Privacy Policy
Last updated September 9, 2026
Cratonix Vault stores something unusually personal: your conversations with AI assistants. This policy sets out what we collect, how it is protected, who can see it, and how you remove it, as the product works today.
Who we are
Cratonix Vault is operated by Cratonix AI Inc., a Delaware corporation. For anything in this policy, write to support@cratonix.ai.
What we collect
Only what the product needs to work. There is no analytics, advertising, or third-party tracking.
- Account details. Your name and email address. A password, if you set one, is stored only as a salted hash. If you sign in with Google, we receive your name and email from Google and nothing more.
- Your files. The export archives you upload, with their filename, size, and source assistant.
- What our engine produces from them. If you build a memory bank, our backend engine reads the conversations in your archives and keeps a condensed copy of each, a short summary, and the resulting themes and portrait. Nothing is read until you ask.
- Security records. Your sessions and a log of sign-ins, password and two-factor changes, and file actions, each with IP address, browser, and time. You can read it under Settings.
- Two-factor secrets, encrypted at rest, if you turn it on.
- Waitlist. The email address you give us when asking for an invite.
We do not ask for a payment method, phone number, date of birth, or postal address, and we buy nothing about you from anyone.
How we use it
To run the service and nothing else: signing you in, storing and returning your files, enforcing your quota, protecting your account from abuse, and the few transactional emails the service needs.
We do not train models on your data, sell it, rent it, or share it for advertising. Any change to that would require your explicit opt-in.
Your conversations and AI processing
Building a memory bank is automated end to end. No human at Cratonix AI reads your conversations to produce it, and no human reads, samples, or spot-checks what you upload.
Your memory bank is built by Cratonix AI’s proprietary backend engine, which uses Anthropic’s models under Anthropic’s Zero Data Retention commitment for our production use of its API: Anthropic does not retain the conversation text we send or the summaries it returns beyond processing each request, and does not use either to train its models. If you never build a memory bank, nothing is sent to Anthropic.
A person here could see your content in exactly two situations: you ask us to, for support and only for as long as that takes, or we are legally compelled to. Error reports are stripped of your content before they are stored, and your activity log records that something happened, never what it said.
Controls you hold
- Privacy filters. Under Settings, Privacy, you can have identifiers such as card numbers, government ID numbers, and API keys removed from your memory bank and from the text sent for summarizing, and keep sensitive topics such as health, religion, and politics out of the bank. Both are reversible.
- Taking your memory elsewhere. Your memory bank moves into another assistant through your own clipboard, from your browser. Cratonix AI Inc. sends nothing on your behalf.
- Deletion. Delete any file, any memory, or your whole account yourself, from Settings, at any time.
Where it lives
Your data is stored encrypted at rest in the United States and is reachable only over HTTPS. Files are never public: every download is authenticated and streamed through the application.
This is not end-to-end encryption. Cratonix AI Inc. holds the keys and is technically able to access the files you store, and does so only at your request or under legal compulsion.
Service providers
A small number of providers process data on our behalf: infrastructure for hosting, database, and file storage; email delivery for verification, password-reset, and sign-in messages, which sees your address and the message but never your files; Anthropic, as described above; and Google, only if you sign in with it. Each is bound by a data processing agreement. A current list is available on request.
How long we keep things
Your files stay until you delete them. A deleted file can be restored for 30 days and is then permanently removed; you can also delete one permanently at once. Abandoned uploads are discarded within a day.
Deleting your account removes your account, your file metadata, every stored file, and your memory bank, immediately and irreversibly. Security log entries are kept briefly where needed to investigate abuse, then removed.
Your rights
You can change your name, download any file, sign out devices, review your activity, and delete your account yourself at any time. Depending on where you live, you may also have the right to a portable copy of your data, to correction, to restriction of processing, or to complain to a supervisory authority. Write to support@cratonix.ai and we will respond within 30 days.
Children
Cratonix Vault is not intended for anyone under 16, and we do not knowingly collect their information. If you believe a child has created an account, write to us and we will remove it.
Changes to this policy
Material changes are dated above and emailed to registered users before they take effect. The service is invite-only while in early access; this page is kept current with what the code actually does.