Privacy

Your question stays a question.

This notice says what stays on your device, what we store to run AskCanada AI, and who helps us do that. It is written in plain language. It is not a legal opinion.

Last updated: 2026-10-03

What this notice covers

This notice describes how AskCanada AI handles information when you use askcanada.ai. It covers questions, files you attach, the chat kept in your browser, feedback, and the cookies used to run the site.

AskCanada AI is an independent service. This is not a privacy notice of the Government of Canada or of a province or territory. We cannot see government accounts. A department's own notice applies when you use that department's site.

The short version

You do not need an account to ask a question. We do not sell information, and we do not use questions for advertising. The chat you see is kept in your browser for that visit, not as a profile on our servers.

Please do not include a social insurance number, a passport number, a case number, or a password in a question, a file, or a message to us. We will not ask you for them.

Questions you ask

When you ask a question, the text is sent to our servers so an answer can be written. It is also sent to third-party model providers, through an AI gateway, so they can draft the answer and the cards under it. The models we call are supplied by providers such as OpenAI, DeepSeek, and Google. Their processing can take place outside Canada.

We send the question so the answer can be produced. We do not send it to be used in ads. We ensure it is sent without your identity and under terms that don’t allow it to be used for training yet provider's own terms describe what they do with content they process. We do not control those terms.

Official pages we fetch

To write the answer, we search and fetch official government pages, and sometimes a public feed such as weather or open data. Those requests go to the government site or the feed. We send the topic or the place, not an account and not a device identifier.

The pages we fetch are public. Fetching them does not sign you in, and it does not tell the department who you are.

Chat history on your device

The chat you see is saved in your browser's session storage for this tab. It stays on the device. We do not keep a server copy as your account, and there is no login that would let us reopen it later.

That copy is limited, so the browser does not fill up: a limited number of recent chats, and the recent messages in each one. Attached files are not kept in that copy. Closing the tab, or clearing site data for askcanada.ai, removes it. A tool you fill in on the page, such as a calculator, can also be remembered in the same kind of storage for that tab. A rating you give an answer can be remembered there too, so the button stays selected.

Files you attach

You can attach an image, a PDF, or a plain-text file so the answer can refer to it. There is a size limit. The file is stored for a short time, about fifteen minutes, in temporary storage on our host, Cloudflare, so the model can read it. After that it is no longer available for the answer.

Do not attach identity documents. A file is processed like a question: it goes to our servers and to the model provider for that answer, and it is not added to the chat history stored on your device.

Usage limits and the device cookie

Asking a question is limited, so the service can stay available. After a check that the browser looks like a normal visitor, we set a signed cookie on this browser. The check is provided by Cloudflare. The cookie is HTTP-only, which means scripts on the page cannot read it. It can last until you clear it, up to the long maximum browsers allow.

The limit is counted against that cookie and against the network address, at the same time. We store those counts under a code derived from the cookie and the address, not as the raw address. Clearing cookies does not reset the address count. Changing networks does not reset the browser count. The counts last for the current limit window, a number of hours, and then age out.

Feedback, suggestions, and contact messages

If you rate an answer, send feedback, suggest a source, or use the contact page, we store that message in a database so we can operate and improve the service. We do not turn it into a profile for advertising.

  • A helpful rating stores the question, the tools that were shown, and the route the question took.
  • A rating that says the answer did not help can also store the answer you saw, the sources on screen, and a short comment, so the miss can be traced.
  • General feedback stores your message and the topic you picked. If you choose to include the chat, we store the question and answer you were looking at.
  • A source suggestion stores the site you named and any note.
  • A contact message stores the topic, the message, and the name and email if you typed them. The email is used to reply.

Codes instead of addresses

With a feedback or contact record we store a code derived from the browser and the network address, not the address itself, plus the language of the page. We limit how many of these messages one browser can send in a day.

That code lets us slow down abuse and group a burst of reports from the same browser. It is not your name, and it is not a government identifier.

