Spaces:
Running
Black Dragon AI - Privacy Policy
Last updated: 8 June 2026 Policy version: 2026-06-08-v1
This Privacy Policy explains how Black Dragon AI handles information when you use the web app, local desktop backend, hosted backend, games, notes, memory, file tools, voice features, image/search features, and PC-assistant tools.
This document is a production-ready template, not legal advice. Before public launch or commercial distribution, the operator should have this reviewed by a qualified lawyer and fill in the operator details below.
1. Operator Details
Operator name: [Rajiv Kumar]
Contact email: [rokyd2p@gmail.com]
Grievance / privacy email: [itisblackdragon@gmail.com]
2. What Black Dragon Is
Black Dragon is an AI assistant and productivity tool. Depending on configuration, it can:
- answer questions through a backend AI provider or local model,
- save user-approved memory and notes,
- process typed prompts, uploaded files, and images,
- show browser/search/image results from third-party sources,
- provide games and creative tools,
- perform safe PC-assistant actions on the owner device when the local backend is running.
The frontend must not contain API keys. AI provider keys, login secrets, and server credentials must be stored only in backend environment variables, hosting secrets, or a protected backend secret file.
3. Information We May Collect
Black Dragon may process the following information:
- profile name or email typed by the user,
- chat prompts and AI responses,
- saved memory facts intentionally provided by the user,
- notes, drawings, and handwritten canvas content,
- uploaded files, images, and extracted text,
- browser search or image search queries,
- app settings and accepted Terms/Privacy version,
- backend logs, request IDs, timestamps, route names, token estimates, and safety events,
- local PC status data when the user asks for PC assistant features,
- voice input transcripts when voice features are used.
Black Dragon should not intentionally collect payment data, government identity numbers, banking credentials, passwords, OTPs, or sensitive personal data unless a future deployment explicitly adds a lawful, secure workflow for that purpose.
4. Why We Process Data
Black Dragon processes data to:
- provide AI answers and productivity features,
- maintain chat history and memory,
- run notes, games, file tools, image tools, and PC-assistant features,
- detect abuse, rate-limit traffic, and protect backend keys,
- comply with legal requests where applicable,
- improve reliability through logs and monitoring.
5. AI Providers and Third Parties
When API mode is enabled, the backend may send prompts, selected memory context, and relevant attachments to configured AI providers such as Groq, OpenRouter, or another provider chosen by the operator.
When browser/image features are used, Black Dragon may request results from third-party sources or search endpoints. Images and external results may belong to third parties. Black Dragon does not guarantee ownership, license, accuracy, availability, or suitability of those results.
Users must verify rights before copying, publishing, modifying, selling, or using third-party images or content commercially.
6. Local Storage
On a local desktop deployment, Black Dragon may store data on the device, including:
backend_data/black_dragon.db
backend_data/secrets.json
%TEMP%\BlackDragonChats\
%TEMP%\BlackDragonUploads\
The local backend owner controls these files. Deleting them may remove chat history, memory, notes, logs, and local configuration.
7. Hosted Storage
On a hosted deployment, data may be stored by the hosting provider, backend database, temporary filesystem, monitoring logs, or AI provider systems. The operator must configure hosting retention, access controls, backups, and deletion rules before public release.
Hugging Face, Netlify, GitHub Pages, Render, Railway, Fly.io, or any other hosting provider may have their own privacy and security terms.
8. Memory and Notes
Black Dragon memory is intended for user-provided preferences and useful facts. Users can ask what is remembered and can clear memory through the app where the feature is enabled.
Notes may include typed text or drawings. Users are responsible for the content they create, save, export, or share.
9. Voice and Camera / Microphone
Voice features depend on browser and device permissions. Audio may be converted into text by the browser speech system or a configured speech service. Black Dragon should request microphone permission only when the user starts a voice feature.
The current app does not require camera access for normal chat.
10. PC Assistant Data
Local PC-assistant features may read basic device information such as operating system, disk status, running processes, network information, or scan status when requested by the user.
Public hosted deployments should disable destructive or device-control features. Users remain responsible for local commands they request.
11. Indian Privacy Law
For India-focused deployments, the operator should review obligations under the Digital Personal Data Protection Act, 2023 and related rules as they become applicable. Practical obligations may include:
- providing a clear notice,
- collecting valid consent where required,
- processing personal data only for lawful and disclosed purposes,
- allowing access, correction, erasure, grievance redressal, and nomination where applicable,
- protecting personal data with reasonable security safeguards,
- deleting personal data when it is no longer needed,
- notifying required parties of personal data breaches where required,
- applying additional safeguards for children.
12. Security
Black Dragon includes or is designed to support:
- backend-only API key storage,
- password/token gate for public backend routes,
- rate limiting and abuse protection,
- PII masking for common patterns,
- prompt-injection filtering,
- compliance logs,
- safe PC-command allowlists,
- destructive-command blocking.
No software or AI system can guarantee absolute security. Users should keep operating systems, browsers, dependencies, and hosting secrets updated.
13. Retention
Suggested default retention:
- active chat and note data: until the user deletes it or the operator removes it,
- temporary uploads: as short as practical,
- security and abuse logs: long enough to investigate misuse,
- inactive account data: delete or anonymize after a defined retention period.
The operator must choose and publish the final retention period before public launch.
14. User Choices
Depending on deployment, users may:
- stop using the app,
- clear local browser storage,
- delete local backend data,
- clear memory,
- export or delete notes,
- contact the operator for access, correction, deletion, or grievance requests.
15. Children
Black Dragon is not for children below(13year), parental consent, safety filters, and moderation controls. Users must not use Black Dragon to exploit, endanger, identify, or harm children.
17. Changes
The operator may update this Privacy Policy. Material changes should be shown in the app and may require users to accept the new version before continuing.
18. Contact
For privacy requests, complaints, or deletion requests, contact:
19. References
- Digital Personal Data Protection Act, 2023: https://www.indiacode.nic.in/bitstream/123456789/22037/2/a2023-22.pdf
- Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021: https://www.pib.gov.in/Pressreleaseshare.aspx?PRID=1700749