Privacy policy
What Gubbins collects, why it collects it, how long it keeps it, who else sees it, and what you can do about all of that. In plain English, because a policy nobody reads protects nobody.
What this product does that you should know about
Four things sit at the top rather than in the small print, because they are the things a reasonable person would want to know first.
1. Your Memory is lent to somebody else's AI, and that is the whole point of Gubbins. It holds what your assistants have learned about you, which is deep: clients, family, money, dates. You grant a key to an assistant, you choose what that key reaches, every read is receipted, and you can revoke it. Nothing enters your Memory without you accepting it first, and every memory is yours to correct or delete.
2. Gubbins holds none of your files. Your documents stay in your own store. What Gubbins keeps is a name, a short description and an address. When an agent needs a document it is lent a reach into one folder, for fifteen minutes at the most, and never the sign-in you gave your store.
3. Every read is receipted, and there is one honest limit to that. You can see which key read your Memory, when, and under which grant. But because a file is read at your store rather than here, a receipt records that access was granted, not which files were actually read. Your store's own log holds that half.
4. Some older material is kept under older promises. Gubbins used to hold conversations, and copies of those made before 27 August 2026 still rest here: deleted at 90 days, readable only by the team, and tidied by a scrubber that removes shapes rather than names. Generalised examples of how it answered are kept indefinitely and carry no link back to anybody.
All four are explained in full below, in sections 3.3, 3.9, and 3.1 with 4 and 3.6.
What still has to be filled in
This draft cannot answer the following, because they are not written down anywhere in the product. Each one appears in the text below as a marked gap. A privacy policy carrying an invented company name, address, registration number or hosting country would be worse than no policy at all, so none has been invented here.
- [[TO CONFIRM: legal entity name]] Who the controller actually is: a named person trading as Gubbins, or a limited company.
- [[TO CONFIRM: company number]] If it is a company, its registered number.
- [[TO CONFIRM: registered or trading address]] A postal address people can write to.
- [[TO CONFIRM: privacy contact email address]] There is no support or privacy address anywhere in the product today.
- [[TO CONFIRM: ICO registration number]] Whether the controller is registered with the Information Commissioner's Office, and under what number.
- [[TO CONFIRM: Supabase project region]] Where the database and the server functions physically run. The live project was recorded as
eu-west-2, London, on 30 July 2026, but that is a dashboard setting rather than a fact in the code, so it is left as a gap. - [[TO CONFIRM: Vercel hosting region]] Where the website and app files are served from.
- [[TO CONFIRM: Anthropic data terms]] Which Anthropic terms apply, whether a data processing agreement is signed, whether zero data retention is switched on, and how long Anthropic keeps what is sent.
- [[TO CONFIRM: Supabase and Vercel data processing agreements]] Whether they are in place and accepted.
- [[TO CONFIRM: international transfer mechanism]] What covers any transfer outside the UK, for each of the three suppliers.
- [[TO CONFIRM: whether a DPIA exists]] The product's own notes say one is needed and does not yet exist.
- [[TO CONFIRM: response time commitment]] How quickly a request about your information will be answered in practice.
- [[TO CONFIRM: policy effective date and version history]] What date this takes effect from, once it has been reviewed.
- [[TO CONFIRM: that the terms of use and this policy agree with each other]] Both were drafted on the same day and should be reviewed together, since they describe the same product from two directions.
- [[TO CONFIRM: how long an unused invitation should be kept]] Sign-up became invite only on 30 July 2026, so an email address is now held before there is an account attached to it. Nothing deletes an invitation that was never taken up. See section 1.
- [[TO CONFIRM: the retention period for a cold bank]] How long a bank that has stopped being paid for is kept, and whether anything is ever deleted. The setting exists in the product and is deliberately empty, and nothing deletes a cold bank today. Data protection law requires a period that is justified, written down and actually followed, and an unjustified "we keep it for ever" is itself a failure, so this one needs a solicitor rather than a guess. The terms of use carry the same gap and both must be answered together. See section 7.
