Know where
your information goes.
This page describes the public INRI GPT website and demo. Business projects have their own agreed scope and data handling requirements.
Updated 3 October 2026. INRI GPT is created by Inri Inc, founded by Inri Bollo and Unejs Osmani.
The public AI demo
When you run an analysis, your selected workflow and text travel over HTTPS to our server and then to Cloudflare Workers AI. The service generates a response and returns it to your browser. INRI GPT does not save demo prompts or generated outputs in its application storage and does not use them to train models.
Cloudflare processes the request as a service provider. Its Workers AI data policy states that customer content is not used for model training without explicit consent. Use sample or redacted text; do not submit confidential records, passwords, financial account details, or patient information to this public demo.
Chat workspace, documents, images, and audio
Chat messages, recent conversation context, document excerpts, image prompts, attached images, and audio recordings are sent over HTTPS to our server and Cloudflare Workers AI when you press Send. Models include Meta Llama 3.1 8B for text, FLUX.1 [schnell] for image generation, LLaVA for image understanding, and Whisper for transcription. The INRI GPT application does not persist these inputs or outputs on the server.
Chat text is stored in this browser tab?s session storage so you can switch conversations and refresh the page. Use Delete conversation to remove a chat. Attachments, generated images, and charts remain in page memory and are not restored after refreshing. Downloads you choose to save remain on your device. The color theme preference is stored locally in your browser.
Document text is extracted in your browser, with clear size and excerpt limits. PDF extraction reads up to 20 pages; only a bounded excerpt is sent for AI processing. Images are resized locally. Audio is converted locally to mono WAV with a 30-second limit. Your microphone is accessed only when you choose Record and grant permission. Browser read-aloud uses the speech service and voices available on your device, which may depend on your browser or operating system provider. The calculator and CSV chart calculations run locally without model requests.
Recent chat context is limited to five exchanges and the current message, within a 12,000-byte limit. Source attachments add up to 16,000 bytes. All AI tools require Turnstile verification and are subject to usage caps. INRI GPT does not share your chat content with Unays LLC through the partnership links.
Customer accounts, organizations, and purchases
We store your account name, email, password hash, organization memberships, purchase records, project briefs, messages, and uploaded files on our Oracle-hosted server. Project information is visible to organization members and Inri Inc administrators. Payment details are processed by PayPal; we store order references, amounts, currencies, and payment status, not card details. Passwords are hashed with Argon2id. API keys, invitation tokens, and reset tokens are stored as hashes.
Google Workspace linking uses only identity permissions. We store the linked Google account identifier, verified email, and Workspace domain without keeping Google access or refresh tokens. Customer session cookies are Secure, HttpOnly, and SameSite=Lax. Contact us to request account or project-data deletion; purchase records may need to be retained for accounting obligations.
Advertising
Google AdSense advertising is loaded after you choose Allow ads. This preference is saved locally and can be reset through the footer. Ad requests are configured for non-personalized advertising. Google may process technical information and use cookies or local storage when ads are enabled; see its advertising policy. Our advertising code does not submit AI prompts or private account fields to Google. Inri Inc must configure Google Privacy and messaging where a certified consent platform is required.
Project inquiries
The contact form collects the name, email address, optional company name, and message you choose to provide. We use these details to review and respond to your inquiry. Submissions are stored in a restricted folder on our Oracle-hosted server, outside the public website directory, and are automatically removed from active inquiry storage after 180 days. Local backups retain up to three backup versions.
Abuse prevention and technical logs
Cloudflare Turnstile checks that form requests come from legitimate visitors. Cloudflare receives technical information needed for this verification; see its privacy policy. Our server uses IP-derived identifiers for short-term request limiting. Normal hosting and security logs can contain IP addresses, request paths, and timestamps. Request bodies are not deliberately logged by the application.
The site does not include advertising trackers or analytics cookies. Turnstile may use technical browser storage or signals necessary to perform its checks. The workflow choice can be held temporarily in your browser session when following a demo link.
Security and production requirements
We use HTTPS, server-side secrets, limited input sizes, Turnstile verification, request throttling, and a daily demo quota. The model cannot run code, browse your systems, or take actions for your business. Outputs can still be incorrect and require human review.
We do not claim SOC 2 certification or blanket regulatory compliance. Data residency, access controls, contractual terms, retention, and any regulated-data requirements must be reviewed for a production project.
Questions or deletion requests
Use the contact form to request access, correction, or deletion of an inquiry, or to ask about data handling. Include the email address used for the original inquiry so we can verify the request. Do not include sensitive identity documents in the form.