Privacy Policy
Last updated: [DATE]
This Privacy Policy explains how MetaWeaver Labs ([legal entity name, address]) (“MetaWeaver,” “we,” “us”) collects, uses, and protects information when you use the MetaWeaver hosted service at metaweaver.xyz (the “Service”). MetaWeaver is a private knowledge-base tool: it turns documents you provide into a searchable, workable knowledge base, using an AI provider key that you supply.
1. Information we collect
We aim to collect only what the Service needs to work.
Information you provide
- Account information — your chosen user name and email address. Passwords are stored only as a salted hash; we never see or store your plaintext password.
- Your content — the documents, files, and text you upload or connect, and the knowledge base MetaWeaver builds from them. This is yours; we store it to provide the Service to you.
- AI provider keys — if you add your own AI/embedding provider key (“bring your own key”), we store it encrypted at rest and use it only to make requests on your behalf.
- Contact submissions — if you use a contact or enquiry form, the name, email, company, and message you send.
Information collected automatically
- Usage & metering — storage used and knowledge-base size, to enforce plan limits and show you your usage.
- Payment information — if you subscribe to a paid plan, payments are processed by Stripe. We receive a customer and subscription identifier and plan status; we do not receive or store your full card number.
- Technical & security data — IP address, browser user-agent, and similar request metadata, used to operate the Service, prevent abuse, and secure accounts.
2. How we use information
- To provide, maintain, and improve the Service — including indexing your content and running the features you invoke.
- To authenticate you, secure your account, and detect and prevent abuse and fraud.
- To process payments and manage subscriptions.
- To respond to your support requests and enquiries.
- To send service-related communications (for example, email verification and password resets).
We do not sell your personal information, and we do not use your content to train our own or anyone else’s AI models.
3. AI processing & your keys
MetaWeaver works on your documents using an AI provider that you choose and pay for with your own key. When a feature sends content to your AI provider (for example, to answer a question or build a page), that content is transmitted to the provider you configured, and the provider’s own terms and privacy policy apply to what they receive. You are responsible for choosing a provider you trust with your content. If you run MetaWeaver against a local model, that content need never leave your own machine.
4. Sharing & sub-processors
We share information only with service providers that help us run MetaWeaver, and only as needed. These currently include:
- Hosting / infrastructure — [hosting provider], where the Service and its database run.
- Stripe — payment processing.
- Cloudflare Turnstile — bot / abuse protection on sign-up and similar forms.
- Email delivery — [email provider, e.g. Google Workspace], for transactional email.
- Your chosen AI provider(s) — as described in Section 3.
We may also disclose information if required by law, or to protect the rights, safety, and security of our users and the Service. [Confirm the sub-processor list and add a DPA/GDPR representative if serving EU users.]
5. Retention & deletion
We keep your account information and content for as long as your account is active. You can delete your content at any time from within the Service, and deleting your account permanently removes your account and its data. If you exceed a plan limit, we block new writes but never delete your existing data — you keep full read access to everything you have built. [State specific retention periods for backups, logs, and billing records.]
6. Security
We use industry-standard measures to protect your information, including encryption of stored provider keys, hashing of passwords, and access controls scoped to your account. No system is perfectly secure, but we work to protect your data and to limit what we collect in the first place.
7. Your rights
Depending on where you live, you may have rights to access, correct, export, or delete your personal information, and to object to or restrict certain processing. Much of this is available directly in the Service (usage, content deletion, account deletion). To make any other request, contact us at the address below. We will not discriminate against you for exercising these rights. [Tailor to GDPR / UK GDPR / CCPA-CPRA obligations as applicable, including the legal bases for processing and any “Do Not Sell/Share” statement.]
8. International transfers
We may process information in countries other than yours. Where required, we put appropriate safeguards in place for such transfers. [Specify hosting region(s) and transfer mechanism, e.g. SCCs.]
9. Children
The Service is not directed to children, and you must be at least [16 / 13 / age] to use it. We do not knowingly collect personal information from children.
10. Self-hosting
MetaWeaver can be self-hosted. If you run your own instance, you — not MetaWeaver Labs — control the data on it, and this Policy applies only to the hosted Service we operate.
11. Changes to this Policy
We may update this Policy from time to time. When we make material changes, we will update the date above and, where appropriate, notify you. Continuing to use the Service after changes take effect means you accept the updated Policy.
12. Contact
Questions about this Policy or your data? Email us at contact@ajaxweaver.com [or a dedicated privacy@ address].