Contents
1. Who is responsible
Gubbins is run by [[TO CONFIRM: legal entity name]][[TO CONFIRM: company number]], of [[TO CONFIRM: registered or trading address]]. In data protection terms that entity is the controller for the information described here, which means it decides what is collected and why.
You can reach us about anything on this page at [[TO CONFIRM: privacy contact email address]].
ICO registration: [[TO CONFIRM: ICO registration number]].
Gubbins is an early beta. It is shown to a small number of people on purpose: sign-up opened on 30 July 2026 but is invite only, and no money changes hands. There is no way to use Gubbins without an account, since the conversation that once ran at the front door retired on 27 August 2026.
Being invited means we hold your email address before you have an account, and sometimes a short note about who you are. It is kept on a list your browser cannot read, it is checked when an account is created, and it records whether the invitation was taken up. If you were invited and never signed up, that address is still on the list until somebody removes it. [[TO CONFIRM: how long an unused invitation should be kept]]
2. The short version
- Gubbins is a bank for what your AI assistants have learned about you. They read from it with a key you grant, and what they want to add waits in a review pile until you accept it.
- Everything it holds sits in your Memory, which you can see, correct and delete, memory by memory.
- Gubbins holds no file bytes. Your documents stay in your own store. What it keeps is a name, a short description and an address, plus the memories distilled from the file.
- Every read is receipted, so you can see who reached your Memory, when, and under which grant. The one honest limit is about files, and section 4 states it.
- When an agent needs a document, Gubbins lends it a reach into one folder for fifteen minutes at the most, and never the sign-in you gave your store.
- Gubbins asks an AI model in one place only, when you press for it in the Review room, and that goes to Anthropic. Nothing else in Gubbins calls a model.
- We measure how much, never what. What a person costs us is counted, and the query that answers it reads no column that could hold your words.
- Deleting your account is immediate. There is no grace period and no undo. You can download everything first.
- Older conversations from when Gubbins used to talk still rest here under the retention promises made at the time. Nothing new is written to them.
- There is no advertising, no tracking, no third-party analytics and no cookies.
- Gubbins is for adults, 18 or over.
3. What Gubbins collects, and why
3.1 Conversations, from when Gubbins used to talk
This section is history, and it is kept because the data is. Until 27 August 2026 Gubbins held conversations, and anybody could have one at the front door with no account. All of that retired. Nothing in Gubbins talks now, and no new conversation is being recorded anywhere.
The copies made before that date still rest here under the retention promises made at the time, so this describes what they are and what happens to them. It is not a description of anything the product does today.
What was typed was sent to our server, and from there to Anthropic, so that a reply could be generated. A copy of the conversation was then stored so the team could review the quality of Gubbins' answers. That copy was rewritten after each exchange, so one conversation is one record rather than many.
Stored alongside the conversation:
- Which part of the product was speaking, and how many turns you took.
- A count of what the scrubber removed, by type, so a reader can tell "nothing personal was said" apart from "four things were removed".
- The version of the app, the screen you were on, and your browser family (for example Chrome or Safari). Not a full browser fingerprint.
- A caller key. For an anonymous visitor this is a salted, one-way hash of your IP address, shortened. The IP address itself is never stored. The hash is used to spot the same caller across requests, for rate limiting and to stop somebody overwriting a conversation that is not theirs.
An anonymous conversation has no account attached to it, so there is no way for anyone, including us, to match it back to a person later, and no way to ask for one specific conversation to be deleted. Each is deleted automatically at 90 days, and since none has been created since 27 August 2026, that store empties itself and stays empty.
Only the Gubbins team can read those conversations, and that is enforced by the database rather than by this promise.
3.2 If you have an account
Creating an account records your email address, the name you give, and a password (stored by our authentication provider in hashed form, never in plain text).
