Achar

Privacy

Achar stores two kinds of personal data, and they are worth separating because the rules that apply to them are different. The first is the accounts of the people who use the product. The second is whatever personal data your editors choose to put inside a document.

Your account

  • We store the email address, the name, and the sign-in provider you used. Sign-in is Cognito, and a federated sign-in shares the address the provider gives us.
  • We never store a password for a federated account, because we never see one.
  • We do not sell, rent, or share account data with anybody whose product you did not ask us to connect.

Your content

Content belongs to the project it is in. We do not read it, train on it, or mine it, and we have no mechanism to do any of those things — which is a stronger statement than a policy, because a policy can be changed and an absent capability cannot.

Deleting things

Deleting a project deletes its datasets, documents, assets, tokens and memberships. Deleting a dataset deletes its documents and assets. Because content is the product and an accidental delete is unforgivable, tables and buckets are *retained* when a stack is destroyed — removing the data is a separate, explicitly-ticked step, and it says so out loud.

Write to privacy@achar.example to ask what is held about you, to correct it, or to have it removed.