consens.io
Product Watches Topics Questions Benchmark Open app

Data handling

Privacy Notice

Short and clear: how consens.io handles prompts, provider calls, account data, and local settings.

Important note

consens.io compares answers from multiple AI models. Please avoid entering personal, confidential, or sensitive information in prompts. Model providers can process the content you send to them.

1. Controller

Max Plack
Lutherstraße 79
30171 Hannover
Germany

Email: contact@consens.io. Also see the Imprint. The project is privately operated in Germany and currently not monetised.

2. Purposes and data we process

  • Prompts and model outputs in the web app: used to provide the service, send requests to selected AI models, and display answers. Signed-in Consensus conversations are automatically stored in Google Cloud Firestore, including questions, model answers, consensus, differences, sources, conversation context and attachment metadata. The app also automatically saves the associated sidebar bookmark. This does not require a separate Save action. Follow-up questions reuse stored conversation context, which may be condensed by an additional AI call. These records remain until you delete the conversation/bookmark or your account; there is no general automatic chat-expiry period. A separate temporary result for sharing expires after 24 hours and is removed by periodic cleanup, independently of the saved conversation.
  • Consensus API runs: the administrator-issued Consensus API stores the submitted question, server-selected model plan, model outputs, consensus, differences analysis, status, and timestamps in Firestore so clients can retrieve asynchronous results and safely retry requests. API-run content and its idempotency mapping expire 30 days after acceptance and are removed by periodic cleanup; clients can delete completed runs earlier. API keys are stored only as a SHA-256 hash plus a short non-secret display prefix and audit timestamps. During account deletion, a minimal UID-bound block record may be retained temporarily if cleanup must be retried.
  • Technical requests and logs: your IP address, requested resource, connection/browser information and time are processed to deliver pages and protect the service. Application diagnostics use content-free error categories, counts and timings. Hosting infrastructure may keep separate access logs; the absence of IP addresses from our application database does not mean that infrastructure providers never process them.
  • Attachments: files or extracted text are processed in server memory and sent to the model endpoints needed for your request. File bytes are not saved in Firestore. File names/types and any file contents quoted or summarised in saved answers can remain in conversation records or published content.
  • Account data: if you sign up, your e-mail address and a user ID are processed via Google Firebase Authentication (including optional Google Sign-In) for access control, quota handling, and related usage features. Your tier and saved bookmarks (query, answers, sources, attachment metadata) are stored in Google Cloud Firestore until you delete them or your account.
  • Your memory (optional profile and notes): in Settings you can write a short profile about yourself (who you are, what you work on, how you want answers written, constraints that always apply) and a longer manually maintained memory note. It is stored on your account in Google Cloud Firestore and is added to the instruction sent to every model you select for a run, so those model providers receive it with each question. Nothing is derived, summarized, or rewritten automatically from your questions or from model answers. If you explicitly select a statement in an interactive question, Consensus, or model answer and submit a “Remember” or “Correct memory” action, we send the current Memory (up to your plan limit), the selected statement, your text, and the selected add-or-correct intent to the configured model through OpenRouter. It may return only one structured replace, append, or delete proposal; our server validates and applies it. A Remember action may append or replace one uniquely matching passage but cannot delete one. We store an idempotency record, persistent usage counters, and the previous Memory revision for Undo. The Undo time limit limits the action, not the storage lifetime of revision records; those records remain until account deletion. These records and revisions are never used for Watch, Publisher, or Topic runs and are deleted with your account. Only text you enter in Memory settings or explicitly submit through Remember or Correct memory is stored and used. You can edit it, pause it with a single switch, or clear it at any time; it is deleted with your account. Scheduled Watch reruns do not receive your Memory profile as a separate input, and published pages do not display it as a profile field. However, generated answers or questions can reflect personal details from Memory; review content before publishing it. Please do not enter special-category data (for example health, beliefs, or political opinions) or other people’s personal data.
  • Abuse prevention and usage: IP-based rate limits and account-bound counters prevent overload and quota abuse. We store usage, tier, request-idempotency and vote records, but no IP-to-account registration mapping. Model-ranking votes are bound to your account internally; the public ranking contains aggregate model counts.
  • Feedback: if you send feedback, we store your message, the e-mail address you optionally provide, your account ID, and a timestamp, for as long as needed to follow up on the feedback.
  • Earlier interest requests: records from the former Pro-interest feature can contain account ID, email and timestamp. The current app no longer offers that submission. Existing records are removed with account deletion or on an erasure request where no overriding retention ground applies.
  • Browser storage and cookies: Firebase uses browser storage to maintain your requested login, with session-only storage as a fallback. A first-party HttpOnly session cookie for protected pages expires after one hour or is removed on logout. Local/session storage also holds interface and model preferences, feature flags and, if entered, your OpenRouter key. Persistent settings remain until changed or cleared in the app or browser. Storage/access strictly necessary for a service you expressly request is based on § 25(2)(2) TDDDG; related personal-data processing uses the GDPR grounds below. Rejecting or clearing browser storage can prevent persistent login or settings.
  • Your own OpenRouter key, optional: if you enter it, the key is stored in your browser only. With each request, it is transmitted over an encrypted connection through our server to OpenRouter to authenticate your model requests. We do not store your key on the server.

