Privacy Policy
This is the current public revision. Human and machine views carry the same policy facts.
- Version
- 1.0
- Effective
- Language
- en
Privacy Policy
This Policy explains how personal data is handled by the hosted ai_stp service. The controller and operator is ai-engineers-guild, identified by its public GitHub organization and operating the service from Kazakhstan. Privacy requests: [admin@aiguild.space](mailto:admin@aiguild.space).
Data covered by this Policy
Depending on how you use the service, the following data may be processed:
- authentication data — OAuth provider, stable provider identifier, verified email address, and authentication timestamps; - profile data — optional display name, avatar URL, and information you choose to make public; - account and security data — internal account, session and device identifiers, device type and label, user agent, session state, and approximate city or country when available; - service content and activity: configurations, metadata, licenses, publication records, reports, complaints, grants, reactions, and other actions associated with the account; - communications: messages and information sent to support, privacy, security, or abuse contacts; - technical data needed to deliver and protect a connection. A source IP address may be processed transiently by the network and rate limiter, but the ai_stp application database does not store it as account or consent evidence.
The service does not intentionally request government identifiers, payment data, health data, biometric data, precise location, passwords for Google or GitHub, private source code, environment values, or secrets. Do not submit such data in public content.
Sources
Data comes from you, your selected OAuth provider, your browser or CLI client, service security controls, and other users when they submit a report, complaint, or access grant involving your public content.
Purposes and legal grounds
Data is processed to:
- create and authenticate an account and provide requested service features; - maintain sessions, authorize devices, protect accounts, prevent abuse, and investigate security events; - attribute, publish, index, distribute, moderate, and remove content; - answer support, privacy, legal, and rights requests; - establish what legal-document revision was accepted; - comply with applicable law and protect legal claims.
Depending on the jurisdiction and activity, the legal ground is performance of the service agreement, your consent, the Operator's legitimate interest in operating and securing a public service, or compliance with a legal obligation. Consent may be withdrawn, but withdrawal does not invalidate prior lawful processing and may make an account impossible to provide.
Disclosure and processors
Data is disclosed only as needed to:
- Google or GitHub for authentication under their own terms and privacy rules; - hosting, object-storage, network, email, monitoring, backup, or support providers acting for the Operator; - other users when you deliberately publish profile or catalog content; - competent authorities or affected parties when disclosure is legally required or reasonably necessary to protect rights, safety, and service integrity.
Personal data is not sold. The service does not run behavioural advertising or use personal data for advertising profiles.
Location and international transfers
The primary service infrastructure and database are intended to be located in Kazakhstan. Authentication and other necessary providers may process data in other countries. Those countries may apply different data-protection laws. The Operator limits transfers to what is necessary for the service and uses the available contractual, consent-based, or other lawful transfer mechanism required by applicable law.
Retention and deletion
Account and profile data are kept while the account is active. Sessions and their cookies normally expire within 14 days or earlier on logout or revocation. Published content is kept until it is deleted, withdrawn, moderated, or the service ends. Legal acceptance, moderation, complaint, security, and audit records may be retained after account closure only for the period reasonably needed to demonstrate compliance, protect the service, resolve disputes, or meet law. Backup copies are isolated from ordinary use and removed through the applicable backup cycle.
When a purpose ends, data is deleted, anonymized, or retained only under another valid legal requirement. The Operator will publish a more specific retention schedule before introducing processing that requires one.
Your rights
Subject to applicable law, you may request confirmation, access, correction, export, restriction, objection, withdrawal of consent, or deletion. You may also complain to a competent data-protection authority. California residents may additionally request information about collection and disclosure and are protected from discrimination for exercising applicable rights. Because ai_stp does not sell or share data for cross-context behavioural advertising, there is no sale or advertising-sharing opt-out to exercise.
Send a request from the email associated with the account to [admin@aiguild.space](mailto:admin@aiguild.space). Additional verification may be required. The Operator will respond within the period required by applicable law.
Security
The service uses access controls, limited data collection, secret separation, encrypted transport, session expiry, auditable privileged actions, and other reasonable organizational and technical safeguards. No online system is perfectly secure. Report suspected compromise to [admin@aiguild.space](mailto:admin@aiguild.space).
Children
The hosted service is for people aged 18 or older and is not intended to collect children's personal data knowingly. Contact the Operator if such data may have been submitted.
Versions
Each version is retained as a separate Markdown file in the public Git repository. Material changes create a new immutable published revision and, where required, a new request for acceptance.