Sign-up also asks you to confirm that you are 18 or over. No date of birth is asked for and none is stored anywhere. The only thing written down is that an adult declaration was made, when, and whether it was made by you or recorded by us on your behalf. See section 11.
That confirmation is one tick box, which also accepts the terms of use and this policy, and the account cannot be created without it. What is recorded is one small record for each of the two documents: that you accepted it, which version, and when. The version is a label rather than a number and today it reads 2026-07-30-draft, because both documents are still drafts pending review, and knowing which version somebody agreed to is the only way to tell who would have to be asked again if a reviewer changes something material. Nothing running in a browser can write or alter those records, and both are in your data export. They go with the account if you delete it.
Conversations you had with Gubbins before 27 August 2026 are still saved to your account so you can come back to them, and the scrubbed review copy of each is deleted at 90 days. The switch that turns review keeping off is still in your profile and still deletes the copies already made.
3.3 Your Memory, and the keys that reach it
Your Memory holds what your AI assistants have learned about your world, filed into clusters. Every memory shows where it came from, and you can correct one or remove it, and it is then gone. There is no second, hidden store behind it.
This is the heart of the product, so it is worth being plain: your Memory holds whatever gets deposited into it, which for many people includes clients, family members, money worries and dates. It is kept for as long as you keep it.
Nothing arrives without you. What an assistant wants to deposit lands in a review pile as a proposal. You accept, edit or decline it. A memory in your bank is one you allowed in.
Lending your Memory: what a key reaches, and what a receipt records
This is what Gubbins is for, so it is worth being plain about it. Your Memory is lent to somebody else's AI. Not sold, not copied, and not shared in the ordinary sense: lent, to an assistant you chose, under a key you granted and can take back.
Those assistants are not ours. They belong to Anthropic, or OpenAI, or whoever made the one you use, and what one of them does with what it read is governed by your agreement with that company rather than by this policy. What Gubbins controls is what leaves here, to whom, and the record of it.
You grant a key to an assistant, scoped to the clusters you chose and the grade you allowed. That key reaches nothing else, and you can revoke it. Where a key comes from an assistant you signed into rather than one you pasted a secret for, that sign-in creates the key and nothing else about your account travels with it.
Revoking a key stops any further reading immediately. It cannot reach back into what was already read, which is true of anything anybody has already been told and is stated here rather than glossed over.
Every read is receipted. A receipt records which key read, when, under which grant, and what it reached. Receipts are yours: they are on screen, they are in your download, and they go with your account if you delete it.
A receipt is a record about your data rather than a record of your words. Nothing in a receipt quotes what a memory says.
Files. A file is filed and graded alongside your memories, and what Gubbins holds about one is deliberately very little. Section 3.9 sets that out in full, because where your documents actually live is the thing people most expect to be otherwise.
3.4 Feedback
The feedback button appears on every screen. A report records your comment, which screen you were on, where on the screen you clicked, technical details about your browser and, if you choose to attach one, a screenshot of the page as it was. A screenshot may therefore contain whatever was visible at the time, including conversation text.
If you are signed in, the report is linked to your account so you can see it in your data export. If you are not, it is linked only to the salted hash described above.
3.5 Technical and usage records
Two operational records exist, and neither contains anything you typed:
- Product events. A fixed, short list of steps (the front door opened, a first message was sent, a proposal was reached, an account was made, the first conversation finished) and error codes naming where something broke. Error records can carry a short technical description of up to 300 characters, written by us, not by you. Also the app version, screen, browser family, and which variant of the opening message you saw.
- Engine usage. For each call to an AI model: the stage, the model used, how many tokens went in and out, what it cost, and whether it succeeded. This is what pays the bill and enforces spending limits.
We measure how much, never what. Spending is reported per space and per cause, so we can see what a person costs us and price the product honestly. The query that answers it selects no column that could hold your words: not a memory, not a title, not a sentence. That is a property of the query rather than a rule somebody follows.
