Privacy
In force from 13 September 2026. This says what we hold about you, where it is, and how long.
What we hold
Your knowledge: the memories and records your organization writes, the evidence they cite, and who wrote each one.
Your identity: the name, the email address and the organization your sign-in provider tells us. Sign-in is handled by Clerk; we never see your password.
How the service ran: which requests were made, by which agent, and whether they were allowed. This is what makes it possible to answer "who read that".
Where it is
In Amazon Web Services in Ireland, in one region, encrypted at rest and in transit. It is not copied to another region.
The people who run the service can reach the store to operate it. Nobody reads your knowledge to look at it.
Who else sees it
Clerk, for signing in and for the subscription. Amazon Web Services, for running and storing. Vercel, for serving these pages.
We use Vercel Analytics on the public pages and on the application. An address inside the application is redacted before it is sent: the question you typed and the key you opened never leave. Only the shape of the page does.
Nothing else, and no advertiser.
Agents and models
When you ask the store a question, the evidence it selected is sent to the model that answers. That model is named in Settings. It is not trained on what you send.
An agent connected to your store reads only what its grant allows, and every one of its reads is checked before anything is retrieved.
How long
Your knowledge stays until you delete it. A deleted memory is erased within thirty days.
Operational records of how the service ran are kept for as long as they are useful to run it, and they hold identifiers rather than your knowledge.
What you can ask for
A copy of everything: Settings, Your data. Deletion: the same place, or any memory from its own page.
Anything else, including a question about how your data is handled, goes to the address on the support page, and we answer.