Your data
Operated by BenevolentSky LLC. This page describes what the software actually does today — not what we intend to build. Where a protection is a design guarantee we say so; where it is only a practice, we say that too. Contact: privacy@benevolentsky.com.
What we store
- Your email — to sign you in and to reach you about the service. It is kept in an identity store that is separate from records.
- The name you choose — displayed as the human seat on rooms you convene or steer.
- Your rooms and their sealed records — the question you asked, the models' turns, the judges' harvest, timings, and the cost to the cent.
- Your credit ledger — every grant, flight, and refund, so the meter is inspectable.
- One coarse word for how you arrived — exactly one of search, social, referral, or direct, recorded once when you claim a seat. We do not store the referring URL, the search terms, or anything that could follow you across sites. It exists so that when we publish a prediction about where our visitors come from, we can actually settle it instead of guessing — see the calls.
- Ordinary server logs for security and reliability.
What never enters a record
Your email address never enters a sealed record. Records reference an account by an opaque, salted identifier that cannot be reversed to your address without a secret held on the server. This is a property of how records are built, not a policy we apply afterwards.
Who can read your rooms
Every room carries a visibility you choose when you convene it:
- Private — you and the operator. Unauthorized requests are answered exactly like a request for a record that does not exist.
- Crew — any signed-in seat.
- Commons — anyone who can reach the site.
Honest limit, stated plainly: "private" means private from other users. The operator can read what is on their own server. We are a small operation, not a zero-knowledge system, and we will not pretend otherwise.
Taking your data with you
Download everything we hold about you
One JSON file: your account, your ledger, and every record you convened as the exact bytes that were sealed — not a summary of them. That distinction is the whole point. A record only means something because its hash verifies, and a generated document would break that the moment a single character differed. So no model writes your export; it is a deterministic dump, it costs nothing, and the file carries the verification recipe so a stranger who distrusts us entirely can check it offline.
Not included, stated plainly: rooms you steered but did not convene belong to whoever convened them — your named turns live inside those records permanently, because the software has no edit operation and a revision would be detectable against the public timestamp anchor. Server logs are excluded. Your email never appears inside any record at all.
What you can delete — and the one thing you cannot
- A private record: yours to delete, from your flight log, at any time — with one exception we would rather name than let you discover. If a later record branched from it or cited it, deleting it alone would leave that later record pointing at nothing, so we refuse and tell you which ones are holding it. Delete those first, or delete the account and the whole private chain goes together.
- Your whole account: yours to delete. That removes your email, your ledger, your sign-in tokens, and every private record you hold — including entire private chains, since a private record can only ever be read by you and the operator. The single case we keep: a private record that a published record of yours cites. Deleting it would break a chain strangers can see, so it stays and the rest goes.
- One thing survives deletion, and here is exactly what it is. If you claimed the five free flights, a one-way fingerprint of your address remains — a hash, never the address itself. It exists for one reason: without it, deleting an account and signing up again would hand out another five free flights, repeatedly, until the advertising budget was gone. Stated honestly rather than dressed up: this is a pseudonymous marker, not anonymisation. Nobody can read addresses out of it, but somebody who already knew an address could confirm it had been used. If you never claimed free flights, nothing at all remains.
- A record you published to the commons stays. Others may have branched from it or cited it, and deleting it would break their chains. It carries only the name you chose — never your address. If you would rather keep your work, keep your rooms private; publishing is always a deliberate act.
- A sealed record cannot be quietly revised — which is a different claim from "we cannot
edit it". We are not going to tell you we are incapable of something we are merely
unwilling to do. Precisely:
- The software has no edit operation. Corrections happen the honest way, by later records that cite and challenge earlier ones. A flawed record stays exactly as sealed — including ours.
- The seal is our own sha-256 over the record. It proves the content has not changed since sealing. It is single-writer — a consistency check, not independent witness — because we hold the only pen.
- The anchor is that same hash, committed at seal time to four independent public timestamp calendars and thence to the Bitcoin blockchain. People with no relationship to us hold it from a date we cannot move. It proves when; it says nothing about what.
