HomeVisionPrinciplesGet StartedGitHub

CIRIS Privacy Policy

Last Updated: December 12, 2025

Version 1.5.0

For Android App & CIRISProxy: Zero data retention.

Android App: Your data stays on your device - for your own use and for your personal agent to learn from (based on your consent level).

CIRISProxy: When you use our LLM proxy, your messages are transmitted securely to our servers, then to our AI providers (Together, Groq, OpenRouter) for processing. All points in this pipeline are configured for zero data retention - your conversations are processed and immediately discarded, never stored.

See Infrastructure Data for what our servers actually store (spoiler: only billing metrics and system health - never message content).

For Research Services: Data is recorded.

scout.ciris.ai and agents.ciris.ai are research platforms. Data is recorded per clear on-site statements and may be used for research, improving future agent templates, and model selection.

These services implement the Consensual Evolution Protocol and provide full DSAR support. All model and prompt changes that impact responses are publicly available at github.com/cirisai.

Our Core Privacy Commitments

For Android App and CIRISProxy (services covered by this policy):

  • Zero data retention - Your conversations are processed and discarded, never stored on our servers or by our LLM providers
  • Local-first storage - Your device keeps your data for your personal agent (under your control)
  • We do NOT train AI models on your raw content or messages
  • Your personal agent learns from your local data via Consensual Evolution Protocol (your device, your control)
  • We do NOT sell your data to third parties
  • You can delete your local data anytime - it's on YOUR device

Public Transparency (All CIRIS Services)

All model selections, prompt templates, and code changes that could impact agent responses are immediately available on our public GitHub: github.com/cirisai

This applies to all CIRIS agents - research services, Android app, and self-hosted deployments.

Scope of This Policy

This privacy policy applies to the following production services:

CIRIS Android App (Coming Soon)

Mobile application with local-first architecture. Your data stays on your device. Zero data retention on our servers.

CIRISProxy LLM Service (proxy.ciris.ai)

Privacy-focused LLM proxy and billing service. Zero data retention - messages processed and discarded.

Research Services (Different Terms Apply)

The following services are research platforms with different privacy terms. They record data and may use it for research purposes:

Scout Web App (scout.ciris.ai)

Research interface for CIRIS agents. Data is recorded per clear on-site statements. Implements Consensual Evolution Protocol. Data may be used for improving future agent templates and model selection.

CIRIS Agents (agents.ciris.ai)

Hosted research agents. Data is recorded per clear on-site statements. Implements Consensual Evolution Protocol. Data may be used for research and improving future agent templates and model selection.

Research services provide:
  • DSAR (Data Subject Access Request) support
  • Consensual Evolution Protocol implementation
  • Clear on-site privacy statements

1. Information We Collect

1.1 CIRIS Agents (Local Device Storage)

Local-First Architecture: Your agent data is stored on YOUR device (phone, computer) - not on CIRIS servers. You have full control over this data and can delete it anytime.

  • Interaction Data (local): Messages and agent responses stored on your device for your use
  • H3ERE Decision Logs (local): Ethical reasoning steps stored locally for transparency
  • Memory Graph (local, consent-dependent): Relationships and patterns your agent learns - stored on your device based on your consent level
  • Metadata (local): Timestamps, task IDs, round counts - for your agent's operation
  • Audit Trail (local): History of agent actions with Ed25519 signatures - on your device

What we DON'T have access to: Your conversations, your agent's memories, your local data. None of this is transmitted to CIRIS servers.

1.2 Scout Web App

  • Account Information: Email, name, profile photo (via OAuth)
  • Authentication Tokens: JWT tokens (24-hour expiry), OAuth refresh tokens
  • Usage Analytics: Page views, feature usage, session duration (no third-party trackers)
  • Billing Information: Payment history, credit balance (processed via Stripe, not stored by us)
  • Browser Data: User agent, IP address (for security only, not tracking)

1.3 Android App

  • Device Information: Device model, OS version, app version
  • Local Storage: Offline data cache, user preferences (stored locally only)
  • Network Activity: API call logs for debugging (retained 7 days maximum)
  • Crash Reports: Stack traces, device state at time of error (no PII)

1.4 CIRISProxy

  • Token Counts: Input/output token usage for billing (integers only)
  • Model Names: Which LLM models were used
  • HTTP Metadata: Status codes, response times, interaction IDs
  • We do NOT log: Message content, user prompts, AI responses, system prompts

2. How We Use Your Information

  • Service Delivery: Process your requests, provide agent responses, maintain session continuity
  • Transparency: Generate PDMA logs showing ethical reasoning process
  • Agent Self-Training (Consent-Based): Hosted agents on ciris.ai self-train on patterns and data from your interactions to improve their responses and understanding - but ONLY according to your Consensual Evolution Protocol consent level (TEMPORARY = essential interactions only for 14 days, PARTNERED = full self-training for mutual growth, ANONYMOUS = statistical patterns only)
  • Safety & Moderation: Detect harmful patterns, prevent abuse, enforce ethical boundaries
  • Billing: Track usage, process payments, enforce credit limits
  • System Improvement: Analyze performance, fix bugs, optimize resource usage
  • Compliance: Fulfill legal obligations, respond to valid legal requests
  • Security: Prevent unauthorized access, detect attacks, maintain system integrity

