Legal
Privacy note
The honest reason this page is short: without accounts, there is very little to collect.
Effective 16 July 2026.
No accounts
There is no sign-up, so we never ask for a name, an email, or a password. A token is a random string generated in your browser. It is your identity here, and it is not tied to anything about you.
What we store
Only what you send to the API: the chunk text, the embeddings, and the metadata you attach to them. This data belongs to you. It is held so the service can return it, and for nothing else. Delete a collection and it is gone; lose a token and the collections behind it are pruned after 14 days.
What we do not log
Request and response bodies are not written to logs. If something breaks, the only handle we have is the X-Request-Id header from the affected response — which is why we ask you to quote it. We keep short-lived operational logs of connection metadata (timestamp, coarse size, status code) to keep the service running and to spot abuse; these rotate quickly and are not linked to any identity, because there is none.
No third parties
The site loads no analytics, no fonts from a CDN, no trackers, and no third-party scripts. Nothing on these pages phones home. You can confirm this in your browser's network tab — every request goes to this origin and no other.
Cookies
None. The site sets no cookies and uses no local storage to track you. The token you generate lives only in the page until you copy it; reload and it is gone.
Where it runs
One server, in the EU. Data you ingest stays on it and is not copied elsewhere during the beta.
Changes
If this note changes, the effective date above changes with it. Material changes will also be noted in the changelog.
Contact
The address in security.txt reaches us.