Privacy Policy
Effective July 26, 2026
LibRAGraph is a self-hosted knowledge vault. Because your content is indexed and stored on infrastructure you control, there is very little about you that we hold at all. This policy says precisely what we do hold, and what we never receive.
The short version
We hold the account details needed to identify you and, if you buy something, to bill you. We do not receive the content in your vault, and we do not receive the content of any service you connect to it. We do not sell personal information, we do not run advertising, and we do not use your content to train models.
Scope
This policy covers this website and the optional hosted service that a vault can be paired with for sign-in, connection setup, and remote reach.
It does not cover the vault software itself when you run it standalone. A standalone vault talks to nobody: it holds your content under your own credentials on your own infrastructure, and we have no visibility into it whatsoever.
This website
This site is static. It sets no cookies, runs no analytics, embeds no tracking pixels, and has no login or forms.
It loads its typefaces from Google Fonts, so your browser makes a request to Google that includes your IP address and user-agent. That is the only third-party request the site makes. Nothing else on the page is loaded from another host.
What we collect in the hosted service
- Account and profile. Your name and email address, and your organization membership and role. Where you sign in through an identity provider, we receive these from that provider as part of sign-in.
- Billing. Where you purchase a subscription or credits, our payment processor handles the transaction and we retain the resulting subscription, invoice, and credit-balance records. We never see or store your full card number.
- Operational metadata. Records needed to run the service and bill it accurately: which vaults exist, when they connected, request and traffic volumes, error and audit events. These reference subjects by opaque identifier — never by the content of a record, and never by personal values.
- Correspondence. What you send us when you contact us for support, and our replies.
What we do not receive
- The content of your vault. Documents, mail, messages, files, search indexes and the knowledge graph built from them live in your vault. Our hosted service is architecturally barred from reading them; no role we hold grants access to vault content.
- Content from the services you connect. Your vault fetches that content from the provider directly and indexes it locally. It does not pass through us.
- Your credentials in readable form. We do not receive your passwords for any service. Provider client secrets are never held by our hosted service in plaintext, and access tokens are delivered to your vault encrypted to your vault’s own key.
Services you connect
When you connect an external service to your vault, you authorize that access yourself, on that provider’s own consent screen, which shows you exactly what is being requested. You can withdraw it at that provider at any time; your vault keeps whatever it already indexed until you delete it.
The access is used for one purpose only: your vault reads the content you authorized and indexes it into your vault, so that you can search it and the AI tools you choose can answer from it. We do not read that content, retain it, transfer it to anyone, sell it, use it for advertising, or use it to train or improve any machine-learning model.
Where LibRAGraph accesses Google user data, our use and transfer of that data to any other app adheres to the Google API Services User Data Policy, including its Limited Use requirements.
Why we use what we collect
- To authenticate you and establish what you are permitted to do.
- To provision, pair and reach your vault, and to keep that connection working.
- To meter usage, invoice accurately, and process payments.
- To detect and prevent abuse, fraud and service outages.
- To answer you when you contact us.
- To meet legal and accounting obligations.
We do not use any of it for advertising, and we do not build profiles for resale.
Who else is involved
We do not sell personal information and we do not share it for anyone else’s marketing. We use a small number of service providers to run the service, each with access limited to what its function requires:
- Amazon Web Services — cloud hosting and managed identity for the hosted service.
- Stripe — payment processing, where you purchase.
- Google Fonts — typefaces for this website, as described above.
We may also disclose information where we are legally required to, or where it is necessary to protect the rights and safety of our users or ourselves.
Retention
We keep account and profile records for as long as your account is open. Billing and audit records are kept for as long as accounting and legal obligations require. Correspondence is kept as long as it is useful for support history. When you close an account we delete or anonymize what we are not required to retain.
Content in your vault is not ours to retain or to delete — it is yours, on your infrastructure, and closing your account with us does not touch it.
Security
Personal information is encrypted in transit and at rest. Secrets are never written to logs or error responses, which reference subjects by opaque identifier. Administrative access to the hosted service requires multi-factor authentication, is scoped and time-limited, and is audited. See Security for the architectural boundaries.
Your choices and rights
You can ask us to give you a copy of the personal information we hold about you, correct it, delete it, or restrict how we use it, and you can object to a particular use. Where the law gives you a right not to have information sold or shared, note that we do neither.
Email info@libragraph.com and we will respond. Because so little of your data is ours to hold, most deletion requests are satisfied by deleting your account record — your content was never here.
International transfers
The hosted service runs in the United States. If you use it from elsewhere, the account and operational information described above is processed there. Your vault’s content stays wherever you chose to run your vault.
Children
The hosted service is not directed at children under 13, and we do not knowingly collect personal information from them. If you believe we have, contact us and we will delete it.
Changes
If we change this policy we will update the effective date above, and for material changes we will notify account holders. Ask us for a previous revision and we will send it to you.
Contact
Questions, requests, or complaints about privacy: info@libragraph.com.