Privacy notice

What CHAOS stores, and why.

This notice describes what the product actually does today, not what would sound reassuring. Read it together with the Terms.

Two things worth reading twice: project memory is designed to be permanent, and producing output involves external AI model providers. Both are stated in full below.

Your account

To have an account, CHAOS stores your email address, the name you choose to show, your account status, which access plan applies to you, and whether you hold an operator role. Authentication (sign-up, sign-in, email confirmation, password reset) is handled by the product's managed authentication service, which also stores the credential material — we never see your password.

Every account gets a personal workspace. If you are a member of other workspaces, that membership and your role in it are stored so that access can be enforced.

Your projects and what you write

Projects you create are stored with their name, description, goal, status and owner, together with the workspace they belong to.

Your conversations with a project are stored: each session and each message, with its role, its content, and when it was written. This is what makes a project continuable rather than disposable.

Persistent project memory

This is the core of the product and it is deliberately permanent. What you tell a project — facts, corrections, constraints, preferences — is stored as project memory in the LOS intelligence service and recalled in later sessions of that same project. It is not a temporary chat context that disappears when you close the page.

Memory is scoped to the project it was created in. It is not used to answer in another user's projects, and it is not pooled into a shared public memory.

Because memory is designed to persist, treat what you put into a project as something that will still be there later. Do not place secrets, credentials or information that must not be retained into project memory.

Research, objectives and learning

When you run research inside a project, the request and the resulting material are processed and kept by the intelligence service so that later work can continue from it instead of starting again.

Goals, plans and tasks you create are stored against the project, and the learning a project accumulates — what it treats as settled, contested or still open, with its supporting evidence — is stored as part of that project's intelligence.

The intelligence service and external AI providers

CHAOS runs on LOS, a separate intelligence service. Your prompts and project content are sent to it from our servers — the browser never talks to it directly and never holds its credentials — so that it can produce memory, knowledge, research, reasoning and learning.

LOS in turn uses external AI model providers to perform cognitive work, and routes different kinds of task to different providers. This means your project content can be processed by external model providers as part of producing output. We do not claim that your content never leaves the service, because that would not be true.

The product database and authentication run on the managed cloud backend the application is deployed with. We do not list further named subprocessors here, because the ones we could name truthfully are the two described above.

Sharing with people you choose

Sharing is off by default. Nothing you build is visible to another account unless you grant it.

When you grant read access to specific knowledge, the grant is stored: what was shared, who it was shared with, who granted it, when, and whether it is still active or has been revoked. Recipients get read-only access to exactly what the grant covers, and revoking a grant removes that access.

Federated discovery between projects

Discovery only considers knowledge that has been explicitly marked as discoverable. Private knowledge is never entered into it.

To find relevance, the service compares server-side representations of discoverable knowledge with a server-side representation of the other project's context, including a semantic comparison. That comparison happens entirely on the server: the other project's wording is transient there, is never sent to your browser, and is never written into logs or the page.

What is stored is the outcome: a candidate with its scores and status, plus discovery events recording that an evaluation, a reveal or a decision happened. A candidate is a suggestion only. No content is disclosed and no access is granted until the owner explicitly approves it.

Service, security and operational data

For each request your account makes to the intelligence service, the product records an operational event: which kind of request it was, the path and method, whether it succeeded, how long it took, the related project identifier, and your user identifier. This is what powers the usage summary on your account page and lets us see whether the service is actually working.

Administrative and security-relevant actions are recorded in an audit log with the actor, the action, the target and a timestamp. Standard technical information needed to serve a web request, such as your network address, is processed by the hosting infrastructure in the normal course of serving the site.

We do not run advertising trackers, and we do not sell your data.

Retention, export and deletion

You retain ownership of the content and data you provide, and of the project intelligence built from it. Self-service data export is not yet available during Public Alpha, so you should not assume you can currently download a structured copy on your own.

We are not going to state a retention period, an encryption guarantee, a data residency location or a deletion timescale here, because no such commitment is defined in the system yet. Persistent memory is designed to persist, and you should assume that what you place in a project remains available to that project.

There is no self-service account deletion in the product today, and no verified support mailbox to request a deletion or a copy of your data through. Those gaps are stated openly on the support page and are being worked on rather than papered over.

Changes to this notice

CHAOS is in public alpha and this notice will be extended as the product and its operational commitments mature. The current version is always the one on this page.