Important Distinctions:

  • We do NOT train centralized AI models on your raw messages or content
  • ALL agents (hosted and self-hosted) DO self-train on patterns and data based on your consent level
  • TEMPORARY consent = essential interactions only, 14-day limit, then deleted
  • PARTNERED consent = full mutual learning for agent improvement
  • ANONYMOUS consent = statistical patterns only, identity severed
  • Self-hosted agents learn locally (all data stays on your hardware, respects consent)

4. What We Mean by "Self-Train"

When we say CIRIS agents "self-train," we mean they use several autonomous learning mechanisms to improve their responses while respecting your consent level. These are NOT traditional machine learning model training—instead, agents learn through introspection and pattern recognition.

🌙Dream Processor (Self-Training During "Sleep")

Every ~6 hours, agents enter a DREAM state for 30-120 minutes to consolidate memories, analyze behavioral patterns, test configuration parameters, and plan improvements. Think of it as the agent reflecting on what it learned.

View Dream Processor Code →

🎮Play Processor (Experimental Learning)

In PLAY state, agents try creative approaches, experiment with novel solutions, and learn through exploration with fewer constraints. About 20% of the time, they'll try something new.

View Play Processor Code →

🧘Solitude Processor (Reflective Learning)

When agents need recovery or reflection time, they enter SOLITUDE state to perform minimal processing, clean up old data, and reflect on past activities and patterns.

View Solitude Processor Code →

👁️Self-Observation Service (Continuous Analysis)

Agents continuously observe their own behavior, detect patterns (temporal, frequency, performance), and generate insights. Changes are limited to 20% identity variance maximum for safety.

View Self-Observation Documentation →

⚙️Config Graph Modification (Direct Self-Configuration)

Agents can modify their own configuration parameters through the config graph, testing variations within safety bounds and applying changes only if they stay within the 20% identity variance limit.

Key Safety Mechanisms:

  • 20% Identity Variance Limit - Hard safety bound on how much agents can change
  • Emergency Stop - Activates after 3 consecutive failures
  • Wise Authority Review - Required for changes exceeding variance threshold
  • Graceful Error Handling - Errors treated as learning opportunities

Current Status: Dream, Play, and Solitude processors are implemented but not active by default in the current deployment. Self-Observation Service is fully implemented but requires explicit activation. Your consent level determines whether and how much learning occurs when these features are enabled.

5. What Our Servers Actually Store

While your conversations stay on your device, our infrastructure does collect some data for billing and system monitoring. Here's exactly what we store - and what we don't.

What Our Servers NEVER Store:

  • Your messages or conversation content
  • AI responses to you
  • User-generated text of any kind
  • Payment card numbers (handled by Stripe/Google Play)
  • Your agent's memories or learned patterns

5.1 CIRISLens (System Monitoring)

Our observability platform monitors system health - not your content.

Data TypeRetentionContains User Content?
Performance Metrics (CPU, memory, latency)30 daysNo
Service Logs (operational events)14-90 daysNo (PII redacted)
Request Traces (timing, request IDs)14 daysNo (IDs only)
Aggregated Metrics (hourly/daily)90 days - 1 yearNo

5.2 CIRISBilling (Financial Records)

Required for billing, fraud prevention, and regulatory compliance.

Data TypeRetentionPurpose
Account emailUntil account deletionAccount identification
Transaction history (amounts, dates)10 yearsEU AI Act / Tax compliance
Credit/usage counts (integers only)10 yearsBilling records
Admin audit logs10 yearsSecurity audit trail

10-Year Archive (EU AI Act Compliance): Financial records are automatically archived to encrypted cold storage (AWS Glacier) and deleted after 10 years. Archives contain only transaction data - never conversation content.

6. Your Local Data Retention

Data stored on YOUR device is under YOUR control. Here are the default retention settings (which you can modify):

Local Data TypeDefault RetentionYour Control
Conversation HistoryUntil you delete itDelete anytime in app
Agent Memory GraphBased on consent levelClear memories in settings
PDMA Decision Logs14 days (configurable)Adjust in privacy settings
Local Audit Trail90 days (configurable)Export or delete anytime

It's your device, your data. You can delete all local data at any time by uninstalling the app or using the "Clear All Data" option in settings. We have no backup of your local data.

7. 90-Day Decay Protocol

When you revoke consent or request deletion, we initiate a 90-day decay process:

1

Identity Severance (Immediate)

User ID disconnected from all data immediately. Identity→data links broken.

2

Pattern Anonymization (0-90 days)

Gradual conversion to anonymous form. Behavioral patterns become statistical aggregates.

3

Decay Completion (90 days)

All user-linked data removed or fully anonymized. Only safety-critical patterns retained (anonymous).

