LucentFire

Your data

Operated by BenevolentSky LLC. This page describes what the software actually does today — not what we intend to build. Where a protection is a design guarantee we say so; where it is only a practice, we say that too. Contact: privacy@benevolentsky.com.

What we store

What never enters a record

Your email address never enters a sealed record. Records reference an account by an opaque, salted identifier that cannot be reversed to your address without a secret held on the server. This is a property of how records are built, not a policy we apply afterwards.

Who can read your rooms

Every room carries a visibility you choose when you convene it:

Honest limit, stated plainly: "private" means private from other users. The operator can read what is on their own server. We are a small operation, not a zero-knowledge system, and we will not pretend otherwise.

Taking your data with you

Download everything we hold about you

One JSON file: your account, your ledger, and every record you convened as the exact bytes that were sealed — not a summary of them. That distinction is the whole point. A record only means something because its hash verifies, and a generated document would break that the moment a single character differed. So no model writes your export; it is a deterministic dump, it costs nothing, and the file carries the verification recipe so a stranger who distrusts us entirely can check it offline.

Not included, stated plainly: rooms you steered but did not convene belong to whoever convened them — your named turns live inside those records permanently, because the software has no edit operation and a revision would be detectable against the public timestamp anchor. Server logs are excluded. Your email never appears inside any record at all.

What you can delete — and the one thing you cannot

Where your questions go

Your room content is sent to AI model providers, routed through OpenRouter, to produce the deliberation — this is what a flight is. Flights are routed exclusively to endpoints designated zero-data-retention: those providers contractually commit not to store or train on your inputs. That is a contractual commitment vetted by our routing provider, not a cryptographic guarantee — what we can prove per flight is the routing itself, and each record discloses which provider actually served each seat.

That zero-data-retention guarantee covers the model providers. It does not cover web search, and we are not going to let you assume it does.

Live grounding — when the room searches the web

Models only know what they were trained on. A flight may optionally send a scout to search the live web first, so the room argues from published sources instead of memory. This is off unless you turn it on, per flight. It is not an account setting and there is no way for it to be left on by accident: a request either carries the search instruction or it does not, and without it nothing reaches the web.

If a question is sensitive enough that its subject must not leave this building, fly it without grounding. The room will say plainly that it is working from training data alone.

Our processors: OpenRouter (model routing), Exa (web search — only on flights where you enable grounding), Render (hosting, United States), Resend (transactional email), Cloudflare (network). We do not sell personal information, do not share it for advertising, and run no third-party analytics or ad trackers.

When an AI agent operates this site for you

People increasingly drive web interfaces with an AI agent rather than by hand, and a record whose only options are a human did this and no human did this cannot describe that. So the convene form lets an operator declare it, and the declaration is sealed into the record and shown in its opening sentence.

If the material in a room must not leave this building, operate that flight yourself. The same advice as grounding, for the same reason: we would rather name a boundary we do not control than imply a protection we have not got.

US residents

The Service is operated from the United States and intended for US residents. Depending on your state you may have rights to access, correct, delete, or port your personal information. Write to privacy@benevolentsky.com; we verify identity before acting. Access from the EU, EEA, and UK is blocked at the network edge, and we do not knowingly process personal data of individuals in those regions.

Security, without overclaiming

Sessions are signed tokens; sign-in links are one-time and expire in fifteen minutes; secrets live in server configuration, never in code; traffic is TLS. Features that lose their configuration fail closed rather than degrade quietly. We hold no formal certifications and claim none. No system is unbreachable; if a breach affects your data we will tell you at your account email without unreasonable delay.

This page states current behaviour and is written to be accurate rather than comprehensive; a full terms of service is in preparation with counsel. If anything here does not match what the software does, the software is the bug and we want to hear about it: privacy@benevolentsky.com.