Privacy Policy
Contained Evolution LLC (Michigan, USA) · Version 2026-08-19-r13
Invitation-only closed beta. This Policy describes what we
collect, how we use it, who else touches it, and what you can do about
it. It's written in plain language and is
subject to review by
legal counsel before paid subscription tiers open broadly. By
using the app you accept the version in force; we may update it and
ask you to agree again. See also the
Terms
& Conditions and the
Crisis &
Self-Harm Safety Protocol.
1. Scope
This Policy applies to Contained Evolution (the “app”), provided by
Contained Evolution LLC (Michigan, USA). It covers the personal-assistant
app at app.tenari.world, the SHELL appliance,
the SHELL desktop client, and any related services we operate
directly. Third-party services you connect on your own — e.g. your own
OpenRouter, Anthropic, OpenAI, Google, or ElevenLabs key — are governed
by those providers’ own privacy policies; we describe below exactly what
we do and don’t do with those keys.
2. Information we collect
- Account. Email address, name, password hash (when
you sign up with email/password) or Google account identifier (when you
sign up with Google); signup date; Terms-acceptance version + timestamp.
- Profile & personal assistant settings. The
name and colour you give your assistant, the dials you tune (tone,
directness, humour, proactivity, verbosity, challenge, name-use,
emoji), optional interests and identity choices you deliberately save, and your appearance
preferences.
- Your content. Notes, mind-maps, scribbles,
canvases, tasks, boards, playbooks, files, daily briefs, team
bulletins, and anything else you create in the app.
- Memory Tree. What you share in chat that gets
captured into Ripening (last 24 hours), is admitted into your
accepted memory (categorized long-term memory), or you file
manually. Stored in our cloud so your assistant and search can use it
— see §7 for how it's protected, and mark anything 💾 Local in Files
if you'd rather we couldn't read it.
- Chat. Your messages and the assistant’s replies,
the model used, the cost in dollars and tokens, and tool calls fired.
- Usage. Stardust balance states (Spendable and any optional automation set-aside), automation definitions and run results, and
transactions, PASS status, and any daily spend limit you set.
- Payments. If you accept a paid beta offer or buy an AI-usage refill,
Stripe holds your card details; we store only your Stripe
customer ID, subscription/transaction IDs, and metadata returned by
Stripe (we never see or store your card number).
- Integrations you opt into. Google OAuth tokens
when you connect Google Drive / Calendar / Gmail; the scopes you
granted; metadata returned by those APIs.
- Taste Buds grocery handoff. When you turn on the
grocery handoff in Reactor and confirm a handoff in Taste Buds, we send
the unchecked canonical shopping-list item names and quantities to
Instacart to create a hosted list. We cache that generated link for up to
seven days while the list is unchanged. DoorDash and Uber Eats handoffs
copy the list locally on your device and open the external site; CE does
not send the list to either service.
- Account-synced AI Providers and MCP keys. If you save
an OpenRouter, Anthropic, Gemini, supported legacy OpenAI, or MCP key to
your account, CE encrypts it at rest with AES-256-GCM in our database so
it is available on your signed-in devices. CE's server can decrypt these
keys. In the current AI Providers chat path, CE decrypts your key only
inside the server request that spends it and sends the inference request
to the provider from CE's server; the decrypted key is never returned to
your browser. Removing the key in AI Providers deletes or revokes CE's
stored copy; you should also revoke a compromised key with its provider.
- Device-only integration keys. Keys entered only for
ElevenLabs Voice, Flow's Groq mode, or Media Lab's Gemini integration are
stored in that device's browser storage and are not account-synced. Saving
a provider key separately in AI Providers uses the account-synced behavior
described above.
- Device + telemetry. Install/PWA state, basic
error logs, and metadata needed to operate the service (e.g. session
cookie, IP address at the time of a request). No third-party analytics
or advertising trackers are loaded today.
3. How we use it
- To run the app: log you in, render your data, route your chat
messages to the appropriate AI model, charge your subscription, and
track Stardust usage.
- To improve the service: investigate bugs, monitor errors, plan
features. Reviews of stored content are limited to what is needed for
those purposes and authorised CE personnel only.
