Skip to content

Legal

Privacy policy

How we handle your data, and specifically how we handle your source code, which is the part that actually matters for a tool like this.

Last updated 8 August 2026

A note on this document. Graphlit is pre-launch. This policy describes how the product is designed to handle data and is written to be accurate rather than to be broad. It has not yet been reviewed by a qualified lawyer, and it will be before general availability. If anything here matters to a decision you are making, ask us and we will answer specifically.

The short version

We collect the minimum needed to run the product and talk to you. We do not sell your data, we do not share it with advertisers, and we do not train models on your code. You can export everything and delete everything, at any time, without asking a person.

What we collect

You give us

  • Account and contact details: your email address, and optionally your name, company and role when you fill in a form.
  • What you tell us: the content of messages you send us and what you say you are building.
  • Project content: sketches, photographs of drawings, the architecture graphs derived from them, and the source code you import or that is generated for you.
  • Payment details: handled entirely by our payment processor. We never see or store your card number.

We collect automatically

  • Basic technical data: IP address, approximate location derived from it (country, and region or city where available), browser and device type, and timestamps. Used for security and rate limiting, and to understand where our visitors and customers come from.
  • Where you arrived from: the referring website and any campaign tags on the link you followed, recorded once on your first visit. It tells us which places send people to us.
  • Product usage: which features are used and whether operations succeed or fail, in aggregate, so we know what is broken.

We do not use third-party advertising trackers, and there are no advertising cookies on this website.

Your source code

This is the section worth reading twice, because it is the one that is different for a tool like this.

  • You own your code. Importing a repository or generating one gives us no ownership of it and no licence beyond what is needed to operate the service for you.
  • Access is scoped and purposeful. Your code is processed to build the architecture graph, run analysis, execute the build tasks you ask for, and verify the result. Nothing else.
  • Staff access is exceptional. No one on our team reads your code as a matter of routine. It happens only when you ask for support and grant it, or where we are legally compelled. Either way it is logged.
  • Deletion is real deletion. Delete a project and its code, graph and analysis are removed from live systems immediately and from backups within 30 days.
  • Local-first where possible. Photographs of sketches are read on your own machine first. Where that read succeeds, the image never leaves your computer.

AI models and training

  • We do not train on your code. Not our models, not anyone else's. Your code is never contributed to a training corpus.
  • Some features send content to a model provider in order to work: reading handwriting, inferring architecture, writing a feature. That happens under business terms that prohibit training on the content we send.
  • Most of the product never calls a model at all. The graph assembly, drift detection, contract checks, health scan and security rules are ordinary deterministic code that runs without contacting any model provider.
  • You can see which is which. Features that involve a model are labelled in the product, not buried in a policy.

How we use your data

  • To provide the product and the features you ask for.
  • To keep it secure: abuse prevention, rate limiting, fraud detection.
  • To fix things, using aggregate error and usage data.
  • To reply to you when you contact us.
  • To send you the emails you asked for. We do not send marketing you did not.
  • To meet legal obligations.

Where the law requires a legal basis, ours is: performance of a contract (running the product), legitimate interests (security and improvement), consent (optional emails), and legal obligation.

Who we share it with

We do not sell your personal data or share it for advertising. We use a small number of processors to operate:

PurposeWhat they receive
Cloud hosting and databasesEverything needed to run the product, encrypted in transit and at rest
Transactional emailYour email address and the message content
Model providersOnly the content required by the feature you invoked, under no-training terms
PaymentsBilling details, handled by the processor; we never see card numbers
Error monitoringDiagnostic data, with source content scrubbed

We may also disclose data where legally required, or as part of a merger or acquisition, in which case you will be told before your data moves.

Everyone in that table is a processor: they handle data on our instructions in order to run a part of the product, and they may not use it for their own purposes. Nobody in it is a commercial partner.

What is not on this list, and will not appear on it silently

  • We have no paid partnerships, referral deals or revenue-sharing arrangements with anyone, as of 8 August 2026. Nothing in the product recommends a tool because we were paid to.
  • We do not sell data, and we do not have a price for it. Not personal data, not aggregate data, not anonymised data.
  • No advertising, analytics or data-broker network receives anything. There is no ad pixel, no third-party tracker and no cross-site identifier on either the site or the product.
  • Any future sharing outside this table needs your consent first: asked for specifically, refusable without losing access to anything you already pay for, and withdrawable afterwards.

This section is dated deliberately. If it ever stops being true, the honest thing is a changed date and a notice, not a quietly broadened sentence. See changes to this policy.

How long we keep it

  • Project content: while your account is active. Deleted on request, immediately from live systems, within 30 days from backups.
  • Account data: while your account exists, then 30 days.
  • Waitlist entries: until you ask to be removed, or 24 months after launch, whichever comes first.
  • Contact messages: 24 months, so we have context if you write again.
  • Billing records: as long as tax law requires, typically 7 years.
  • Security logs: 90 days.

Your rights

Wherever you live, we will honour requests to:

  • Access a copy of your data.
  • Correct anything inaccurate.
  • Delete your data and your account.
  • Export your projects and code in a portable form.
  • Object to or restrict certain processing.
  • Withdraw consent for optional emails at any time.

Email prin@cipher.academy and we will respond within 30 days. We will not ask you why, and we will not charge you. Depending on where you live you may also have the right to complain to a data protection authority.

Security

  • Encrypted in transit (TLS) and at rest.
  • Access to production is limited, authenticated and logged.
  • Tenant data is isolated, and that isolation is covered by automated tests.
  • Third-party dependencies are monitored for known vulnerabilities.
  • If a breach affects you, we will tell you and the relevant authority within 72 hours of becoming aware.

No system is perfectly secure, and anyone claiming otherwise is worth distrusting. If you find a vulnerability, see our security page.

Cookies

This website uses no tracking or advertising cookies. The only thing stored in your browser is your light or dark theme preference, which stays on your device and is never sent to us. Inside the product, a session cookie keeps you signed in. That one is strictly necessary and cannot be turned off without signing out.

Children

Graphlit is not directed at children under 16, and we do not knowingly collect their data. If you believe a child has given us information, email us and we will delete it.

Changes to this policy

We will update the date at the top when this changes. If a change materially affects how we handle your data, we will email you before it takes effect rather than relying on you re-reading this page.

Contact

Questions, requests, or complaints: prin@cipher.academy. A person reads it.

Graphlit · India