Privacy policy
Last updated
This policy explains what personal data Incantory collects, why, who helps us process it, how long we keep it, and the choices you have. It covers the website, the API, the SDKs and CLI, the MCP servers, the extensions and the mobile app.
The controller of your data is [operator legal entity], [registered address]. Contact: [email protected].
The short version
- We collect as little as we can: an email address to sign you in, the profile you choose to fill in, what you publish, and the security data needed to keep accounts safe.
- No advertising, no tracking cookies, no selling of data. Our page analytics is self-hosted and cookieless, so there is no cookie banner.
- We never send your prompts to a third-party AI provider. The site's own background AI runs on a model gateway we host ourselves.
- You can download everything we hold about your account, or delete it, at any time from Settings → Account.
What we store
Your account
- Email address, and when it was verified. It is how you sign in (magic link) and how we contact you.
- Handle, display name, bio, website and avatar, if you set them. These are public.
- Year of birth and an adult flag. We ask for your year of birth once, to apply the minimum age and to decide whether mature content can be turned on. We store only the year and a yes/no "is an adult", never your full date of birth.
- Preferences: language, timezone, notification settings, the mature-content switch.
- Reputation, badges and counters (followers, prompts), which are public.
Sign-in and security
- Sessions: a hash of the session token, when it expires, and the device name, browser user-agent and IP address it was created or last used from, so you can see and revoke your sessions in Settings → Security.
- Linked accounts: if you sign in with GitHub or Apple, the provider's account id, the email it gave us and your GitHub login name.
- Passkeys: the public key and counter for each passkey. Your private key never leaves your device.
- API tokens: a name, a short prefix and a one-way hash of the token (we cannot see the token again), its scopes, and when and from which IP address it was last used.
- Email changes: the old and new address for 7 days, so you can undo a change you did not make.
- Mobile push: the Expo push token for each device that has the app installed and notifications on.
- Discord: if you link Discord, your Discord user id (to sync a role). We do not keep Discord access tokens.
What you publish and do
Prompts and their versions, drafts, examples, makes, posts, comments, collections, uploaded media, stars, follows, votes, "works on" reports, watches, blocks and mutes, reports you file, claims and removal requests, contest entries, webhooks you set up, and imports you run. Most of this is public by design; drafts, blocks, mutes, reports and webhook settings are private.
Uploaded images are re-encoded, which removes EXIF and GPS location data before anything is published.
Usage analytics
- Site analytics uses Umami, which we host ourselves. It is cookieless and records page views and a few actions (copy, download, share, fork, sign-up) without building a profile of you. Our server forwards your IP address to Umami only so it can look up your country and tell visits apart; Umami does not store it.
- Creator analytics (the views and copies an author sees) come from our own event table. Each event records what was viewed, the country (from Cloudflare's country header), the referring site, and a visitor hash that is salted daily so it cannot be linked across days. We do not store your IP address in these events. If you are signed in or using an API token, the event is linked to your account.
Logs and moderation
- An audit log records privileged actions (moderation, admin changes, account security events) with the acting account, the IP address and the browser user-agent.
- Email suppression: if an email to you bounces or is marked as spam, we keep the address and the reason so we stop sending to it.
- Error reports: when something breaks, a technical report (the error, the page or API route, the request id, the browser type) goes to our self-hosted error tracker. We do not attach your email or content to these reports.
- Removal and copyright requests keep the requester's name, email and the details they sent, so we can reply and keep a record.
Why we use it
- To provide the service you asked for (contract): accounts, sign-in, publishing, notifications, the API.
- To keep it safe (legitimate interests): spam and abuse prevention, rate limits, security logs, moderation, the age gate.
- To improve it (legitimate interests): aggregate, cookieless analytics and error reports.
- Because the law requires it (legal obligation): copyright notices, responses to lawful requests, the minimum age.
- With your consent, where we ask for it: optional emails such as digests (you can unsubscribe from any of them with one click), push notifications, linking Discord.
Who processes it for us
We use a small number of service providers. Each only gets what it needs to do its job.
| Processor | What it does | Data it handles |
|---|---|---|
| SendGrid (Twilio) | Sends sign-in links, notifications and digests | Your email address, the message, delivery and bounce events |
| Cloudflare | Serves the site through its network (CDN and tunnel), protects forms with Turnstile, and stores uploaded media and exports in R2 | IP address and request data in transit, Turnstile signals, uploaded files |
| GitHub | Sign in with GitHub, if you choose it; public data for import and claims | Your GitHub account id, login and email |
| Apple | Sign in with Apple, if you choose it | Your Apple account id and (possibly relayed) email |
| Expo | Delivers push notifications to the mobile app | Your device's push token and the notification text |
| Discord | Community server and role sync, if you link your account; public posts about featured work | Your Discord user id; public content |
| Umami (self-hosted by us) | Cookieless page analytics | Page URL, referrer, browser type, country |
| llama-gateway (self-hosted by us) | The site's own background AI: tags, summaries, translations, spam and duplicate checks | Public prompt text and metadata. It runs on our own infrastructure; nothing is sent to a third-party AI provider |
| GlitchTip (self-hosted by us) | Error tracking | Error details and request metadata |
Our servers, database and backups run on infrastructure we operate ourselves. Some processors are in the United States; where data leaves your country we rely on the safeguards the law provides, such as standard contractual clauses.
We do not sell or rent personal data, and we do not share it with advertisers. We disclose data to authorities only when the law requires it, and we tell you when we are allowed to.
How long we keep it
| Data | How long |
|---|---|
| Raw analytics events | 30 days, then only daily totals are kept (no visitor hashes) |
| Audit log of privileged actions | 1 year |
| Webhook delivery logs | 30 days |
| Background job records | 14 days when finished, 30 days when failed |
| Sessions | Until they expire (30 days after last use) or you sign out or revoke them |
| Email-change undo data | 7 days |
| Error reports | 90 days |
| Database backups | Nightly backups kept for 60 days, plus storage snapshots for up to 30 days |
| Media backups | A weekly copy of uploaded media, replaced as the originals change |
| Your account and content | Until you delete them |
When you delete something, it disappears from the site straight away. Copies in backups are not edited one by one; they age out on the schedule above.
Your data, your choice
- Export. Download everything your account owns as one JSON file from Settings → Account (or
GET /api/me/exportwith a token). - Correct. Edit your profile and settings at any time.
- Delete. Delete your account from Settings → Account. Your sessions, linked sign-in methods, passkeys, push tokens, notifications, follows, blocks and mutes are removed, your API tokens are revoked, webhooks are switched off, and your profile is anonymised. You choose whether your public content stays up, credited to a deleted user (other people may have forked it under its open licence), or is removed from the site.
- Object or restrict. You can turn off optional emails and push notifications, hide mature content, and ask us to stop any processing based on legitimate interests.
- Complain. If you are in the EU, the UK or another place with a data-protection authority, you can complain to it. We would like the chance to fix things first: [email protected].
We answer requests within one month. We may need to confirm it is really you before acting.
Children
Incantory is not for children under 13 (or under 16 where local law sets that age). We do not knowingly keep accounts for them: if the age check fails at sign-up, the account is not created and the year of birth is not stored. If you believe a child has an account, write to [email protected] and we will delete it.
Security
Connections are encrypted (HTTPS). Session and API tokens are stored only as hashes. Admin tools are not reachable from the public internet. No system is perfectly secure; if we learn of a breach that affects you, we will tell you and the relevant authorities as the law requires.
Changes
If we change this policy in a way that matters, we will announce it on the site (and email account holders) before it takes effect. The date at the top shows the last change.
See also the cookie statement and the terms of service.