Privacy policy

ReasonGraph Cloud · PrimAxiom Labs B.V., Amsterdam, the Netherlands · last updated 7 September 2026

This page says what we store, where it runs, who else touches it and when, and how you get it out. It is written to be read, not skimmed past. If something is unclear, email info@primaxiom.ai.

Who we are

PrimAxiom Labs B.V., a company in Amsterdam, the Netherlands, runs ReasonGraph Cloud and is the controller for your account data. For the facts you store through the API, you are the controller and we are your processor.

What we store

DataWhyKept until
Account: email, name if you gave one, sign-in identifiersSign-in, notices about the ServiceAccount closed
API keys (hashed), key names, per-key request countsAuthentication, quotasRevoked or account closed
Facts you store, the entities and cause→effect spans extracted from them, embeddings, session names, timestamps and supersede historyThe memory itselfYou delete them, or 30 days after account closure
Monthly request counts per workspacePlan limits13 months
Billing: Stripe customer id, plan, invoicesPayment, tax law7 years for invoices (Dutch tax rules)
Server logs: IP address, request path, status, timingSecurity, debugging30 days

We do not use your facts to train models and we do not sell any data. We do not run advertising or tracking scripts on the site.

Where it runs

Facts, extracted entities and embeddings live in a database on servers we rent and operate ourselves, currently in the EU. Entity and cause→effect extraction runs on those same servers with small models, so storing and querying memory does not send your facts to any AI provider. More regions may follow; if a new region would apply to your workspace we tell you first.

When an LLM provider is involved

Two features send content to a large language model run by a third-party provider. Both are off unless you use them:

The provider is currently Groq, Inc. (United States), used under terms that do not allow training on the content. We may switch or add providers, including EU-hosted ones, and will keep this section current. The contradiction check on write (the resolve-conflicts option) runs on our own servers with a small model we fine-tuned; it does not use an outside provider. Nothing else reaches an LLM.

Providers we use

ProviderWhat forWhat they seeWhere
A cloud hosting providerServers and databaseEverything on the servers, encrypted at rest at the volume levelEU
Clerk, Inc.Sign-in and accountsEmail, name, sign-in method, IP at sign-inUnited States, with EU data transfer safeguards
Stripe Payments Europe, Ltd.Payments, invoices, customer portalName, email, payment details, billing addressEU / United States
Groq, Inc.Optional LLM features aboveOnly the content described above, only when you askUnited States

Where a provider is outside the EU we rely on the EU standard contractual clauses or the EU–US Data Privacy Framework. A full list with contract details is available on request, as is a signed data processing agreement.

Your rights and how to use them

We answer requests within 30 days.

Security

Traffic is encrypted in transit. API keys are stored as hashes and shown once. Servers run with a firewall, automatic updates and encrypted volumes, and only the founder has access. If a breach affects your data we notify you without undue delay and within the time the law requires.

Cookies

The console uses the session cookies needed for sign-in (set by Clerk). The landing and pricing pages set no cookies. We do not use analytics cookies.

Changes

When this policy changes in a way that matters we email account holders before it takes effect. Older versions are available on request.

Contact

PrimAxiom Labs B.V., Amsterdam, the Netherlands · info@primaxiom.ai