Security, privacy and data ownership
Protect account-owned data, source rights, media and sensitive locations.
On this page
The account owns application data, but ownership of a record is not a license to republish every source behind it.
Sources and media
Keep provenance, capture time, permitted use and retention with evidence. Discovered image URLs, downloaded files, hosted assets, rights-cleared media and approved publication are distinct states. A research citation does not grant trademark, copyright or publicity rights.
Raw provider payloads and private storage addresses must not appear automatically in public results.
People and location
Customer/ICP hypotheses are not verified identities or consent to contact. Precise device traces, operator verification evidence, private recordings and participant histories require narrower access than aggregate territory or performance data.
Purpose and scope matter even when an application can authenticate.
Secrets and sharing
Developer sign-in uses a separate host-only session, not the main-site login. Its maximum lifetime is seven days, with a twelve-hour idle limit; sensitive administration requires proof within fifteen minutes. Signing out revokes the developer session, not the main-site session or account-owned API keys. Current membership and account status remain independent access checks.
Keep application keys on trusted servers. Do not include them in browser bundles, URLs, account names, analytics or agent prompts. Share only explicitly authorized artifacts; a signed preview is not public publication authority.
Limits of these statements
These principles are the intended contract, not a certification or blanket compliance claim. Storage, retention, deletion, export and third-party processing need their concrete implemented policies. Public documentation and search contain approved public content only; internal and restricted partner procedures are not indexed.