This is one of the two things the beta asks of you, and the terms state the other beside it.
Nothing is recorded from a developer's own machine, so our own testing never counts as a visitor.
3.6 Examples kept to judge quality
Because review conversations are deleted at 90 days, the judgements made about them would be deleted too. So a small number of generalised examples are kept: a thing somebody said, the reply Gubbins gave, and the note about why it was good or bad.
Before an example is stored, every piece of free text is passed through a model that replaces the identifying specifics: names of people, businesses and organisations, places, contact details, and unusual combinations that would identify somebody even with the names removed, such as a trade plus a town. If that step fails, nothing is stored at all.
An example carries no link back to the conversation it came from, to a person, or to an account. There is no identifier to re-join on, by design, and that is the basis on which these are kept indefinitely rather than for 90 days. It also means an example cannot be found again from the conversation it came from, by us or by anybody.
3.7 Payment, and the question that was withdrawn
No payment is taken and no payment details are collected. There is no price list, no plan to pick and nothing to buy.
The plumbing for taking a payment now exists in Gubbins and is switched off, deliberately, so it can be tested before it matters. Nothing charges anybody while that switch is off, and no card details have ever reached us. When charging does begin, a payment provider will hold the card and we will not: what Gubbins would keep is a customer reference and a subscription reference, never a card number.
Until 27 August 2026 you might have been shown a price list and asked which of those you would pay for, labelled as research on the screen. That question has been withdrawn and nothing asks it now. An answer given at the time is still held, still labelled as research, still in your download and still deleted with your account. It was not a purchase, not a subscription and not permission to charge you later. If charging ever begins, every customer will be asked properly, with terms and a payment authorisation given at the time.
3.8 Reading aloud
Where Gubbins reads something to you, it uses a voice already built into your device. Nothing leaves your machine to do it, no speech model is downloaded and no audio is sent anywhere.
Dictation retired with the conversation on 27 August 2026. Gubbins does not open your microphone, and there is nothing left in the product that would ask to.
3.9 Your files, and where they actually live
Gubbins holds no file bytes. There is no column in our database that could hold one, and that is enforced by the database rather than by a rule we follow.
What Gubbins keeps about a file: its name, a short description of what it is capped at 800 characters, and its address, meaning which store it lives in, which folder, and what it is called there. Plus the date it was last read and by whom, and the memories distilled from it.
Beside your memories, Gubbins keeps a record of the files you or your assistant tell it about: a plan, a brief, a note an assistant wrote for you. Gubbins holds what a file is and where it is: its name, a short description, and the store and folder the original lives in. It never holds the file. The original stays in the store you chose, which you attached by signing into it yourself, and your assistant goes there for the document rather than being handed a copy by us. Text kinds only (markdown, plain text, a spreadsheet as text, structured text, a web page held as text). A file is filed in your clusters and graded like your memories, so a key reaches a file only through a cluster you lent it and only at a grade you allowed. Every read of a file by a key is receipted, on the same ledger as every other read. A file is deleted on your press, the record of every file leaves with your bank when you export, and Gubbins' own AI never reads one without a grant. Like a memory, a file arrives as a proposal and is held only once you accept it. Where the original could not be filed at your store, because a folder was renamed or an account disconnected, the record still lands and says so plainly, with the store's own words and the memories distilled from the file kept beside it: we would rather keep what was learned than lose it because a folder moved.
Google Drive and Microsoft 365 are the two stores that can be attached. Anything else is refused by name, with a sentence saying what it would take.
What an agent is lent, and the honest limit on the receipt
What we lend, and never lend. An agent that needs to reach a folder is lent a scoped reach into that one folder, for at most fifteen minutes, covering only the acts named. The sign-in you gave your store stays in the vault and is never handed over. The fifteen minutes is a ceiling set by the database, so code that asked for longer would be refused by the database itself. Every lend is receipted: who, which folder, which acts, and when.
