subprocessor breach
- ●Payment fraud abuse (subscriptions created with stolen cards)
- ●Denial of the meal-ledger publish pipeline (integrity)
- ○Physical attacks on your unlocked device
- ○Social engineering of individual subscribers
- ○Traffic-flooding DoS on public endpoints (Cloudflare handles that layer)
- ○Vulnerabilities in Anthropic's inference API (report to Anthropic directly)
- ○'What if the government seized your database' — see the data-flow diagram
For security reports and coordinated disclosure, email privacy@ladle.chat. We aim to respond within one business day. Critical issues (active exploitation) — put [URGENT-SECURITY] in the subject and we escalate immediately.
For everything else — data export, deletion, general privacy — hello@ladle.chat gets a real person.
Full privacy policy →Trust starts with what you don’t have to worry about.
No training on your chats. Delete anytime. Publish incidents.