Automaton Nebula
Privacy policy
This policy says what is done with your data and with the data of the people you store things about. The retention figures are the ones the server actually applies, not an approximation: they are written in the code and can be checked from the panel.
Version 1.0, in force since 6 September 2026. The binding text is the Spanish one; the other languages are a courtesy translation.
Who answers for your data
The controller is José Luis Sánchez, Spanish tax number 71223690G, address calle Repullete 100, 23300 Villacarrillo (Jaén), Spain. There is no appointed data protection officer: it is not required for a project of this size, and the person who runs the service is the one who answers.
What data is here
Four things, and no more. Your email address, which is all it takes to sign in. The contents of your vault: the workspaces, the facts you write, the conversations you archive and the tags and notes you attach to them, including any third-party data you decide to put in. A minimal technical trail: which tool asked for which workspace and when, without the text of what was asked, plus the credentials of the connectors and devices you authorise. And, if you pay, just enough to know which plan you are on: which plan, how much, in what currency and when. The card never passes through here, nor does your name or billing address: Paddle handles that, as the one doing the charging.
What is not stored
The IP address is not stored in any table. It is used in memory to count sign-in attempts and stop brute force, and it disappears when the server restarts. There is no analytics, no pixels, no advertising identifiers and no profiling. No server log ever prints the text of a fact or a conversation. And anything that looks like a secret — a key, a password, a card or account number — is refused before it is written, unless you say outright that it is not one.
Why it is handled and on what basis
To provide the service you contract, which is performance of the contract: holding your vault, handing it to the AIs you authorise and keeping your account. On legitimate interest, to keep the service standing: limiting sign-in attempts, preventing abuse and knowing which credential wrote what. And on legal obligation, where there is one, to keep the records of a purchase for as long as tax law requires. No processing rests on consent except the consent you give when you connect a particular AI, which you can withdraw by revoking that connection.
How long each thing is kept
The vault — workspaces, facts, conversations, conflicts, aliases and imports — is kept until you delete it, and does not expire on its own. The access log lives ninety days, which covers a quarter of work; beyond that it would stop being a log and become a portrait of how you work. Retry keys, seven days. Email sign-in codes and OAuth codes, one day after they expire. Finished import jobs, thirty days. An OAuth client that was registered and never had a live connection, thirty days. Payment records are kept for as long as tax law requires. An automatic sweep runs once a day.
Where it is
On a dedicated server hosted in Germany, inside the European Union, with a daily backup and a restore drill every week. There are no international transfers on the provider's part. The only data leaving this server is the one you cause by connecting an AI, and it is described in the next section.
Who else touches it
Three processors while you do not pay, and they are named: Hetzner Online GmbH, which hosts the server, in Germany. Cloudflare, which acts as proxy and defence in front of the domain and sees traffic, not the contents of the vault. And Resend, which sends the email carrying the sign-in code and handles your address for that. If you pay there is a fourth, Paddle, which charges as merchant of record and handles your payment data; it issues and keeps the invoice. Nobody else. There are no analytics or advertising providers, because there is no analytics and no advertising.
What travels to an AI
When you authorise a connector and that AI asks for your context, this and nothing else goes to the servers of whoever provides that AI: the workspace name, the text of the current facts that match, with their validity dates, the tags you gave them, who wrote each one —you or the AI itself— and whether it is confirmed, the two texts of an undecided conflict, any session notes, and one identifier and one link per fact so the AI can cite it and you can correct it later. If it also searches your conversation archive, the title, the date, which AI it came from and the matching excerpt go too; and if it asks for a fact's history or exports a workspace, the texts that were already superseded or rejected go as well. Your email does not go, nor any credential, nor the access log, nor the names of your other connections, nor your private notes. All of that falls under that AI's privacy policy and not under this one. The panel shows exactly what would be sent before sending it, and private mode stops storing on a given connection while it is on. A workspace marked sensitive never goes to a cloud connector: only the panel and devices with their own credential read it. What an AI already received is in that AI, and deleting it here does not delete it there.
Nothing is trained and nothing is sold
Your data trains no model, neither ours nor anyone else's, and it is not sold or handed over for commercial exploitation. No language model runs on this server: what detects duplicates, contradictions and relative dates is a rule-based classifier, with no dependencies and no calls to anyone. It is a design decision, written into the project itself as a line that is not crossed.
Cookies
One, and it is technical: the one that keeps your session open after you sign in with the code. It is marked HttpOnly, SameSite Lax and Secure, and it disappears when you sign out. There are no third-party cookies, no analytics cookies and no advertising cookies, which is why you will not see a banner asking permission for something that is not being done.
Third-party data that you store
If your vault holds data about your clients or their contact people, for that data you decide the purpose and the provider acts as processor on your behalf, with the duties that implies: handling it only to provide you the service, keeping it confidential, not subcontracting beyond the three processors named above, and returning or deleting it when you are done. Anyone needing a separate signed processing agreement can ask for it at the address below.
Security, breaches and changes
All traffic is encrypted in transit, credentials are stored as digests and never in the clear, and each connector carries its own permissions with deletion closed by default. Should a breach occur with a risk to your rights, the supervisory authority will be notified within the legal deadline and affected people will be told where required. Changes to this policy are published on this same page with their date, and those materially affecting how your data is handled are notified by email before they apply.
Exercising your rights
Downloading the vault and deleting the account are self-service from the panel and take effect immediately, with nobody to write to. For anything else — access, rectification, objection, restriction — the address below is enough. You may also complain to the Spanish Data Protection Agency if you believe something has been handled badly.