Privacy Policy
What data we process, why, on what legal basis, who receives it, and how to exercise your rights. No advertising, no analytics, no commercial sharing.
Versión / Version 2026-08-13
1. Controller
Manuel Couto Pintos, acting as an individual. For any data protection matter, and to exercise your rights: manu.couto1k@gmail.com.
No data protection officer has been appointed, as none of the cases in Article 37 GDPR applies. The Universidade de Santiago de Compostela is not the controller of this processing.
2. What we process
| Category | Specific data | Source |
|---|---|---|
| Identity and account | Email address, display name and, if you sign in with Google, your profile picture. | Provided by you, or received from Google when you sign in. |
| Content you create | Chats and messages, agent graphs, agent and skill definitions, datasets, annotations, experiments and research logbooks. | Entered by you as you use the service. |
| Execution traces | The execution tree of each graph run: which node ran, how long it took, what it received and produced, tool calls, and the prompts sent to the model, together with token counts and estimated cost. | Generated automatically when you run a graph. |
| Provider credentials | API keys for OpenAI, Google, Mistral, NVIDIA or Hugging Face, and Ollama server addresses. | Entered by you. Stored encrypted with AES-GCM and never shown back. |
| Technical data | Server logs with the requested path, response code, processing times and a request identifier. IP address processed transiently by the infrastructure. | Generated automatically when you connect. |
| Acceptance of the legal documents | Your user identifier, which document you accepted, which version, and when. | Recorded when you accept. |
3. Why, and on what legal basis
| Purpose | Legal basis (Art. 6 GDPR) |
|---|---|
| Creating and maintaining your account and providing the service: storing your graphs, running your workflows, showing your results. | Performance of the contract you enter into by accepting the Terms of Use (Art. 6(1)(b)). |
| Recording execution traces so you can inspect and debug your own runs, and so we can diagnose service failures. | Performance of the contract (Art. 6(1)(b)) and legitimate interest in the correct operation and improvement of the system (Art. 6(1)(f)). |
| Keeping the service secure: technical logs, abuse and incident detection. | Legitimate interest in protecting the service and its users (Art. 6(1)(f)). |
| Keeping a record of which version of the legal documents you accepted. | Compliance with the accountability obligation (Art. 6(1)(c) read with Art. 5(2)). |
| Responding to your messages and to requests to exercise your rights. | Legal obligation (Art. 6(1)(c)) and legitimate interest in replying to you (Art. 6(1)(f)). |
There is no automated decision-making producing legal effects on you within the meaning of Article 22 GDPR, no commercial profiling, and no use of your data for advertising.
4. Recipients and international transfers
We do not sell or share data for commercial purposes. The following providers are involved, each in the role shown:
| Provider | Role | Location and safeguard |
|---|---|---|
| Supabase (on AWS) | Database and authentication. Your account and all your content live here. | Region eu-west-1 (Ireland), inside the European Economic Area. |
| Cloudflare | Web delivery and running the backend container. | Global network. Transfers covered by the European Commission’s standard contractual clauses. |
| The model provider you configure | Receives the prompt of each run, which may include the content of your chats, datasets and documents. | Mistral: France (EEA). OpenAI, Google, NVIDIA and Hugging Face: United States, under the EU-US Data Privacy Framework or standard contractual clauses, depending on the provider. Your own Ollama server involves no transfer at all. |
| Resend | Transactional email, such as team invitations. | United States, under standard contractual clauses. |
Public authorities may also access data where there is a legal obligation to provide it.
5. Shared workspaces
If you create or join a team, the content you create inside that workspace is visible to the other members, including its execution traces and cost. Your name and email are visible to other members and to whoever invited you. Check which workspace you are in before entering anything sensitive.
6. How long we keep it
- Account and content: for as long as the account exists. Deleting it erases them immediately and permanently.
- Execution traces: currently kept for as long as the run they belong to exists, and deleted with your account. A more aggressive automatic deletion of prompt text is planned; this section will say so when it takes effect.
- Technical logs: kept briefly, limited to what is needed to diagnose incidents.
- Record of acceptance: for as long as the account exists; deleted with it.
7. Your rights
You may at any time exercise the rights of:
- access to your data and to information about its processing;
- rectification of inaccurate data;
- erasure, which you can exercise yourself by deleting your account from Settings;
- restriction of processing;
- portability of the data you provided, in a structured format;
- objection to processing based on legitimate interest.
To exercise them, write to manu.couto1k@gmail.com from the address linked to your account. We will reply within the one-month period set by Article 12(3) GDPR.
If you believe the processing does not comply with the law, you may lodge a complaint with the Spanish Data Protection Agency (www.aepd.es), or with the supervisory authority of your country of residence.
8. Security
The measures in place include:
- encryption in transit via TLS;
- encryption of provider keys with AES-GCM, so the database never holds them in the clear;
- authentication delegated to Supabase, with no passwords stored by the service;
- isolation of data per user and per workspace, checked on every query;
- database access restricted to the service itself.
Should a breach occur that poses a risk to your rights, it will be notified to the Spanish Data Protection Agency and, where the risk is high, to you as well, under Articles 33 and 34 GDPR.
10. Minors
The service is not intended for anyone under 14. If we become aware of an account created below that age, it will be deleted.
11. Changes to this policy
Each version of this policy is identified by a date. Where a change materially affects the purposes, the recipients or your rights, you will be informed and asked to confirm the new version before continuing to use the service.
This policy is published in Spanish and English. In the event of any discrepancy, the Spanish version prevails.