Analytics and error reports

We use Analytics provider to see which parts of the site are used and to record technical errors. That includes events such as a question being asked, a file being attached, feedback being sent, or a tool being used. PostHog can set its own cookies. We also keep a technical trace of how an answer was produced, tied to an identifier for that chat, so a failure can be fixed.

These records are for operating the service. They are not sold, and they are not used to advertise to you. Analytics provider may process them outside Canada, under its own terms.

Cookies

The site uses a few cookies. The chat itself is stored separately in the browser, as described above, and is not a cookie.

  • A language cookie, so a return visit can open in English or French. The language is also in the address, /en or /fr.
  • The device cookie described above, used for the usage limit.
  • A sidebar cookie that remembers whether the chat list is open. It expires after about a week.
  • Analytics cookies set by PostHog, when analytics is running.

If you block cookies

You can block or delete cookies in the browser. The usage limit, the language preference, or the sidebar may then work differently. Blocking cookies does not remove a message you already sent us.

Clearing site data removes the local chat, the language cookie, and the device cookie in that browser. It does not delete a contact message that is already in our database.

What we do not ask for

We do not ask you to create an account. We do not ask for a social insurance number, a government file number, or a password. We do not read your government inbox. We do not sell personal information, and we do not use it for advertising.

If you type personal details into a question anyway, they are part of the question and are handled as the rest of this notice describes. The same is true of a file, a feedback note, or a contact message. Leave them out.

Who else receives information

We share information with the providers that run the service: our host, the model providers that write answers, and the analytics provider. They receive what they need to do that work.

We may also disclose information if the law requires it, or to respond to abuse of the service. We do not sell it. We do not give it to a government so they can update your file. Linking you to a government page does not log you into that page.

How long things are kept

Chat history stays in the browser until that session storage is cleared. We do not set a retention period for a server-side copy of your chats, because we do not keep one as an account.

Attached files can be used for the answer for about fifteen minutes, and they are not saved into the chat on your device. Usage counts last for the limit window. Feedback, contact messages, and source suggestions are kept so we can review problems and improve the service, and then deleted or reduced when they are no longer needed for that. Analytics and technical traces follow the provider's usual retention. Our host may keep connection logs for a limited time for security. These records are not all kept for the same reason, so they do not all share one number of days.

Security

The site is served over HTTPS. The device cookie is signed and marked so scripts on the page cannot read it. Identifiers we store for limits and feedback are derived codes, not the raw network address. Access to the feedback database is limited to operating the service.

These are ordinary measures. They reduce risk. They do not make a loss or a mistake impossible. Do not send information you would not want stored in a message.

Children

The service is written for a general audience looking up public government information. It is not directed at children. We do not knowingly collect information from a child.

If you believe a child has sent us a contact message or feedback, write to us through the contact page and we will delete what we can find from that message.

Your choices

You can use the site without sending a contact message or feedback. You can avoid attaching files. You can clear site data for askcanada.ai to remove the chat history and the cookies in this browser.

If you want us to look at a contact message or a piece of feedback you sent, use the contact page and say what you sent, and the email if you left one. We will do what we reasonably can. We may not be able to find a record that has no name on it.

You can also contact the Office of the Privacy Commissioner of Canada about how a Canadian organization handles personal information. That office is independent of us. This notice does not set out the steps for that complaint.

Processing outside Canada

Model providers, analytics, and hosting can process information outside Canada. A question can therefore be handled in another country for the time it takes to write the answer.

We do not use that as a reason to collect more. We collect what the answer, the limit, and the message you chose to send require.

Changes to this notice

We update this notice when the way we store or share information changes. The date at the top is the date of the latest version. The notice on this page is the one that applies.

If a change only explains more clearly something we already do, we still change the date. Using the site after that date means the updated notice describes the service you are using.

How to reach us about privacy

Questions about privacy can be sent through the contact page. Choose Privacy as the topic if it fits. Include an email if you want a reply. Please do not include identity numbers in the message.

The source policy describes what we read. The accessibility statement describes how the site is meant to be used.

Related