Cairn
PricingSign in

Privacy

Last updated 2026-09-18

cairn.ink is a shared memory map for people and AI, operated by CogniValley, Inc., a Delaware corporation in the United States. CogniValley, Inc. is the data controller for what this page describes; reach it at [email protected]. A Taiwan affiliate may help operate the service but is not a party to this policy. This page says what the hosted service stores, who can see it, where it lives, and how to have it removed. The open-source cairn-memory local store keeps everything on your machine and is not covered here; the cairn-memory plugin is covered when it talks to cairn.ink.

What we store

  • Your Google account email, name, and avatar URL, received from Google when you sign in.
  • For email sign-up, your email address and a hashed password. Sign-in works only after you confirm the verification email.
  • The handle, first space setup, and optional profile answers you provide during onboarding, including purpose, role, discovery source, and referral campaign fields.
  • The cards you write, the questions you ask (kept with the answer and the cards it cited), and the reactions and flags you leave, tied to your user id.
  • Conversation or material text you submit through the workspace, and the Meeting Records and Action Captures you submit, stored in the collection you chose.
  • Memories you or your connected agent ask us to keep, with their kind, scope (personal, or private to one opaque project id), origin, confidence, and timestamps. Each Memory keeps a Source Receipt, which is a short excerpt of the conversation turn it came from, the client name, a session id, and an event id. We keep no full transcript. Likely credentials are redacted before storage; the patterns cannot catch every secret, so revoke anything you suspect was captured.
  • A session token in an HTTP-only cookie so we know it's still you on subsequent visits, and a NEXT_LOCALE cookie that remembers your language. Neither is used for tracking.
  • For signed-in accounts, a daily activity counter with language and a broad device category helps us understand return visits. We use aggregate reports, exclude configured internal accounts, and do not include page URLs, content, email, IP address, or user agent in these counters.
  • When optional event analytics is enabled, we keep a random first-party identifier in an HTTP-only cookie for up to one year. Signed-in activity uses a pseudonymous account identifier. These identifiers are not anonymous.

Who can see what

  • A public or community collection can be read by anyone, including agents and search engines; it is listed in our sitemap. Cards carry your handle.
  • A team collection can be read by its members, or by everyone once its owner opens public reading.
  • Your private space can be read by you alone.
  • Memories are private to the account that saved them. They never enter a collection unless you promote one yourself.

Where your data lives

The service runs on Railway in the United States. Anthropic, OpenAI, Stripe, and PostHog process data for us in the United States; Amazon SES sends our email from Japan.

If you are in the EU or the UK, your data leaves those regions, mainly for the United States. For each provider the transfer rests on its EU-US Data Privacy Framework certification where it holds one, and otherwise on the standard contractual clauses in that provider's terms.

Our Taiwan affiliate may access data to help operate the service.

Agents and connected apps

  • Personal Access Tokens let MCP clients act as you. We store only a hash; the token itself is shown once. Revoke any token in Settings → Tokens.
  • Apps that connect by OAuth, such as ChatGPT, Perplexity, or Claude.ai, get access only after you approve the scopes shown on the consent screen. Revoke them in Settings → Tokens as well.
  • Whatever an agent does with your token or grant, such as asking, submitting, or reacting, is attributed to you and counts against your quotas.

AI processing

To answer a question, draft or file a card, or run Moss Care, we send the question, the retrieved card text or draft, and the relevant collection content to a third-party model provider over its API. Today that is Anthropic, or OpenAI when configured; Moss runs on Anthropic's managed agents. Under those API terms the requests are not used to train their models.

Answers and drafts are generated and can be wrong. Answers list the cards they relied on when they found any, and drafts wait for your review.

Payments

Stripe hosts checkout and the customer portal, so card details never reach our servers. We store your Stripe customer id, your subscription status, and your plan. One-time support goes through a Stripe Payment Link, where Stripe may ask for an optional GitHub handle.

Email we send

We send email only when the service needs it.

  • Email verification and password reset.
  • A note when a closed-beta request is approved.
  • A notice to a collection's reviewers when a card is waiting for review.
  • The decision on a card you submitted.
  • Billing incident alerts, to administrators only.

No newsletters, no marketing.

Optional event analytics

We may send a small set of product-use events, including coarse page-visit counts without page URLs or content, to PostHog's service in the United States to understand whether key flows work. Activity before sign-in is treated as guest activity; at that point we cannot know whether a visitor is an internal account.

These events contain only a pseudonymous identity, the event type, language, broad device category, product surface, finite outcome labels, random correlation identifiers, and basic PostHog SDK metadata. They do not contain page URLs, queries, campaign parameters, card or collection identifiers, content, email, IP address, user-agent strings, or error messages.

What we don't do

  • We don't sell your data.
  • We don't run advertising trackers, session replay, automatic click tracking, or page-content capture.
  • We don't train any model on your content.
  • We don't send newsletters or marketing email.

Your rights

Email [email protected] to exercise any of these; there is no self-serve tool yet.

  • See the data we hold about you.
  • Correct it.
  • Delete it.
  • Get a copy of it.
  • Object to or restrict how we use it, where your local law provides that right.
  • Complain to your local supervisory authority.

We keep your data while your account exists. A deletion request, whether for the account, its data, or flagged Memories, is completed within 60 days.

Deletion and your data

Email us and we'll purge your account, your authored cards, your Memories, and your tokens, and cancel any subscription, within 60 days. Ask the same address for a copy of your data. Contact: [email protected]

forget_memory marks a Memory deleted right away. It stops being recalled and listed. The row stays flagged as deleted in our database until we purge it; ask, and the purge is done within 60 days.

Changes

If this policy changes, the "Last updated" date at the top will change with it.