- To communicate with you: scheduled Daily Brief emails via Resend
when you enable that delivery.
4. What we don’t do
- We do not sell your personal information — to
anyone, ever.
- We do not do behavioural advertising or build advertising
profiles on you. There are no ad trackers, no ad networks,
and no cross-site tracking pixels in the app.
- We do not share your content with anyone except the
providers needed to deliver the service or an integration you explicitly
enable and confirm (listed
in §5). We do not use your memory or chat content to train any AI
model — ours or anyone else’s.
- We do not silently sweep every device key into your account.
AI Providers and MCP keys are server-stored only when you choose to save
them there. Device-only Voice, Flow, and Media Lab keys remain on that
device unless you separately save a corresponding key to AI Providers.
5. Who we share with (processors)
We use third-party infrastructure to deliver the service. Each
receives only what is needed for their specific role:
- Railway — application hosting + PostgreSQL
database (US-hosted).
- OpenRouter — default routing of your AI chat
requests across multiple model providers, when you are not using a BYOK
key.
- Stripe — payment processing for subscriptions
and credit packs. Stripe holds your card details under their own
privacy policy.
- Resend — scheduled Daily Brief email delivery
when you enable it.
- Cloudflare — DNS, edge TLS, and the named
tunnel for SHELL.
- Google — OAuth sign-in and, only if you connect
them, Drive / Calendar / Gmail APIs you opted into.
- Instacart — only when you enable and confirm the
Taste Buds grocery handoff; receives the unchecked item names and
quantities needed to generate the hosted shopping list.
- ElevenLabs / Anthropic / OpenAI / Google AI Studio
— used when you select the related feature or provide a BYOK key. For an
account-synced AI Providers key, CE stores the encrypted key and decrypts
it only inside the server request that spends it, sending the inference
request to the provider from CE's server. Device-only Voice, Flow, and
Media Lab keys are sent directly from that device and are not stored by
CE.
6. Retention
We keep each category of personal information only as long as it serves
the purpose it was collected for. For most categories the criterion is your
account itself: the data exists to make the product work for you, and it is
deleted when you delete your account. Nothing is kept indefinitely except
records we are legally required to keep or records that carry no identifier
at all.
| Category |
Why we hold it |
How long |
| Account & identity, device sessions | Authenticate and operate your account | Life of your account |
| Conversations | Your Companion's continuity | Life of your account |
| Memory Tree | Personalization you control | Life of your account; deletable item by item at any time |
| Pending memory (Ripening queue) | Candidates awaiting review | Claim content until resolved or expired; content-free status records for 14 days after resolution |
| Your content — notes, journals, files, projects | You asked us to store it | Life of your account; deletable individually |
| Provider API keys | Operate the features you enabled | Deleted immediately when you remove the key or the account |
| Billing records | Tax and accounting obligations | 7 years from the transaction, even after account deletion |
| Terms acceptance | Proof of agreement | Kept after deletion: email, version, timestamp only |
| Simulated economy ledger (Moon Rocks) | Keep the shared in-world accounts balanced | Kept after deletion with every reference to you removed — amounts and dates only |
| Crisis referral counts | Statutory annual reporting | Kept indefinitely — carries no user identifier and no message text |
| Age-check answers | Show we did not ignore an under-18 signal | Life of your account; the message that triggered it is never stored |
| AI disclosure record | Show we told you that you are talking to an AI, as New York law requires | Life of your account; which screen and when only, never what you said |
When you delete your account we cascade-delete the rows we control
across your profile, memory, chat, tasks, files, and sessions.
One record that identifies you survives: your acceptance of these
Terms and this Privacy Policy — the email used, the version accepted, and
the timestamp. Accepting the current Terms is required to use the
app, and we retain this proof of agreement as a record of consent and to
meet our legal obligations, even once the rest of your account is gone.
