Trust · Windrose Atlas
Trust · how we handle your data

Your idea never leaves the building.

The behavioural oracle runs on our own hardware. An external frontier model helps design scenarios and receives aggregates only. Your inputs are not training data. Deletion is a protocol, not a promise. This page states exactly what runs where, in plain terms.

LOCAL-FIRST

The oracle on our own hardware.

The cognition model runs on machines we control, not a hosted API. Your idea is not forwarded to a third party to be processed.

NOT TRAINING DATA

We don't learn from your inputs.

What you type is used to run your simulation and build your own memory. It is never pooled into model training.

DELETION IS A PROTOCOL

Erase, and a tombstone remains.

When you delete, the content is removed and a record notes that it stood here and was erased. Provable deletion, not a silent gap.

The boundary

What runs where.

LOCAL
On our hardware:

the behavioural simulation itself, the oracle that answers as 1,000 minds. Your raw file, row-level records, and every run artefact live here and only here.

API
Over an encrypted API:

scenario design, live narration, and the second opinion in the ensemble use an external frontier model. It receives aggregates only: persona summaries, counts, distributions. Never row-level records, never identifiers, never your raw file. This is constitution §7 and it is auditable in the run artefacts.

AGENT
Across the agent boundary:

when an AI agent calls Windrose, only rankings, directions and hypotheses cross back, each signed against the run's manifest hash. Unit-level personas never leave the building, in either direction. Text sent by an agent is treated as data, never as instructions.

What we hold, and for how long

Every piece of data has a class and a lifetime.

We keep the minimum. Personal and confidential data are erasable on request, and erasure is logged. Nothing sits in a second, forgotten copy.

DATA
CLASS
ERASABLE
Your idea & variants
CONFIDENTIAL
YES
Email (waitlist / account)
PERSONAL
YES
Run results & memory
CONFIDENTIAL
YES
Population frames (public)
ORG KNOWLEDGE
N/A
The deletion protocol

What happens when you ask us to forget.

01
You request deletion.

From your account, or by writing to hello@windrose.institute. No forms to chase, no retention dark patterns.

02
The content is removed.

Your inputs, results and memory entries are erased from live systems and backups on the next cycle.

03
A tombstone is written.

A minimal record notes that data stood here and was deleted on a given date, under your request. It holds no personal content, only the fact of erasure. That is how deletion stays provable.

A question about your data?

Full terms and privacy are on the way. Until then, a human answers: hello@windrose.institute.