Here is the limit, and it is a real one. Because the reading happens at your store rather than here, a receipt records that access was granted, not which files were actually read.
Gubbins can tell you that an agent was lent a reach into a named folder, for named acts, for fifteen minutes. It cannot tell you which documents in that folder the agent opened, because it was not there and holds none of them.
Your store keeps its own access log, and that is where the second half of the answer lives. This is stated here rather than left to be discovered, because a receipt that looked like a complete record of file reads would be the most misleading thing in this product.
Everything in section 5 about what should not be written down applies to a file exactly as it applies to anything else, and it matters more here: a set of notes or a staff list can carry a great deal about other people, and nobody reads every line of a document before pointing an assistant at it.
3.10 What is stored in your browser
Gubbins sets no cookies. It uses your browser's own local storage for a small number of things:
- Your settings, including the theme and the voice you chose.
- Your sign-in session, if you have an account.
- The fact that you have read the beta notice.
- Where you have moved something in the Review room, so your decision survives a reload.
- A description already generated in the Review room, held only until the tab closes, so pressing again does not spend money on the same answer twice.
- If you connect your own AI provider using your own API key, that key is stored in your browser and never sent to us. It goes only to the provider it belongs to. See section 12 for the honest caveat about that.
3.11 No advertising, no tracking, no analytics
There are no advertising networks, no third-party analytics, no tracking pixels and no social media trackers in Gubbins. The website and app make no requests to any third party except the ones named in this policy. Your information is never sold, and it is never shared for anybody else's marketing.
4. The honest limits: what is removed, and what a receipt can say
Two things in Gubbins do less than their name suggests. Both are stated here rather than left to be discovered.
The scrubber removes shapes, not people
Before a conversation was stored for review, patterns were used to take out email addresses, UK postcodes, dialled telephone numbers and runs of nine digits or more. Those things have a recognisable shape. Names do not.
So "my sister Sarah is having chemo" survives word for word, and so does a company name, a street, a town or an illness. The review store is not anonymous, and nothing in Gubbins describes it as anonymised.
What carries the weight instead: only the Gubbins team can read it, enforced by the database rather than by policy; it is deleted at 90 days; people were told before they typed; and the switch in your profile still deletes what was kept. Nothing new goes in, because Gubbins stopped talking on 27 August 2026.
A receipt records the door opening, not what was taken from the room
For a memory, a receipt is complete: the read happened here, so we know exactly what was served.
For a file, it is not. The document lives in your own store and is read there, so what Gubbins can record is that an agent was lent a reach into a named folder, for named acts, for at most fifteen minutes. It cannot record which documents in that folder were actually opened, because it was not present and holds none of them.
Your store keeps its own access log, and that is where the rest of the answer lives. A receipt that implied it covered file reads would be the most misleading thing in this product, which is why the limit is stated in the same breath as the promise.
5. What Gubbins deliberately does not record
When an assistant proposes a memory to your bank, it is instructed not to write down certain things, whether they are about you or about somebody else:
- Health of any kind: an illness, a diagnosis, a disability, medication, a hospital or GP appointment, a mental health difficulty, a pregnancy, a recovery.
- Race or ethnicity, religion or belief, political opinions, trade union membership, sex life or sexual orientation.
- Criminal offences, allegations, convictions or proceedings.
- Immigration or citizenship status.
- Any of the above about somebody who is not you: a client, an employee, a relative. They are not here to agree to it.
The rule behind it is record the work, never the circumstance. "Attendance allowance forms to complete and GP appointments to book" is a useful fact and is kept. The diagnosis behind it is not. "Off work for six weeks so invoicing has slipped" keeps the invoicing and drops the reason.
Other difficult things are deliberately not excluded, because they are usually why somebody is here: money being tight, a business struggling, a bereavement to sort out. Those are recorded, they are visible in your Memory, and you can remove any of them.
Three honest caveats, and a solicitor should see all of them.
