Privacy
AskSami privacy
What AskSami keeps about you and your product, where it is kept, who else handles it, and how to delete it. Ancestorii Ltd, trading as AskSami, is responsible for it. Questions go to support@asksami.app.
Last updated 18 September 2026
1. What AskSami stores
- Your account. Your name, your email address, how you sign in and, if you use GitHub, Google or Apple, the profile details it passes on (such as your username and the link to your profile picture), the IP address and browser of each signed in session, your time zone and your settings. When you sign up, AskSami also records which page and link you arrived from, any campaign tags on that link, and the page you first landed on and when, or only that you came direct if nothing sent you to the front page, to know which channel brought you; they travel in the page addresses, and no cookie or browser storage is used for them.
- What you told Sami while setting up. What you built, its address, who it is for, where you are stuck and what makes it different, Sami’s replies, and the files, links and Stripe, Paddle or Lemon Squeezy webhook secrets you added. If you never pay, all of it is kept exactly as you left it for thirty days from the last time you touched it and then deleted, and sooner than that if you start setting up again.
- What Sami reads in your code. Facts, each with a short quote and the path of the file it came from, and the names and versions of the files it read. Not your whole code. The full text of a file, or of the changes in your folder, is kept only when Sami opens it from your repository or the terminal command sends it (which it does when you ask and whenever Sami asks), and then it is kept in that chat.
- Your live site. Facts from its pages, each with the page’s address. Web pages and search results Sami reads for you in a chat are kept in that chat.
- What you give Sami. The files you upload, as you sent them, and the figures read from screenshots and CSV files. The links you paste, with the title, author, text and counts read from them.
- Numbers from your product. What the eyes send (signups, clicks, drop offs and your own events, each with where the visitor came from, a random visitor id and any small details your code adds, and no IP address) and what your Stripe, Paddle or Lemon Squeezy webhook reports (amounts, currencies, that service’s customer, order and subscription ids, and any lead id your code stamps on them, not your customers’ names or emails).
- Every chat, in full. What you, the person you invite and Sami wrote, and the files, changes and web pages brought into it.
- What you and Sami work out. Your decisions, your honest read and plan, your channels, what Sami learns about your audience, and your morning briefs. Sami’s memory is never edited and never deleted by Sami: a correction is added and the old record kept, and the memory goes only when the account is deleted.
- Billing and use. Your plan, your Stripe customer and subscription, a record of every AI call made for you once you have paid, with what it used of your allowance, and the credits you bought.
- The rest. The email addresses of people you invite, your terminal tokens and the name of the folder each was last opened in, your GitHub App installation and the repositories it lets AskSami reach (never a GitHub token), and a record of the emails AskSami sent.
2. Where it is kept, and who handles it
AskSami stores all of this in Supabase, in the EU (Ireland). These companies handle parts of it for AskSami, some of them outside the UK and the EU, including in the United States:
- Anthropic: the AI models behind Sami. What you write to Sami (your onboarding answers too, before you pay), what Sami reads, your name and email address, and the email address of anyone you invite go to Anthropic so Sami can answer. Sami’s web searches and page reads run through Anthropic as well.
- Stripe: payments. AskSami sends Stripe your email address and your account id. Your card details go to Stripe and never reach AskSami.
- Resend: sending the emails AskSami writes to you, and the invitations you send.
- GitHub: the AskSami GitHub App that reads your repository, and sign in, if you choose GitHub.
- Trigger.dev: the background jobs that read your code and site, write your honest read and plan, and write your morning brief.
- Vercel: hosting the website and the app.
- Supabase: the database, sign in and file storage.
- Kickbox: checking that an email address can receive mail when you sign up with one. It gets the address before the account is made.
- Google and Apple: sign in, if you choose them.
When Sami reads your site or a link you paste, AskSami’s servers fetch the page from that site.
3. Secrets
- Your Stripe, Paddle and Lemon Squeezy webhook secrets are stored encrypted, the Lemon Squeezy one whether you chose it or Sami made it for you. A Lemon Squeezy secret Sami makes is shown to you once, in the reply that hands it over, and the chat keeps a note in its place.
- Eyes keys, terminal tokens and invitation links are stored as hashes, which cannot be read back. The one exception: an eyes key Sami gives you in a chat also stays in that chat, like everything said there.
- Files that hold secrets by their nature, such as .env files and private keys, are never read from your repository or sent from your terminal.
- In other files Sami reads from your repository, and in the files and changes your terminal sends, anything that looks like a key or a password is blanked before it is kept or shown to Sami. Files you attach, on the platform or with /attach, are kept as you sent them. Blanking catches the usual shapes, not every one, so keep secrets out of your code.
- A Stripe or Paddle API key, an API token, or a webhook secret, pasted into a chat is taken out before the message is kept. Anything else you type is kept as you typed it, so do not paste passwords or other keys.
4. Your data stays yours
Nothing from your project is shown to or used for any other account. Sami’s own knowledge comes from AskSami’s playbook and notes, not from other people’s projects. AskSami does not train AI models on your data.
The person you invite works in your account and sees your projects, as the Terms say.
5. Deleting your account
The account owner can delete the account from the Account page. It asks twice, and the second time you type DELETE. It cannot be undone.
Deleting cancels your plan at once, removes every file you gave Sami, and then deletes the account and all its projects with everything in them: your answers, facts, chats, numbers, decisions, memory, tokens, invitations and the record of emails sent. The person you invited loses access, and you are signed out.
Someone invited into another account can leave it from the Account page instead. What they wrote stays in that account’s chats. If you cannot reach the Account page, because you never paid or you left someone’s account, write to support@asksami.app from your account’s email address and ask for your account to be deleted.
Some things live outside AskSami. Stripe keeps its own record of your payments. Emails already sent stay in your inbox. The AskSami GitHub App stays installed on your GitHub account until you uninstall it there. If you added the eyes to your product or pointed a Stripe, Paddle or Lemon Squeezy webhook at AskSami, they keep sending until you take them out, and AskSami refuses and keeps nothing they send. Our providers keep their own service logs for a limited time.