3. Usage analytics with Umami

We use Umami Cloud for privacy-focused web analytics. Umami records page views and selected interaction events so we can understand which parts of consens.io are used, improve the product, find friction, and prevent abuse. The tracker is configured to respect browser Do Not Track signals and to exclude URL search parameters and hash fragments.

Umami may process technical usage information such as visited pages, referrer, browser, operating system, device type, approximate country, timestamps, and the custom events listed below. Umami states that its tracking code does not use cookies, anonymizes collected data, and does not identify users across websites.

The custom events we track are limited to product usage signals: landing-page calls to action, opening or using the app, sending or cancelling a query, completing a model run, generating or cancelling a consensus, copying a consensus or citation, changing interface modes, model selection changes, sidebar section opens, settings/help/feedback actions, login/register/password-reset/account-deletion attempts and outcomes, bookmark save/open/delete actions, API-key test outcomes, and Pro-interest clicks.

Event properties are limited to non-content metadata, for example selected mode, number of selected models, provider or model label, status, trigger type, and boolean states such as logged-in, own-keys, Agent Mode, or Auto Consensus. We do not send prompts, model answers, consensus text, feedback message text, e-mail addresses, passwords, authentication tokens, API keys, bookmark contents, or other user-entered content to Umami as custom event data.

Legal basis: Art. 6(1)(f) GDPR, our legitimate interest in measuring aggregate product usage, improving the service, maintaining security, and prioritizing development. You can object to this processing under Art. 21 GDPR using the contact details above. To disable tracking in this browser, turn off Umami tracking. This saves a local opt-out preference; clearing browser storage removes that preference. You can remove the opt-out at any time. The tracker also respects browser Do Not Track signals.

4. Provider routing

Model requests go through OpenRouter, Inc. (USA). Available model families include OpenAI, Anthropic/Claude, Google/Gemini, Mistral, xAI/Grok, DeepSeek, Moonshot AI/Kimi, Z.ai/GLM and Meta/Muse. A model developer is not necessarily the company hosting the endpoint: OpenRouter can route the same model to different infrastructure providers.

Depending on the feature, requests include your question, instructions, enabled Memory, attachments, earlier conversation context, model answers and sources. Consensus, Differences, coverage checks, dispute resolution, context preparation and explicit Memory edits can involve additional configured models beyond the comparison models. Scheduled Watches and API runs use server-configured models. Deselecting a comparison model therefore does not exclude every possible processing endpoint.

Our inference requests set OpenRouter's Zero Data Retention routing option. According to OpenRouter's ZDR documentation, this limits inference routing to endpoints with a non-retention policy. It is not a promise that every service keeps no data: temporary in-memory prompt caching is permitted, operational metadata is separate, and web-search tools are outside this routing guarantee. OpenRouter's own optional content logging also depends on the account's settings.

Model runs can use OpenRouter's web-search tool. Search terms derived from your input may reach the selected search service, including Exa or native search services. Their processing and retention are separate from inference ZDR.

There is no EU-only endpoint restriction. Processing can take place outside the EU/EEA, including the USA and, depending on the actual endpoint, Singapore or China. Model labels alone do not identify the country of processing. Do not submit confidential information or sensitive personal data. This precaution does not replace our own data-protection obligations.

5. Shared pages (public sharing)

If you publish a consensus answer as a public shared page (an explicit, opt-in action in the app), we store the shared content (question, consensus answer, differences analysis, sources, and model names) together with your internal account ID. The account ID is used solely so that you can manage and revoke your own shared pages and so that we can fulfil our moderation duties; it is never displayed publicly and never embedded in the public page.