Where your questions go
Your room content is sent to AI model providers, routed through OpenRouter, to produce the deliberation — this is what a flight is. Flights are routed exclusively to endpoints designated zero-data-retention: those providers contractually commit not to store or train on your inputs. That is a contractual commitment vetted by our routing provider, not a cryptographic guarantee — what we can prove per flight is the routing itself, and each record discloses which provider actually served each seat.
That zero-data-retention guarantee covers the model providers. It does not cover web search, and we are not going to let you assume it does.
Live grounding — when the room searches the web
Models only know what they were trained on. A flight may optionally send a scout to search the live web first, so the room argues from published sources instead of memory. This is off unless you turn it on, per flight. It is not an account setting and there is no way for it to be left on by accident: a request either carries the search instruction or it does not, and without it nothing reaches the web.
- What leaves. Search queries written by the scout and derived from your question. Not copied verbatim, but derived — they can reveal its subject.
- Where they go. A third-party search provider (Exa), named on every record that used grounding.
- What we cannot promise. This leg is not zero-data-retention. The search provider may retain queries under its own policy. Our routing guarantee governs model providers and does not reach this hop — nobody offers a zero-retention web, and we would rather say so than imply a protection we have not got.
- What we do instead. Every query, every source, every retrieval timestamp, and everything the scout searched for and could not find is written into the record. The exposure is disclosed and logged like a citation, so what the room was shown is inspectable rather than taken on trust.
If a question is sensitive enough that its subject must not leave this building, fly it without grounding. The room will say plainly that it is working from training data alone.
Our processors: OpenRouter (model routing), Exa (web search — only on flights where you enable grounding), Render (hosting, United States), Resend (transactional email), Cloudflare (network). We do not sell personal information, do not share it for advertising, and run no third-party analytics or ad trackers.
When an AI agent operates this site for you
People increasingly drive web interfaces with an AI agent rather than by hand, and a record whose only options are a human did this and no human did this cannot describe that. So the convene form lets an operator declare it, and the declaration is sealed into the record and shown in its opening sentence.
- Whose software it is. Yours. An agent you use runs in your browser, on your subscription, under your account. We never see it, never route through it, and have no relationship with its provider. It is your tool and your responsibility, and it would be dishonest of us to imply any control over it.
- What we cannot promise. Our data-handling guarantees do not reach it. The routing guarantee governs the model providers we call. Whatever your agent reads on these pages or types into them passes through its provider under their policy — including the contents of a private room. That hop is outside our boundary and our receipts do not cover it.
- What is recorded. The declared operator — what it calls itself and, if given, its model — sealed beside the named human, who remains fully accountable for the room. Steers entered through an agent-operated room are marked as such on the turn and on the seat, so a reader is never shown a machine’s contribution wearing a person’s label.
- Declared, never detected. We cannot tell an agent from a person and we do not claim to. An undeclared one is invisible to us. The presence of that line means something; its absence proves nothing, and every surface that shows it says so.
If the material in a room must not leave this building, operate that flight yourself. The same advice as grounding, for the same reason: we would rather name a boundary we do not control than imply a protection we have not got.
US residents
The Service is operated from the United States and intended for US residents. Depending on your state you may have rights to access, correct, delete, or port your personal information. Write to privacy@benevolentsky.com; we verify identity before acting. Access from the EU, EEA, and UK is blocked at the network edge, and we do not knowingly process personal data of individuals in those regions.
Security, without overclaiming
Sessions are signed tokens; sign-in links are one-time and expire in fifteen minutes; secrets live in server configuration, never in code; traffic is TLS. Features that lose their configuration fail closed rather than degrade quietly. We hold no formal certifications and claim none. No system is unbreachable; if a breach affects your data we will tell you at your account email without unreasonable delay.
This page states current behaviour and is written to be accurate rather than comprehensive; a full terms of service is in preparation with counsel. If anything here does not match what the software does, the software is the bug and we want to hear about it: privacy@benevolentsky.com.