Privacy Policy
This policy describes what Arachnest, referred to below as "the service", does with information about you while it is in alpha.
1. What we collect
- Account information: your username, email address, and a hashed version of your password. Plain passwords are never stored.
- Content you capture: conversation transcripts, the facts extracted from them, and the projects, entities, and relationships you build.
- Technical information: server logs, including your IP address, request times, and error details, and counters used for rate limiting.
- Password reset tokens: short-lived tokens created when you request a reset.
2. How it is used
- To run the service: storing your graph and showing it back to you and your project members.
- To turn captured conversations into structured facts. This sends the conversation text to a third-party language model provider for processing.
- To keep the service working: security, abuse prevention, debugging, and rate limiting.
- To contact you about your account, such as password resets and service notices.
3. Who it is shared with
- We do not sell your data.
- Facts you place in a project are visible to the other members of that project, according to the exposure setting on each fact.
- Service providers that process data on our behalf: the language model provider used for extraction, and the infrastructure provider that hosts the service.
- Others, if required by law or to protect the rights and safety of users.
4. Where it lives and how long
The service runs from a single deployment. Your data is kept while your account is active. As alpha software, data may be reset or migrated during development. When you ask for deletion, your account and the content you own are removed, except where something must be kept to meet a legal obligation.
5. Your choices
- Each fact has an exposure setting: private to you, shared with a project, or part of your public identity. You control it.
- You can leave a project, which ends your access to it going forward.
- You can request a copy of your data, or its deletion, by contacting us.
6. Security
Passwords are hashed. Access is scoped per project and enforced at the database level as well as in the application. Sessions use bearer tokens rather than long-lived cookies. This is alpha software and has not had a formal security audit, so treat it accordingly.
7. Cookies and analytics
This marketing site can load Google Analytics (GA4) to see how the pages are used, but only after you accept the cookie banner shown on your first visit, nothing loads before that choice, and declining or ignoring it means it never does. The core application itself uses no analytics or tracking cookies; signing in relies on a bearer token, not a long-lived cookie (see Security above).
8. Children
The service is not directed at children and is not intended for anyone under 16.
9. Changes
This policy may change as the service develops. The date at the top of the page shows the last update.
10. Contact
Requests about your data can be sent to the address published wherever you received your invitation or account. A dedicated privacy contact address will be added here before general availability.
See also the Terms and Conditions for the rules of using the service.