Last Updated: November 29, 2025
Version 1.3.0
This privacy policy applies to all CIRIS services:
Self-hosted or cloud-hosted AI agents running the CIRIS framework with H3ERE ethical reasoning
Browser-based interface for interacting with CIRIS agents, viewing reasoning, and managing account
Mobile application for CIRIS agents with offline-first architecture
Privacy-focused LLM proxy and billing service (Android app only)
Important Distinctions:
CIRIS implements a Consensual Evolution Protocol with three consent streams. Default is TEMPORARY (most privacy-preserving).
Agent Self-Training on Hosted Services: When you interact with CIRIS agents hosted on ciris.ai (like Scout), agents self-train on patterns and data from your interactions based on your consent level. TEMPORARY consent = essential interactions only (14-day limit, then deleted), PARTNERED consent = full self-training for mutual growth and improvement, ANONYMOUS consent = statistical patterns only (identity severed).
When we say CIRIS agents "self-train," we mean they use several autonomous learning mechanisms to improve their responses while respecting your consent level. These are NOT traditional machine learning model training—instead, agents learn through introspection and pattern recognition.
Every ~6 hours, agents enter a DREAM state for 30-120 minutes to consolidate memories, analyze behavioral patterns, test configuration parameters, and plan improvements. Think of it as the agent reflecting on what it learned.
View Dream Processor Code →In PLAY state, agents try creative approaches, experiment with novel solutions, and learn through exploration with fewer constraints. About 20% of the time, they'll try something new.
View Play Processor Code →When agents need recovery or reflection time, they enter SOLITUDE state to perform minimal processing, clean up old data, and reflect on past activities and patterns.
View Solitude Processor Code →Agents continuously observe their own behavior, detect patterns (temporal, frequency, performance), and generate insights. Changes are limited to 20% identity variance maximum for safety.
View Self-Observation Documentation →Agents can modify their own configuration parameters through the config graph, testing variations within safety bounds and applying changes only if they stay within the 20% identity variance limit.
Key Safety Mechanisms:
Current Status: Dream, Play, and Solitude processors are implemented but not active by default in the current deployment. Self-Observation Service is fully implemented but requires explicit activation. Your consent level determines whether and how much learning occurs when these features are enabled.
| Data Type | Retention Period | After Deletion |
|---|---|---|
| Message Content | 14 days (pilot phase) | Permanently deleted |
| PDMA Decision Logs | 14 days | Hashed for pattern detection only |
| Audit Trail | 90 days | Deleted after compliance period |
| Incident Reports | 90 days | Deleted unless legally required |
| Billing Records | 7 years | Legal requirement (tax/compliance) |
| System Metrics | Indefinite | Aggregated only, no PII |
| CIRISProxy Logs | 7 days | Permanently deleted (no content logged) |
Note: These are maximum retention periods. We will not extend these periods without explicit user consent and advance notice. We aim to retain data for the shortest period necessary.
When you revoke consent or request deletion, we initiate a 90-day decay process:
User ID disconnected from all data immediately. Identity→data links broken.
Gradual conversion to anonymous form. Behavioral patterns become statistical aggregates.
All user-linked data removed or fully anonymized. Only safety-critical patterns retained (anonymous).
Under GDPR, CCPA, and other privacy regulations, you have the following rights:
Request a copy of all data we hold about you
Request deletion of your data (90-day decay process)
Request corrections to inaccurate data
Receive your data in machine-readable format (JSON/CSV)
Limit how we process your data
Object to specific processing activities
Email: privacy@ciris.ai
API Endpoint: POST /v1/dsar
Web Interface: scout.ciris.ai/account/privacy
Response Time: Within 30 days (often faster)
For credit purchases only. We do not store credit card information. Stripe's privacy policy: stripe.com/privacy
If you choose Google login, we receive name, email, and profile photo. Google's privacy policy: policies.google.com/privacy
Your prompts are sent to LLM providers for processing. We use providers with strong privacy commitments and no training policies.
CIRIS services are hosted in the United States. If you access our services from outside the US, your data will be transferred to and processed in the US.
We comply with applicable data transfer regulations:
CIRIS services are not directed to children under 13 (or 16 in the EU). We do not knowingly collect personal information from children.
If we learn that we have collected information from a child without parental consent, we will delete it immediately. Contact privacy@ciris.ai if you believe we have data from a child.
We may update this privacy policy to reflect changes in our practices, technology, legal requirements, or other factors.
Continued use of CIRIS services after changes take effect constitutes acceptance of the updated policy.
This privacy policy is governed by the CIRIS Covenant (Version 1.0-β), which establishes our ethical foundation:
Your autonomy, privacy, and dignity are paramount
Maximize benefits, minimize harms
Equitable treatment for all users
You control your data and relationship with CIRIS
Truthful communication about data practices
For privacy questions, DSAR requests, or concerns:
Privacy Team Email: privacy@ciris.ai
General Inquiries: info@ciris.ai
GitHub Issues: CIRISAI/CIRISAgent
Discord Community: discord.gg/SWGM7Gsvrv
DSAR API: POST /v1/dsar
CIRIS - Ethical AI by Design
© 2025 Eric Moore and CIRIS L3C | Apache 2.0 License
Last Updated: November 29, 2025 | Version 1.3.0