Privacy policy
This page says what we store, where it runs, who else touches it and when, and how you get it out. It is written to be read, not skimmed past. If something is unclear, email info@primaxiom.ai.
Who we are
PrimAxiom Labs B.V., a company in Amsterdam, the Netherlands, runs ReasonGraph Cloud and is the controller for your account data. For the facts you store through the API, you are the controller and we are your processor.
What we store
| Data | Why | Kept until |
|---|---|---|
| Account: email, name if you gave one, sign-in identifiers | Sign-in, notices about the Service | Account closed |
| API keys (hashed), key names, per-key request counts | Authentication, quotas | Revoked or account closed |
| Facts you store, the entities and cause→effect spans extracted from them, embeddings, session names, timestamps and supersede history | The memory itself | You delete them, or 30 days after account closure |
| Monthly request counts per workspace | Plan limits | 13 months |
| Billing: Stripe customer id, plan, invoices | Payment, tax law | 7 years for invoices (Dutch tax rules) |
| Server logs: IP address, request path, status, timing | Security, debugging | 30 days |
We do not use your facts to train models and we do not sell any data. We do not run advertising or tracking scripts on the site.
Where it runs
Facts, extracted entities and embeddings live in a database on servers we rent and operate ourselves, currently in the EU. Entity and cause→effect extraction runs on those same servers with small models, so storing and querying memory does not send your facts to any AI provider. More regions may follow; if a new region would apply to your workspace we tell you first.
When an LLM provider is involved
Two features send content to a large language model run by a third-party provider. Both are off unless you use them:
- Synthesized answer (the "answer" option on discover): the facts retrieved for that one question and the question itself are sent to the provider, which returns a written answer.
- Chat (the console's Chat tab and
POST /chat): your messages and the facts recalled for that conversation are sent to the provider, which returns the reply.
The provider is currently Groq, Inc. (United States), used under terms that do not allow training on the content. We may switch or add providers, including EU-hosted ones, and will keep this section current. The contradiction check on write (the resolve-conflicts option) runs on our own servers with a small model we fine-tuned; it does not use an outside provider. Nothing else reaches an LLM.
Providers we use
| Provider | What for | What they see | Where |
|---|---|---|---|
| A cloud hosting provider | Servers and database | Everything on the servers, encrypted at rest at the volume level | EU |
| Clerk, Inc. | Sign-in and accounts | Email, name, sign-in method, IP at sign-in | United States, with EU data transfer safeguards |
| Stripe Payments Europe, Ltd. | Payments, invoices, customer portal | Name, email, payment details, billing address | EU / United States |
| Groq, Inc. | Optional LLM features above | Only the content described above, only when you ask | United States |
Where a provider is outside the EU we rely on the EU standard contractual clauses or the EU–US Data Privacy Framework. A full list with contract details is available on request, as is a signed data processing agreement.
Your rights and how to use them
- See and export: the API returns your facts as plain text; the console lists your keys and plan. Ask us for an account export by email.
- Correct or delete facts: supersede, delete and purge through the API or console at any time. Purge removes the entities only that fact mentioned. Superseded facts stay in history for time travel until purged.
- Delete your account: from the console user menu, or by email. Facts and keys are deleted within 30 days; invoices are kept as the tax law requires.
- Object or complain: email us first; you can also contact the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).
We answer requests within 30 days.
Security
Traffic is encrypted in transit. API keys are stored as hashes and shown once. Servers run with a firewall, automatic updates and encrypted volumes, and only the founder has access. If a breach affects your data we notify you without undue delay and within the time the law requires.
Cookies
The console uses the session cookies needed for sign-in (set by Clerk). The landing and pricing pages set no cookies. We do not use analytics cookies.
Changes
When this policy changes in a way that matters we email account holders before it takes effect. Older versions are available on request.
Contact
PrimAxiom Labs B.V., Amsterdam, the Netherlands · info@primaxiom.ai