First, this exclusion applies to your Memory. It does not apply to the 90 day review copy of an older conversation, which holds what was actually typed, whatever that was.
Second, the exclusion is an instruction given to an AI model rather than a mechanical filter. It is followed reliably in testing, but it is not a guarantee in the way a pattern match is.
Third, only the restricted list above is held back about other people. Ordinary facts about other people are recorded. Learning about the people in your world is not a side effect of Gubbins, it is part of what it is for: your clients, customers, colleagues, staff, suppliers, family and friends are exactly the sort of thing it is built to remember. So if you tell Gubbins that a named client pays late, or that an apprentice comes in on Tuesdays, that is written down and kept, and the person it is about has not been asked and is not told, because there is nothing in Gubbins that could tell them. This is normal for a tool somebody uses to run their affairs, and it is still worth a lawyer's eye on who is the controller for it.
6. The lawful bases
[[TO CONFIRM: these are proposed, and are exactly the part a solicitor should settle]]
| What | Proposed basis | Why |
|---|---|---|
| Running your account and the product | Contract | You cannot be given the service without it. |
| Keeping conversations for 90 days to review quality | Legitimate interests | The voice is the product and there is no other way to tell whether it is any good. A legitimate interests assessment has not been written yet. |
| Product events and engine usage | Legitimate interests | Knowing that something broke, and controlling cost and abuse. |
| Feedback you send | Legitimate interests | You chose to send it; it is used to fix the product. |
| Generalised examples | Not personal data, in our view | They are generalised before storage and carry no link to any person or conversation. If that view is wrong, the retention period is wrong too. |
| The adult declaration | Legal obligation and legitimate interests | Keeping children's data out of the product. |
| Lending your Memory to an assistant you granted a key to | Performance of the contract | This is the product, so it is the row that matters most. You grant a key, you choose which clusters it reaches and at what grade, you can revoke it, and every read it makes is receipted to you. Nothing is served to a key you did not grant, and nothing beyond what you scoped it to. |
| Lending an agent a reach into one of your folders | Performance of the contract | You granted the key and named the scope. The reach is bounded to one folder, to the acts named, and to fifteen minutes, and every lend is receipted. |
| Holding what an assistant proposes until you accept it | Performance of the contract | The review pile is how nothing enters your Memory without you. Declining a proposal removes it. |
Gubbins does not set out to process special category data and has no Article 9 condition in place. Free text typed by a person can nonetheless contain it, which is why section 5 exists and why the review copy is limited to 90 days.
7. How long things are kept
| What | How long | How it goes |
|---|---|---|
| Review copies of conversations | 90 days | A scheduled job deletes expired conversations every night. A second sweep also runs on a small proportion of writes, so neither depends on the other still working. |
| Your Memory, your file records and your receipts | Until you delete them, or your account | By your hand. Deleting your account takes them immediately. |
| Your Memory, once a bank has stopped being paid for and gone cold | [[TO CONFIRM: the retention period for a cold bank]] | Nothing deletes a cold bank today. The setting that would say how long exists and is empty, and no code reads it. Nothing is deleted when payment stops, and export never stops. See section 12 of the terms. |
| Your own conversations, from before 27 August 2026 | Until you delete them, or your account | By your hand. Deleting your account takes them immediately. Nothing new is written to them. |
| Product events | 90 days | Swept on a small proportion of writes and by nothing else, so a quiet period can leave a record past 90 days until enough new events arrive to trigger a sweep. |
| Generalised examples | Indefinitely | Kept on purpose, on the basis that they carry no link to any person. See section 3.6. |
| Engine usage records | No automatic deletion today | Your account identifier is removed if you delete your account, leaving an anonymous cost record. [[TO CONFIRM: whether a retention limit should be set]] |
| Feedback reports | No automatic deletion today | Your account identifier is removed if you delete your account, so the report survives without you attached to it. |
| Rate limiting counters | About two hours | Cleared as new requests arrive. They hold a salted hash and a number. |
| The record that an adult declaration was made | For the life of the account | Deleted with the account. |
| The record of which version of the terms and this policy you accepted | For the life of the account | Deleted with the account. A new record is added rather than the old one overwritten if you are ever asked to accept a revised version. |
| An invitation to sign up | No automatic deletion today | Your email address stays on the invitation list whether or not you use it. [[TO CONFIRM: how long an unused invitation should be kept]] |
| The daily count of refused under-18 sign-ups | Indefinitely | A date and a number. It holds nothing about anybody. |
9. Where it is processed
The database and the server functions run in [[TO CONFIRM: Supabase project region]], and the website and app files are served from [[TO CONFIRM: Vercel hosting region]]. This draft does not state either as fact, because a privacy policy naming the wrong country is a false statement about where somebody's information lives.
