Privacy Policy

How we handle
your data.

What we collect, why we collect it, how we protect it, and the choices you have. Written to be read, not just filed.

Last updated: October 4, 2026 · Effective: July 4, 2026

DataPalace is company memory your AI can actually use. The knowledge you keep here is some of the most sensitive you own, so this page explains, in plain language, exactly how we treat the personal information that flows through it. If anything below is unclear, ask us. We would rather you did.

We are the caretaker of your memory. You remain its owner.

The Short Version

  • Every company's knowledge is walled off from every other company's.
  • Your personal palace is private from your employer and stays yours if you leave.
  • We do not sell your data, and we do not train AI models on your knowledge.
  • You can see and correct your personal information, ask us for a copy of it, and ask us to delete it.

Who We Are

DataPalace is a product of 1479388 B.C. LTD. (doing business as DataPalace), based in Victoria, British Columbia, Canada. In this policy, “DataPalace,” “we,” “us,” and “our” mean 1479388 B.C. LTD. operating the DataPalace service. This policy covers our marketing site, the DataPalace web application, and the DataPalace MCP server through which AI clients connect.

How This Policy Works: Your Organization and DataPalace

DataPalace is a business-to-business service, so two relationships matter.

Knowledge you or your organization put in. When your organization subscribes, it decides what knowledge to store and who may see it. Your organization is responsible for that content and for having the right to store it. We process it on your organization's behalf and under its instructions.

Your role decides what you can do with it. Within your organization, your assigned role and permissions determine which company information you can access, update, or delete. Access is granted palace by palace, and the AI caretakers you may use decide whether you can only read or also edit, so two people at the same company can have different permissions.

Personal information we collect directly. For the information we gather to run the service (your account, your use of the site and app, your support messages), we are the organization responsible for it, and this policy governs how we handle it.

If you use DataPalace through your employer or another organization, please direct requests about the knowledge base content to them first. We will support them in responding.

Information We Collect

Account and identity information

Your name, email address, and the sign-in identifiers created when you authenticate. You sign in with a one-time code we email you, or with a password if your account has one. We store passwords only in hashed form, never in plain text. AI tools you connect sign in separately, through OAuth 2.1.

Access and permissions

Which organizations you belong to and which AI caretakers you can use (Rose, who reads; Libby, who edits; Morpheus, who governs), so we can enforce what you may access and change.

Knowledge base content

The articles, categories, and metadata that you or your organization create. This is meant to be operational company knowledge, not regulated client data or customer personal information. Libby, our AI editor, is instructed to check whether personal information you give her belongs to a customer, to never save a customer's personal information in an article, and to offer to anonymize it instead. These are instructions to an AI, not a guaranteed filter, so review what you save.

Authorship and edit records

To keep every answer traceable, we stamp who created and who last changed each article and category, recording the person's name and a reference to their account.

Session and usage data

Each AI conversation receives its own short-lived session pass (about two hours) carrying your current organization and caretaker. Each sign-in session to the app also records your IP address and browser, and we use your IP address to limit repeated sign-in attempts. We keep access and activity logs to run the service securely and reliably; our hosting provider keeps those logs for up to 30 days.

Sales and early-access requests

If you contact our sales team or request early access, we collect what you enter in the form, such as your name, company, email address, phone number, website, and company size. On the sales form, we save your email address as soon as you enter it, even if you don't finish the form, so our team can follow up with you.

Support and feedback

If you send feedback or contact support, we receive your message, your name and email address, and anything you choose to include. We keep these conversations in our own help desk, which runs on our hosting infrastructure.

Technical data

Standard information your browser sends automatically, such as IP address, device and browser type, and log data, collected when you use the site or app.

Cookies and Similar Technologies

Our site and app use cookies and similar technologies, such as your browser's local storage, to run the service.

Essential cookies

These keep the service working. They sign you in and keep your session secure, remember choices you make in the app (such as which palace you are working in and how wide you like the palace panel), and store basic preferences in your browser (such as light or dark mode). The service will not function properly without them.

Analytics and product-improvement cookies

We don't set analytics or session-replay cookies today. We intend to add non-essential tools to understand how people use DataPalace and to improve the app and our operations, such as product analytics, session replay, and multi-channel customer analytics that help us connect your experience across the places you interact with us. Before we add them, we will update this page.

Your choices

You can control or disable cookies through your browser settings. Most browsers let you refuse new cookies, ask to be notified when one is set, or delete existing ones. Disabling non-essential cookies will not stop you from using the core service, though some features, and our insight into how to improve it, may be reduced. Where the law requires your consent for non-essential cookies, we ask for it before we set them.

We do not use cookies for third-party advertising, and we do not sell what cookies collect.

How We Use Your Information

  • To provide, operate, and maintain DataPalace.
  • To authenticate you and enforce which palaces you may enter and what you may do there.
  • To power search across your knowledge, including semantic (vector) search.
  • To stamp authorship so every answer can be traced to its source.
  • To respond to your support requests and feedback.
  • To keep the service secure, reliable, and free of abuse.
  • To meet our legal and regulatory obligations.

We rely on the grounds permitted under Canadian privacy law, including your consent, performance of our agreement with you or your organization (our Cloud Service Agreement), and legitimate business purposes that a reasonable person would consider appropriate.

AI, Search, and Your Data

This is the part people ask about most, so we are direct about it.

