Your data stays within the local perimeter
Servers, processing and storage — in Uzbekistan. Conversations are never shared with external AI platforms.
Servers and processing in Uzbekistan
Conversations are not sent to external AI platforms
Normal human access control
Navigation
Main sections of the security policy
These blocks reflect the product's practical principles: where data lives, how it's protected, who gets access and how long things are kept.
Data center in Uzbekistan
All servers that process EYWA requests are physically located in a data center on the territory of the Republic of Uzbekistan.
Requests are not sent to OpenAI, Anthropic, Google, or any other external AI provider.
This approach reduces sanctions and legal risks and keeps data within the local perimeter.
Encryption
Data in transit is protected by TLS 1.3, and data at rest is encrypted at the infrastructure level.
Histories, files and user materials are isolated at the access level and linked only to your context.
Even within the team, access to data is limited by roles and purpose.
Not used for training
Your conversations and documents are not used to train the EYWA model further.
We don't sell or transfer this data to third parties for ML tasks.
For corporate clients, separate legal terms and NDAs are possible.
Moderation and protection
The service checks requests for dangerous or prohibited content without turning the product into a total surveillance tool.
Flagged cases are separated from regular user sessions and processed in a limited perimeter.
This helps protect the service without breaking the everyday experience of a normal user.
Retention periods
Conversation history is kept for memory, projects and continuation of work until you delete it yourself.
Temporary files and auxiliary materials are cleared according to internal retention policies.
When an account is deleted, associated user data is removed from the active perimeter and backup cycles per regulation.
Control stays with you
You can request data export, account deletion and clarification on the stored user context.
For sensitive scenarios, it's always better to agree on storage and access requirements with our team in advance.
If you have compliance requirements, we discuss them before launch, not after an incident.
Questions left?
For privacy, security and enterprise requests, it's better to talk directly
If you need separate storage terms, compliance answers, an audit perimeter or private deployment, it's better to discuss it with our team right away.