1. Overview
TimeCapsule AI-Frames is a knowledge-to-action platform that lets you connect everything in one flow. We respect your privacy and provide data control tailored to three modes of usage:
- Local-only: No data leaves your device
- External API usage: With your own API keys
- Subscription usage: Hosted processing with shared AI-Frames/KBase collaboration
2. Information We Collect
2.1 Local Users
- All processing and data are stored locally in your browser or device.
- We do not access, transmit, or analyze your documents or interactions.
2.2 BYOA/API Key Users
- We may temporarily process prompts and responses via your chosen API provider.
- Your API keys are stored only if explicitly permitted and encrypted at rest.
- We do not retain document content unless necessary for a specific session or feature.
2.3 Subscription Users
- We collect basic authentication data (email, name) via OAuth providers.
- Prompts and results may be stored temporarily for credit accounting, debugging, or improving user experience.
- We retain subscription data only as long as required to deliver shared AI-Frames, Knowledge Base access, billing, or legal compliance.
- We retain only the information required to provide access to AI-Frames services, shared workspaces, and collaboration features.
2.4 Shared AI-Frames & Knowledge Bases
- Sharing features let you invite collaborators to specific frames, chapters, or Knowledge Base entries. We store the minimum access metadata necessary to route those invitations.
- Shared content inherits your existing privacy settings and can be revoked at any time from the workspace settings.
- Access logs and sharing metadata are removed when you revoke sharing or delete the asset.
3. Cookie Usage
- Essential Cookies: Used for authentication, session management, and core functionality.
- Analytics Cookies (Optional): Used only with consent. These help us improve performance and UX. No cross-site tracking.
4. How We Use Your Data
- To provide requested services (AI-Frames generation, document interaction, shared workspace notifications)
- To personalize your experience and provide support
- To comply with legal requirements or respond to lawful requests
5. Data Security
- All transmissions use HTTPS
- Sensitive data (API keys, tokens) are encrypted
- Local-first architecture is prioritized whenever possible
- All data is automatically deleted from our servers after 30 days
6. Your Rights
6.1 For EU Users (GDPR)
- Right to access, correct, delete, or restrict your data
- Right to data portability and to object to processing
6.2 For California Users (CCPA)
- Right to know what data we collect and how we use it
- Right to delete personal information and opt-out of sale (we don't sell data)
7. Data Retention
- Analytics: Retained for 26 months (if opted-in)
- Session and auth: Retained while active or until deletion
- Uploaded documents: Not stored unless explicitly uploaded for collaboration or sharing
- Subscription data: Retained only as long as needed to provide collaboration, billing, or legal compliance.
8. Updates
This policy may change as our features evolve. We'll notify you of material changes via in-app notification or email.