Shared pages created through the Share action are public: anyone with the link can read them, and selected pages may appear in search engines through operator-controlled indexing, including automated publication of operator-configured Publisher/Topic content. Watch pages can instead be private. A private Watch page is available only to its creator while signed in, is never submitted for indexing, and is not shown as a related page. Please do not include personal data in content you make public.

Visitors can report a shared page ("Report this page"). The report record contains counters per reason, without a reporter account, IP address or browser data. The HTTP request is still subject to ordinary technical processing and rate limits.

If you enable Consensus Watch, we periodically rerun only the original question using a limited set of models. We store compact history points (date, agreement score, verdict, and a short change summary) next to the selected public or private Watch page, but not the full rerun model responses. You can choose service notifications for material changes, for every successful new consensus, or when a condition you enter is met. The selected local run time and time zone are stored with the Watch schedule. Conditions are stored with the private Watch settings and evaluated against each newly generated consensus by an AI judge; they are not displayed on public pages. A condition notification is sent when the result changes to “met”, not repeatedly while it remains met. Result notifications may include the generated consensus text. Repeated failures may also trigger a one-time pause notice. Every watch e-mail includes a signed link that pauses the watch without requiring login.

Optional Telegram delivery: Signed-in users may voluntarily connect a private Telegram chat and enable Telegram separately for individual Watches. For this purpose we store the Telegram chat and user identifiers, the public Telegram username/first name supplied by Telegram, connection status and minimal delivery metadata. The one-time account-link token expires after ten minutes; expired token records are removed by regular maintenance. Telegram receives the alert text required for delivery (question, agreement score and change summary or generated consensus) and callback data for actions such as mute or pause. We do not read unrelated Telegram chats or use Telegram data for model training. Disconnecting removes the account mapping; account deletion also removes pending links and delivery metadata. Delivery metadata is otherwise automatically removed after 90 days. Telegram's own processing is governed by its privacy policy.

Following a public Watch page (visitors): Visitors can subscribe to change notifications for a public Watch page or Topic by entering an e-mail address, without creating an account. The subscription only becomes active after the address is confirmed via a link we send to it (double opt-in); before confirmation, we already store hashed recipient/resource identifiers, send times and abuse-prevention counters. These are pseudonymous, not anonymous. The confirmation challenge expires after three days; expiry of the link does not itself delete all anti-abuse records. For active subscriptions we store only the confirmed e-mail address, the followed page, and the confirmation date, but no IP address or browser data. The address is used exclusively to send notifications about material changes to that page. Every notification includes a signed unsubscribe link that removes the address without requiring login. Follower addresses are deleted immediately when the subscription is cancelled and when the followed page is revoked or deleted.

Retention and deletion:

  • Consensus results that are eligible for sharing are kept server-side with an expiry of 24 hours and are then removed by periodic cleanup. Saved conversations and bookmarks have their own storage lifetime.
  • Shared pages remain online until you revoke them or delete your account.
  • When you revoke a shared page, it immediately becomes unavailable to the public and is scheduled for permanent deletion after a 30-day retention period by periodic cleanup. Copies cached by browsers or search engines for a short period are outside our control.
  • When you delete your account, all your watches, watch history, shared pages, pending results and Telegram connection/delivery metadata are deleted as part of the account-deletion process.
  • Report counters are deleted together with the page.
  • Follower e-mail addresses are deleted when the subscription is cancelled via the unsubscribe link and when the followed page is revoked or deleted.

Legal bases: Art. 6(1)(b) GDPR for publishing and managing pages you create and for your own Watch settings and requested service notifications; Art. 6(1)(a) GDPR for visitor email subscriptions confirmed via double opt-in (withdrawable at any time through the unsubscribe link); Art. 6(1)(f) GDPR for moderation, report handling, and abuse prevention.

6. Legal bases under the GDPR

  • Art. 6(1)(b): providing your requested account, AI comparisons, conversation history, Memory, API access, sharing and Watch functions, and answering service-related requests.
  • Art. 6(1)(f): protecting the service against abuse, diagnosing faults, moderating public content, handling general feedback and maintaining aggregate model statistics. Our interests are a secure, reliable service and the protection of users and third parties.
  • Art. 6(1)(a): optional visitor email subscriptions and any separately requested consent. Withdrawal applies to future processing and does not affect earlier lawful processing.
  • Art. 6(1)(c): where processing is required to comply with a specific legal obligation, such as handling data-subject requests or lawful authority orders.