A lead for whoever fills those in: the live Supabase project was recorded as region eu-west-2, which is London, when this draft was written on 30 July 2026. That is a dashboard setting rather than anything written in the code, so it has to be confirmed rather than copied, and the Vercel side has not been checked at all.
The AI model provider is Anthropic, which is based in the United States. Any transfer outside the UK is covered by [[TO CONFIRM: international transfer mechanism]].
Your documents are processed wherever your own store keeps them, which is between you and that store rather than something we choose. Gubbins never holds them and so never moves them anywhere.
If you run Gubbins on a local AI engine on your own computer, the conversation with that engine does not leave your machine at all. The 90 day review copy described in section 3.1 is still kept, because that is stored by Gubbins rather than by the engine.
10. Your rights, and how to use them
Under UK data protection law you can ask for a copy of your information, ask for it to be corrected, ask for it to be deleted, ask us to restrict what we do with it, object to us using it, and ask for it in a portable form. You can also complain (section 14).
Several of these are buttons in the product rather than a request you have to write:
- See it. Your map shows every fact Gubbins has learned about you, with where it came from.
- Correct or remove one thing. Edit or delete any memory in your Memory. It is then gone.
- Take it with you. "Download everything" produces a single JSON file containing your conversations, your feedback, the review copies of your conversations, your memberships, your workspace, your Memory, your spaces, your jobs, your connectors, any answer you gave to the withdrawn plan question, the record of which version of these documents you accepted, and the record that an adult declaration was made. It runs entirely in your browser, so it can only ever contain what you could already see.
Two things are deliberately left out, and the file itself says so rather than leaving you to notice: the usage and error records, which carry nothing you typed and are stripped of your identity if you delete your account; and the notes the team wrote while reviewing a conversation, which are the team's own writing about the product and which the database lets only the team read. - Stop the review copies. The switch in your profile stops new ones and deletes the ones already kept.
- Delete your account. Immediate, with no grace period and no undo. You type your email address to confirm, and that is checked again on the server so it cannot be skipped. Your Memory, your clusters, your file records, your connections, your receipts, your keys and your older conversations all go with it. Feedback and cost records survive with your identity removed.
Your documents are not in the download, and deleting your account does not delete them. They were never ours. They are in your own store, where they have been all along, and they stay there under your own control. What leaves with you is the record of what each one was, where it lived and what was learned from it.
For anything else, write to [[TO CONFIRM: privacy contact email address]]. We will reply within one month, which is the legal maximum. [[TO CONFIRM: response time commitment]]
One limit worth stating plainly. If you talked to Gubbins at the front door before 27 August 2026, without an account, that conversation has nothing attaching it to you. We cannot find it in order to show it to you or delete it, and neither can anybody else. It is deleted automatically at 90 days, and since that route retired, every one of them has gone or will go on its own.
11. Children
Gubbins is built for adults, 18 or over. It is a tool for people running their own affairs or a small business, and it has nothing in it aimed at children: no games, no social feed, no video, and no way to talk to anybody else.