Beyond that we keep only records that carry no identifier at all, both
listed above: crisis referral counts, and the simulated economy's ledger
entries. Those ledger rows are stripped of your account reference at the
moment of deletion and keep nothing but amounts, dates, and generic
descriptions like “weekly settlement”. We keep them because each
one is one half of a shared in-world account — the town treasury, the
bank, the market — whose balances would stop adding up for everyone
else if your half disappeared. Moon Rocks are play money and carry no cash
value, so this is bookkeeping integrity, not a financial record about you.
What runs, and what does not: a purge job now
runs every night and enforces the timeframes above that are not tied to account
deletion — billing records after seven years, and content-free Ripening status records
fourteen days after they settle. Candidate claim content is erased when it settles.
What we still have not documented is how deletion propagates to platform backups. That is active work, and we would rather say so
than imply we have finished it.
7. Security
- HTTPS in transit on every request to the app.
- Cloud data (Memory Bank, chat, files) lives on
managed Postgres with per-user database isolation, HTTPS in transit.
Your conversations and your Memory Bank are encrypted at rest
under a key held for your account alone, so a copy of the database does not
read as your words. The database itself refuses to store either of them in
plain text. Finance and ledger records are not encrypted that way yet; that
work is in progress. Either way, because your assistant and search have to
read it, we hold the keys and can access it under lawful process — it is
not private from us. For data you want us to be unable to
read, mark it 💾 Local in Files: it stays on your
device and never reaches our servers.
- Server-stored third-party API keys (AI Providers and
MCP) are AES-256-GCM encrypted at rest under a separate server key from
the memory key. CE controls that encryption key and can decrypt the
provider keys to operate the feature; this is not end-to-end encryption.
- Payments are tokenised by Stripe; we never see
or store your card number.
- Passwords are stored as salted hashes only; we
cannot read your password and will never email it to you.
- No system is perfect. If we learn of a breach affecting your data,
we will notify affected users in line with applicable law.
8. Your rights
You have the right to:
- Access the personal information we hold about you
— request a copy by contacting us (§13).
- Delete your account and the data we control —
self-serve via Settings → Privacy → Danger Zone →
“Delete account.” Cascade-deletes your profile, Memory Bank, chat
history, content, and sessions. If you own a team, you’ll need to
transfer ownership first.
- Correct data that is wrong — most of your
in-app data is editable directly; for the rest, contact us.
- Export a portable copy of your content — contact
us to request an export; automated export is on the roadmap.
- Opt out of the sale or sharing of your personal
information for advertising — we do neither, so there is nothing to
opt out of.
If you are in California (CCPA/CPRA) or the EU/UK (GDPR), these
rights are guaranteed by your local law; we honour them globally.
9. Cookies & local storage
We use a small number of strictly necessary cookies + browser local
storage. We do not use advertising or analytics trackers.
- Auth session cookie — HttpOnly + Secure; keeps
you signed in. Required to use the app.
- Browser local storage — your appearance
preferences, default tier picker, ToS-acceptance cache, device flags,
and device-only Voice, Flow, or Media Lab keys you entered. AI Providers
and MCP account keys follow the server-storage disclosure in §§2 and 7.
- No third-party analytics, ad networks, fingerprint
libraries, or cross-site tracking pixels load in the app today.
10. Children’s privacy
The app is intended for adults. You must be at least 18 years old (or
the age of majority where you live) to create an account, per the Terms
& Conditions. We do not knowingly collect personal information from
anyone under 18. If you believe a minor has signed up, please contact us
(§13) and we will remove the account.
11. International users
The service is operated from the United States and your data is
processed there. If you access the app from outside the US, you consent
to that transfer. Where the GDPR (EU/UK) or CCPA/CPRA (California)
applies, we honour your local rights as described in §8.
12. Changes to this Policy
We may update this Policy. When we do, we will increment the version
and may ask you to agree again before continuing to use the app. The
date-stamped version is shown at the top of this page; continued use
after acceptance means you agree to the version in force.
13. Contact
Contained Evolution LLC — containedevolution@gmail.com
Version 2026-08-19-r13. This is a working agreement
in plain language, not attorney-drafted launch-final text; it is subject
to review by legal counsel before paid subscription tiers open broadly.
Nothing here is legal advice.