Providing an email address is necessary for an account or email subscription; submitting a question is necessary for an AI run. These are not statutory duties, but the requested feature cannot work without that information. Memory, uploads, sharing and Telegram are optional.

We do not use AI outputs to make decisions about you with legal or similarly significant effects under Art. 22 GDPR. Technical access and usage limits are enforced automatically; contact us to request a review if you believe a restriction is mistaken.

7. Recipients, processors, and international transfers

  • Hosting: Render Services, Inc. (USA), for application hosting and technical requests. Render privacy information.
  • Accounts and database: Google Firebase Authentication and Cloud Firestore, supplied by Google under the applicable account agreement, for authentication and stored application data. Google Sign-In is optional. Firebase privacy information.
  • Analytics: Umami Cloud for the usage analytics described in section 3.
  • AI and search: OpenRouter and the inference/search endpoints described in section 4.
  • Email: Firebase for account verification and password setup/reset; the configured SMTP delivery service for Watch/Topic confirmations, notifications and Morning Briefs. Delivery involves recipient address, subject and message content, which can contain your question and results.
  • Browser dependencies: Google (gstatic.com) and jsDelivr (cdn.jsdelivr.net) receive technical requests including IP address when pages load their authentication, rendering or maths libraries. jsDelivr privacy information.
  • Telegram: optional delivery of your Watch notifications after connection and channel activation. Separately, the operator's Telegram bot receives content-free operational alerts (such as error categories or registration events), without prompts, emails or account identifiers.
  • Other recipients: readers and search engines for intentionally public content; authorities or advisers only where legally required or necessary to handle a legal claim.

International transfers require a legal basis under Chapter V GDPR in addition to the processing basis in section 6. An adequacy decision applies only to covered recipients; the EU–US Data Privacy Framework applies only to participating, certified US entities. Other transfers require appropriate safeguards, such as applicable Standard Contractual Clauses and an assessment of the transfer risks.

Model selection, acceptance of the Terms, using your own API key and ZDR do not themselves provide those safeguards. We do not rely on a blanket Art. 49(1)(b) exception for routine AI requests. Contact us for information about the applicable recipient and a copy of relevant transfer safeguards.

8. Storage periods

Account data, conversations, context versions, bookmarks, Memory and revision records remain while you use those saved features, until the relevant deletion or account deletion. API runs expire after 30 days; temporary share results expire after 24 hours. Expiry and physical deletion are different: periodic cleanup removes expired records, and failed cleanup is retried.

Public/private snapshots, Watches and subscriptions follow the deletion rules in section 5. Feedback and correspondence are retained until the matter is resolved, with longer retention only where needed for a legal obligation or a concrete legal claim. Minimal security, quota and subscription-abuse records are processed for prevention of repeated abuse; some are account-bound and removed during account deletion. A hash or expired token is not automatically anonymous or deleted.

Account deletion also covers stored chats and context. If a cleanup step fails, the account is blocked from further writes and cleanup is retried; a minimal deletion-job record is retained to complete that work. Hosting logs, email delivery records and infrastructure backups have provider/configuration-dependent retention. There is no promise of immediate deletion from every infrastructure backup.

9. Your rights in the EU/EEA

  • Access, rectification, erasure, restriction, and portability, subject to legal conditions.
  • Right to object: you may object to processing based on legitimate interests for reasons relating to your particular situation (Art. 21 GDPR); you may object to direct marketing at any time without giving reasons.
  • Withdrawal of consent with future effect.
  • Right to lodge a complaint with a supervisory authority, particularly where you live or work or where an alleged infringement occurred; for example the Lower Saxony data-protection authority, Prinzenstraße 5, 30159 Hannover, Germany.

You can delete your account yourself at any time in the app settings ("Delete account"). This removes your authentication account, profile data, your memory profile and notes, bookmarks, watches, watch history, shared pages, pending share results, Telegram connection/delivery metadata, and entries you created in the feedback and Pro-interest lists. For anything else, contact us at the address above.

10. Security

We implement appropriate technical and organizational measures, including access limitation, logging, and up-to-date transport encryption.

11. Children

consens.io is not directed at children. The service is intended for people aged 16 or older. Users under 18 also need permission from a parent or legal guardian where required to enter into the service agreement. The age rule is not a blanket consent to data processing.

12. Changes and contact

We may update this notice and indicate the last updated date below.

Email: contact@consens.io

Back to app Imprint
Last updated: 5 September 2026
App Topics Questions Model pulse Benchmark Model guide How consensus works About Terms Privacy Imprint