- Sign-up asks you to confirm you are 18 or over, and refuses anybody who does not. No date of birth is asked for. Only the fact of the declaration is kept.
- A refused person leaves almost no trace, and the exception is named here rather than glossed over. No account is made, and nothing is written anywhere that carries an email address or anything else you typed. Two things do move. One is an anonymous daily counter, a date and a number, which counts sign-up attempts that arrived without that confirmation. This policy used to say that counter told us whether children were reaching Gubbins, and since 27 August 2026 it cannot. The confirmation is now a tick box rather than a date, and a child who ticks it is neither refused nor counted, so what the number really counts is nearly always a script or a fault in our own software. It is kept because a number that moves still tells us something is calling that part of the service which is not the sign-up form. The other is a rate limiting counter, which holds a salted one-way hash of the network address and is written before the confirmation is read at all, so it exists for anybody who tries to sign up and says nothing about why they were refused. It is cleared within about two hours.
- There is nothing left to reach without signing up. Until 27 August 2026 anybody could talk to Gubbins at the front door, and that route deliberately asked nobody's age while watching for a visitor who volunteered that they were a school child. It has retired, so the declaration at sign-up is now the only door, which narrows this question rather than widening it.
- There is no route round the refusal.
A declaration is not verification, and this policy will not pretend it is. The Information Commissioner's Office says plainly that a simple self-declaration is unlikely to be an effective way of restricting access to over-18s. What makes it proportionate here is the judgement that Gubbins has essentially no draw for a child. That judgement is written down so it can be argued with, and it expires the moment the product gains anything with child appeal.
[[TO CONFIRM: whether a DPIA exists]] The product's own notes record that a Data Protection Impact Assessment is needed, that none exists yet, and that both it and a legal review are prerequisites for opening sign-ups.
12. Security, and what is not built yet
What is in place:
- Everything travels over HTTPS, with strict transport security set.
- Access to the database is controlled row by row by the database itself, not by the app. Review conversations can be read only by the Gubbins team and by the person they belong to.
- Raw IP addresses are never stored. Where a caller has to be recognised, a salted one-way hash is used instead.
- Server keys never reach the browser. The key that does ship in the browser is designed to be public and is protected by those row-level rules.
- Age checking, account creation and account deletion all happen on the server, so none of them can be bypassed by editing what the browser does.
- Deleting an account deletes the caller, and nobody else. There is no way to point it at another person.
Being honest about what is not:
- If you connect your own AI provider key, it lives in your browser's local storage. It never leaves your device except to that provider, but any cross-site scripting flaw could read it. The proper fix is to hold keys server side, and that is not built.
- There is no two-factor authentication and no CAPTCHA yet.
- The content security policy currently runs in report-only mode, so it reports violations rather than blocking them.
- Automated tests cover the instructions Gubbins runs on and the text checks around them, and very little else. There are none for the server functions, none for the database permission rules that carry most of the weight in this policy, and none for the product end to end. Those are verified by hand.
- Gubbins is an early beta and parts of it will break. Please do not depend on it for anything important yet.
A solicitor may reasonably say that some of this belongs in an internal document rather than a published policy. It is written down here because being accurate about the system is the point of this draft.
13. Changes to this policy
Gubbins is being built quickly, so this will change. When something material changes about what is collected or how long it is kept, the notice shown before you type is updated too, and everybody is asked to read it again. That has already happened once: when conversation keeping began, the old promise that nothing was saved was removed from the product and from the website, and every person who had agreed to the old wording was asked again.
This draft is dated 30 July 2026. [[TO CONFIRM: policy effective date and version history]]
14. How to complain
If something about your information is wrong, tell us first at [[TO CONFIRM: privacy contact email address]], and we will put it right.
You also have the right to complain to the UK's data protection regulator, the Information Commissioner's Office, at ico.org.uk. You can do that whether or not you have raised it with us, though we would rather have the chance to fix it.