We do not train models on your knowledge. We do not sell your data, and we do not use your knowledge base content to train our own or anyone else's foundation models.

Making your knowledge searchable. To let you search by meaning, article text is converted into numerical embeddings by a third-party embeddings provider. Content sent for embeddings is processed under that provider's API terms and, under those terms, is not used to train its models.

Outside AI you connect. When you connect an AI tool (such as ChatGPT, Claude, Gemini, or a coding agent) through MCP, it only has access to the palaces and articles that are available to your authenticated DataPalace user account. What that AI vendor does with the content it receives is governed by your agreement with that vendor, not by DataPalace, so choose your connections deliberately.

How We Share Information

We share personal information only as needed to run the service, and only with providers bound to protect it and to use it solely for the service they provide us:

  • Railway: cloud hosting and infrastructure.
  • OpenAI: generating the vector embeddings that power search.
  • Postmark: sending and receiving transactional email.
  • UptimeRobot: monitoring uptime and service health.
  • Stripe: processing payments and managing subscriptions and invoices for paid plans.
  • Google Workspace: our business email, including messages you send to our support address.

We may also disclose information when the law requires it, to enforce our terms, or to protect the rights, safety, and property of DataPalace, our customers, or the public. If our business is ever involved in a merger, acquisition, or sale of assets, information may transfer as part of that deal, under continued protection consistent with this policy. We do not sell personal information.

Where Your Data Is Processed

DataPalace is operated from Canada, and some of our providers process data in other countries, including the United States. When information is processed or stored outside Canada, it becomes subject to the laws of that country, including lawful access by courts and authorities there. We work with providers that commit to appropriate safeguards for the information they handle on our behalf.

How We Protect Your Information

Security is designed in, not bolted on. Every company's space is walled off at the database level using various methods including Row-Level Security. AI tools connect through modern OAuth 2.1, and each AI connection gets its own pass that expires on its own. Access is granted on a least-privilege basis, data is encrypted in transit, and credentials / secrets are managed centrally. For the fuller picture, see our Trust, Security and Your Data page.

How Long We Keep It

We don't delete information on a timer. Here is what we keep, and how it goes:

  • Your account. We keep it while your account exists. On a verified deletion request, we delete your account within 30 days, along with your memberships, your sign-in records, and your personal palace. If you own a company palace, you first need to transfer its ownership, or close it and ask us to delete it.
  • Other records tied to your email. On a verified deletion request, we also delete your sales and early-access requests and your support conversations. We keep billing records for as long as tax law requires.
  • Your personal palace. It is deleted with your account, or on its own on a verified request. Where palace management is turned on for your account, you can also delete it yourself in Settings, which is immediate and permanent.
  • Company palaces. Content stays while the palace exists. Cancelling a subscription moves the palace to the Free plan and deletes nothing, and closing a palace keeps its content so it can be reopened. The palace owner can ask us to delete a closed palace, or to send a copy of it first, and we do so within 30 days of a verified request. Articles you wrote in a company palace belong to that organization, so deleting your own account does not delete them.
  • Sign-in sessions. Expired sessions, with the IP address and browser they recorded, are cleared the next time you sign in, and all of them are deleted with your account.
  • Sales and early-access requests. We keep them until you ask us to delete them.

We act on a deletion or copy request only once we have verified that it comes from the account holder, or for a company palace, from its owner. For example, the request must come from the email address on the account.

One deliberate exception: to keep an accurate audit trail, the recorded author or editor name may remain on an article even after that person's account is deleted. On a verified deletion request, we will remove those name records as part of fulfilling it.

Your Privacy Rights

Under Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and British Columbia's Personal Information Protection Act (PIPA), you can:

  • Ask what personal information we hold about you and get access to it.
  • Ask us to correct information that is wrong or incomplete.
  • Ask for a copy of your information, which we send in a common, machine-readable format.
  • Ask us to delete your account and your information.
  • Withdraw your consent, subject to legal and contractual limits.
  • Ask how we have handled your information.

Depending on where you live, you may have further rights, such as erasure, portability, or objection under the EU or UK GDPR. To exercise any of these, email help@datapalace.ai. We respond within the timeframes the law requires, generally within 30 days under PIPEDA. If you reach DataPalace through your employer, we may direct your request to them as the organization responsible for that content.

Your Choices

You can update your account details, and you can disconnect an AI tool at any time in that tool's own settings. Its DataPalace session pass also expires on its own. Your personal palace stays with your account if you leave your company or employer. It belongs to you, not the company that paid for the seat. If we ever send optional product emails, every one includes a way to opt out.

Children's Privacy

DataPalace is a tool for businesses and is not directed to children. We do not knowingly collect personal information from children. If you believe a child has provided us information, contact us and we will delete it.

Changes to This Policy

We may update this policy as the product and the law evolve. When we do, we revise the date at the top. For material changes, we will give reasonable notice through the service or by email before they take effect.

Contact Us

Questions about privacy, or want to exercise a right? Reach our privacy contact at help@datapalace.ai, or write to 1479388 B.C. LTD. (DataPalace), Victoria, British Columbia, Canada.

If you are not satisfied with our response, you may contact the Office of the Information and Privacy Commissioner for British Columbia, or the Office of the Privacy Commissioner of Canada.

Governing Law

This policy is governed by the laws of the Province of British Columbia and the applicable laws of Canada.

Nothing to hide.
Everything to protect.

Questions about data handling? Ask us directly, we would rather you did.