PRIVACY
How Epinoia handles your dataEpinoia is a small, private, invite-only research tool built and run by GOODGLYPH. This page says plainly what we do and, more importantly, what we cannot do with your data. It is written to be read, not to cover us.
WHAT WE CANNOT SEE
Almost everything. Your messages, your notes, the text and connections on canvases, the images you share, and the names you give rooms and discussions are all encrypted in your browser before they reach us. We store only scrambled text we genuinely cannot read. This is not a promise to behave; it is how the system is built. A database dump or a legal demand for your room contents would return nothing readable.
WHAT WE CAN SEE
A small amount of information has to stay readable so the app can route messages and notifications: the display names people choose, timestamps, who is in a room, when they are active, and how many messages a discussion holds. We can also see a room's technical id and, briefly, the IP address a request comes from (used only to rate-limit the front door and the request form against brute force and spam, then discarded). We do not build profiles from any of this.
THE ONE EXCEPTION: THE READER
The Reader is your own AI, and you bring your own model. If you connect a hosted model (Claude, OpenAI, Perplexity, Kimi), your question and your API key pass through our server on the way to that provider. They are never stored and never logged. If you run a local model on your own machine, it never touches our server at all. Your key lives only in your browser. Separately, if you turn on web search for a Reader question, that question is sent to our server and on to a search provider to look it up, the same way any web search works. This is true even if you use a local model, so a searched question does leave your machine. Web search is off unless you turn it on, one question at a time.
THE OTHER EXCEPTION: ASKING FOR AN INVITE
If you use the public request page to ask for access, what you type there (your name, how to reach you, and anything you say about your work) is stored as ordinary readable text, not encrypted. It has to be: we cannot write back to someone we cannot read. This is the only readable personal information Epinoia holds. Nobody but the operator can see it, it is used for nothing except replying to you, and it is deleted once you have been answered. Ask at the address below and it goes sooner.
WHERE YOUR DATA LIVES
Epinoia runs on Cloudflare (Workers, D1, and KV storage). The database is configured in Cloudflare's European region. We use no analytics, no advertising, no third-party trackers, and no third-party scripts of any kind.
COOKIES
One functional cookie remembers that you passed the front door, so you are not asked for your password or code on every page. That is its only job. It is not used for tracking.
KEEPING AND DELETING
The owner of a room can delete it for everyone, and deletion is real: because we only hold scrambled text, deleting it is deletion, not a hidden copy. The "leave every room on this browser" button wipes your local keys and identity. Your `.md` exports are your own backup, stored wherever you save them, never on our server. To have anything associated with you removed, delete your rooms or write to the address below.
WE DO NOT SELL OR SHARE YOUR DATA
We do not sell, rent, or share your data with anyone. There is no advertising and no data broker. The only third party in the picture is Cloudflare, which hosts the infrastructure and processes data on our behalf under its own data-protection terms.
THIS IS A BETA, HONESTLY
Epinoia is solo-built and has not had an outside security review yet. It is also a web app, which means each time you open it you are trusting the code the server sends your browser. That is true of every web app that encrypts in the browser. Treat Epinoia as a private space among people who already trust each other, not as a safe place for material that would put someone at risk. The `/security` page explains this in more detail.
CHANGES AND CONTACT
If this page changes, the build tag below changes with it. Questions, or a request to remove your data: email hello@epinoia.app with "Epinoia" in the subject.
HOW THIS STAYS PRIVATETERMS← THE DOOR
BUILD F6D5480