Privacy Policy
Version 1.0 · 6 September 2026
This says what we hold about you, why, for how long, and what you can do about it. It is short because we collect little.
What we hold
To let you in: your e-mail address, your name, and the passkeys or authenticator you registered. There is no password, so there is no password to lose.
Because you told us: a photo, a language, a time zone, a theme and a text size, if you set them.
Because the platform kept a record: which devices are signed in and when each was last used; who opened your profile; what you did that changed something, in the audit log. These exist so that you can see them — an account you cannot audit is an account you cannot trust.
Because a browser sends it: an IP address and a browser identifier with each request, kept short-term for security, and a rough country derived from the IP. We do not keep a location more precise than a country.
What we do not hold: advertising identifiers, third-party trackers, a profile of you assembled from anywhere else, or your behaviour on other sites. There is no analytics script on any page, because there is no script on most pages at all.
Cookies
One cookie, for your session, so that you stay signed in. It is not shared, not sold, and not used to follow you. Nothing on Enclave asks you to accept cookies, because there is nothing to accept.
Organizations, and who is responsible
When you use Enclave inside an organization, that organization decides what is collected in its own tools and is responsible for it; we process it on their instructions. Where an organization has connected its own database, its own model key or its own storage, that data never reaches us at all.
For your own account — the list above — we are responsible, and this policy is the whole of it.
Who else sees it
The companies that run the parts of the service we do not run ourselves: e-mail delivery, payments, and hosting. Each sees only what it needs to do its job, each is contractually bound, and none of them may use it for anything else. We do not sell personal data, and we do not share it for advertising. Ever.
How long we keep it
Your account data until you delete your account, and thirty days after that in backups before it is gone for good. Security records — sign-ins, devices, IP addresses — for ninety days. Audit records for as long as the organization keeps them, which its owner sets. Invoices for as long as tax law requires.
What you can do
See everything we hold, from Settings. Correct anything wrong, from the same place. Export all of it in formats you can read without us. Delete your account, which deletes it, without asking anyone.
If you want any of this and cannot find it, write to privacy@eze.ink and we will do it by hand. If we get it wrong, you can complain to the data protection authority where you live.
Changes
When this policy changes, the version line at the top changes and you will be told before the change applies.