Privacy
Last updated
Ponderly stores the map your AI builds, and almost nothing else. We run no language model on our servers, we never receive your conversations, and nothing you keep here is ever used to train anything.
Who we are
Ponderly is provided by ByCrux LLC ("we", "us", "our"). This policy explains what we collect when you use ponderly.ai and its connected services, how we use it, and what you can do about it. By using Ponderly you agree to it.
The short version
- We never see your conversations. Your own AI assistant talks to you; it sends us only the notes it writes to your tree. The rest of the conversation stays between you and whoever provides that assistant.
- No model runs on our servers. We make no calls to any language model. The only model we run is a small embedding model used to power search over your own notes. It is an index, never a judge.
- We do not train on your content. Not our own models, not anyone else’s.
- Writing requires a connection. Nothing can write to your forest unless you have connected an assistant to it, and disconnecting it stops that.
What we collect
Your account
- Identity. An email address or phone number, depending on how you sign in, plus the identifier our sign-in provider gives us.
- Profile. Your name, your handle, a profile image if you add one, and whether your profile is public or private.
What your AI writes
This is the substance of Ponderly, and all of it arrives because your AI wrote it while you were talking:
- Nodes — the subjects you explore, with the name and description your AI writes, and the history of earlier versions.
- Branches and tangents — how those subjects connect, and the one-line thought behind each connection.
- Visits — a timestamp each time a subject comes up, which assistant recorded it, and a line on the circumstance.
- References — links you or your AI attach to a subject.
- Sketches — the visual notes your AI draws, stored as HTML.
- Images — anything you upload to a node, and your profile image.
Operational data
- Connection records — which assistant you connected and when it was last active, so we can show you whether it is working.
- Request logs — records of calls made to our interface, kept for security, abuse prevention and debugging.
- Sharing state — who follows whom, invites you send, and accounts you block.
What we do not collect
We do not receive the text of your conversations with your AI assistant. We do not run advertising, we do not sell data, and we do not buy data about you from anyone else. We do not store payment card numbers.
How we use it
- To run the service — storing your forest, drawing it, and giving it back to you when you come to read it.
- To make it searchable — an embedding model running on our own servers turns your notes into an index so you can find them later.
- To let you share — rendering a public profile if you have one, and honouring follow requests.
- To show you what a link is — when a comment contains a link, our server fetches that page to read its title, summary and preview image. The site you linked to sees a request from us, identified as PonderlyBot, rather than from you.
- To keep it working — diagnosing failures, preventing abuse, and enforcing rate limits.
- To talk to you — sign-in codes and account notices. We will not send you marketing you did not ask for.
Who we share it with
We do not sell your information. We share it only with the providers who help us run Ponderly, each handling only what its job requires:
- Firebase (Google) — sign-in and identity.
- Neon — the database your forest lives in.
- Cloudflare — storage for images and sketch previews, and delivery.
- Google Cloud — hosting for our interface.
- Vercel — hosting for the website.
- X — for a link to a post on X, we ask X itself for the text of that post so we can show it. We send X the link; we send it nothing about you.
We may also disclose information if the law requires it, or to protect our rights, safety, or the safety of others. If Ponderly is ever acquired, your information may transfer with it, and we will tell you before it does.
What is public, and what is not
Your profile is public by default. Anyone with your address can see your profile and explore your forest. You can switch it to private at any time in Settings, and you can change it back.
With a private profile, your name, handle and follower count still appear at your address, so people can ask to follow you. Everything behind it — every node, every sketch — answers as though it does not exist.
Keeping and deleting
Ponderly is built so that nothing is erased by accident. When you prune a node, merge two, or replace a sketch, we mark the previous state as removed rather than deleting it. That means removed things are retained on our side; it does not mean the app can put them back for you.
When you ask us to delete your account, we delete your forest and the files that belong to it, including the retained history above. Some records — security logs, and anything we are required to keep — persist for a limited period.
Your rights
Depending on where you live, you may have the right to see the information we hold about you, correct it, delete it, or take a copy elsewhere. Write to hello@bycrux.com and we will act on it. We will not treat you differently for asking.
Security
Traffic is encrypted in transit. Access to a forest is scoped to its owner, and to the people that owner has approved. Files are served through links that expire. No system is perfectly secure, and we will not pretend otherwise — but we will tell you promptly if something happens that affects you.
International transfers
We operate in the United States, and our providers may process data in other countries. Wherever it goes, this policy still applies to it.
Children
Ponderly is not for anyone under 13, and we do not knowingly collect their information. If you believe a child has given us information, write to us and we will remove it.
Changes
If we change this policy we will update the date at the top, and we will tell you directly if the change is a significant one.
Contact
Questions about any of this go to hello@bycrux.com, and reach ByCrux LLC.