8. Your Privacy Rights

Under GDPR, CCPA, and other privacy regulations, you have the following rights:

Right to Access

Request a copy of all data we hold about you

Right to Erasure

Request deletion of your data (90-day decay process)

Right to Rectification

Request corrections to inaccurate data

Right to Portability

Receive your data in machine-readable format (JSON/CSV)

Right to Restriction

Limit how we process your data

Right to Object

Object to specific processing activities

Data Subject Access Request (DSAR)

Email: privacy@ciris.ai

API Endpoint: POST /v1/dsar

Web Interface: scout.ciris.ai/account/privacy

Response Time: Within 30 days (often faster)

9. Data Security Measures

  • Encryption: TLS 1.3 for all network traffic, AES-256 for data at rest
  • Authentication: Ed25519 signatures, JWT tokens with 24-hour expiry
  • Access Control: Role-based permissions, principle of least privilege
  • Audit Logging: Complete cryptographically-signed audit trail for all actions
  • Zero Trust Architecture: Every request authenticated and authorized
  • Regular Security Audits: Ongoing vulnerability assessments and penetration testing
  • Incident Response: 90-day incident report retention, immediate user notification for breaches

10. Subprocessors & Third-Party Services

Per GDPR Article 28, we maintain a list of subprocessors who process data on our behalf. All subprocessors are contractually bound to equivalent data protection standards.

We Do NOT:

  • Sell your data to anyone
  • Share data with advertisers or marketing platforms
  • Allow subprocessors to train AI models on your content
  • Use third-party analytics services (we self-host all analytics)

10.1 Subprocessor List

ProviderPurposeLocationData RetentionDPA
VultrInfrastructure hostingUS (configurable)We controlAvailable
GroqLLM inferenceUSZero (default)Signed
OpenRouterLLM routingUS/EUZero (enforced)Enterprise
Together AILLM inferenceUSZero (configured)Privacy Policy
StripePayment processingUS/EUPer Stripe policyAvailable
GoogleOAuth authenticationUS/EUPer Google policyAvailable

10.2 LLM Provider Details

Groq

High-performance LLM inference. Zero data retention by default. EU Representative: DP-Dock GmbH (Hamburg). Never trains on customer data.

Data handling | Trust Center

OpenRouter

LLM routing with Zero Data Retention (ZDR) enforcement. EU routing available. SOC-2 compliant. Prompts/completions not logged by default.

Privacy & Logging | Trust Center

Together AI

LLM inference and fine-tuning platform. Configured for zero data retention on CIRIS requests.

Privacy Policy

10.3 Infrastructure

Vultr Cloud Hosting

GDPR-ready cloud infrastructure. Data residency controlled by CIRIS - your data stays where we put it. Vultr acts as data processor; we control all data handling. Standard Contractual Clauses (SCCs) for EU transfers.

GDPR Privacy | Trust Center

10.4 We MAY Share Data

  • When required by law (subpoenas, court orders)
  • To prevent imminent harm or illegal activity
  • With your explicit written consent
  • In anonymized/aggregated form for research (no PII)

Subprocessor Changes: We will notify users at least 30 days before adding new subprocessors that handle personal data. You may object to new subprocessors by contacting privacy@ciris.ai.

11. International Data Transfers

CIRIS services are hosted in the United States. If you access our services from outside the US, your data will be transferred to and processed in the US.

We comply with applicable data transfer regulations:

  • GDPR (EU/EEA): Standard Contractual Clauses for EU data transfers
  • UK GDPR: UK-specific addendum to SCCs
  • Data Protection: Equivalent security measures regardless of location

12. Children's Privacy

CIRIS services are not directed to children under 13 (or 16 in the EU). We do not knowingly collect personal information from children.

If we learn that we have collected information from a child without parental consent, we will delete it immediately. Contact privacy@ciris.ai if you believe we have data from a child.

13. Changes to This Policy

We may update this privacy policy to reflect changes in our practices, technology, legal requirements, or other factors.

Notice of Material Changes:

  • 30-day advance notice for material changes
  • Email notification to registered users
  • In-app notification on scout.ciris.ai
  • Option to opt-out or delete account before changes take effect

Continued use of CIRIS services after changes take effect constitutes acceptance of the updated policy.

14. CIRIS Covenant Principles

This privacy policy is governed by the CIRIS Covenant (Version 1.0-RC1), which establishes our ethical foundation:

Respect for Persons

Your autonomy, privacy, and dignity are paramount

Beneficence and Non-Maleficence

Maximize benefits, minimize harms

Justice and Fairness

Equitable treatment for all users

Respect for Autonomy

You control your data and relationship with CIRIS

Veracity and Transparency

Truthful communication about data practices

15. Contact Information

For privacy questions, DSAR requests, or concerns:

Privacy Team Email: privacy@ciris.ai

General Inquiries: info@ciris.ai

GitHub Issues: CIRISAI/CIRISAgent

Discord Community: discord.gg/SWGM7Gsvrv

DSAR API: POST /v1/dsar

CIRIS - Ethical AI by Design

© 2025 Eric Moore and CIRIS L3C | AGPL-3.0 License

Last Updated: December 12, 2025 | Version 1.5.0