Privacy

Your records are yours.

The interesting part of privacy here is the tension between an append-only log and a right to erasure. It is addressed directly rather than avoided.

Last updated 16 August 2026

The short version

We collect the minimum needed to run the product and let you sign in. We do not sell data, we do not share it with advertisers, and the audit records you send us are yours.

What we collect

Account data. Your email address, so a sign-in link has somewhere to go, and the times you signed in and out.

Audit records. Whatever your deployment sends: by default metadata and hashes, not payloads. This is your data, held on your behalf. We do not read it, mine it, or train anything on it.

Site analytics. Aggregate page views and referrers, so we know which pages are worth writing. No advertising identifiers, and no cross-site tracking.

Erasure, against an append-only log

Payload deletion uses a tombstone: the content is destroyed, the hash remains, and the chain still verifies. A GDPR erasure request therefore does not break the record, which matters because a compliance control that conflicts with another compliance duty is not usable in practice.

The metadata of an event cannot be removed from a chained log without breaking it. That property is what you are buying. If it conflicts with an obligation you have, tell us before you send anything and we will work out the custody mode that fits.

Where it lives

Data is processed in the AWS Asia Pacific (Mumbai) region unless agreed otherwise in writing. Checkpoints are additionally written to write-once object storage in the same region.

Contact

Access and erasure requests go to augusta@4ugusta.agency. The controller is 4UGUSTA, Gaya, Bihar, India.

Questions about this page go to augusta@4ugusta.agency.