This Privacy Policy explains what personal data we collect through [Product Name] (the "Service"), why, and the choices and rights you have over it.
This policy covers two kinds of users:
Account data. Email address, password (stored only as a salted bcrypt hash, never in plaintext), display name, and, if applicable, the organization you belong to and your role within it.
Content you provide. Files, data source connections, prompts, and configuration you supply when assembling or running a Solution. What we do with this is described in Section 3.
Personal context / knowledge base data (opt-in only). If you explicitly enable it, we build and store a private, continuously-refined summary derived from sources you connect, to improve the relevance of generated output for you. This is off by default; enabling it requires explicit consent, and you can disable it and permanently delete all associated data at any time from your account settings.
Organization context data. If you are an organization administrator, the organization-level "constitution" (base instructions/guardrails) and any organizational knowledge base you configure, plus entitlement, branding, and membership settings for your organization.
Usage and security data. Login timestamps, IP address and user-agent associated with sessions (used for session security and to detect abuse), and basic error/diagnostic data if error tracking is enabled (see Subprocessors).
Cookies. We use one strictly-necessary cookie: an HttpOnly, Secure session cookie that keeps you signed in. It cannot be read by JavaScript and is not used for advertising or cross-site tracking. As of this draft we do not use analytics or marketing cookies; if that changes, this policy and any required cookie-consent mechanism will be updated first.
We do not sell your personal data, and we do not use Your Content to train our own models.
Where GDPR applies, we rely on: contractual necessity (to provide the Service you signed up for), consent (for the opt-in personal/organizational knowledge base features, withdrawable at any time), and legitimate interests (for security measures like login-attempt rate limiting and error tracking), balanced against your rights.
We share data with the following categories of third parties, only as needed to provide the Service:
| Purpose | Provider(s) | Notes |
|---|---|---|
| AI model processing of Your Content | Anthropic, OpenAI | Receives the portion of Your Content needed to generate output for the Solution you configured. |
| Infrastructure hosting | Hetzner Online GmbH (Germany/Finland) | The Service and its database run on Hetzner Cloud infrastructure in the EU. |
| Error tracking | Sentry (if enabled) | Diagnostic/error data only; [confirm activation status and update once live]. |
| Content delivery / DNS / DDoS protection | [Confirm if/when adopted, e.g. Cloudflare] | [Placeholder - update once finalized.] |
| Transactional email | [Not yet finalized] | [Update once a provider is selected.] |
Our infrastructure is hosted in the EU. Some subprocessors (including our AI model providers) may process data outside the EU/EEA, including in the United States. [Confirm with counsel the transfer mechanism relied on for each such subprocessor and reference it here.]
We retain account and content data for as long as your account is active. If you delete your personal context/knowledge base, that data is purged immediately (not just hidden). [Specify retention periods for account data after account closure, and for security/log data, once finalized.]
Depending on your location, you may have the right to: access the personal data we hold about you; correct inaccurate data; request deletion; request a portable copy of your data; object to or restrict certain processing; and withdraw consent for opt-in features (which you can do directly, for the personal knowledge base, from your account settings). To exercise any of these rights, contact [Contact Email].
We use industry-standard measures appropriate to the sensitivity of the data, including: bcrypt password hashing, short-lived signed access tokens with rotated and hashed refresh tokens, encryption of stored provider credentials, TLS encryption in transit, and rate limiting with account lockout on repeated failed login attempts. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
The Service is not directed to, and we do not knowingly collect personal data from, individuals under 16. If you believe a child has provided us personal data, contact [Contact Email] and we will delete it.
We may update this policy from time to time. We will post the updated policy with a new effective date, and for material changes will make reasonable efforts to notify active users before the change takes effect.
Questions about this policy or your data: [Contact Email].