GNOSYS LABS Talk to us

Privacy

Your data is yours.

We hold the least data we need to run your experiments, keep it isolated per tenant, and delete it on your schedule. This page is a plain-English account of what we collect and why.

Last updated: 2026-06-23.

What we collect

  • Account data — the email and credentials you use to sign in, and your API keys (stored hashed, never in plaintext).
  • Datasets you upload — the classifier inputs, model outputs, scores, slices, and any gold labels you submit. This is the data the experimentation loop runs on.
  • Operational metadata — run status, token usage for billing, and structured request logs (tenant, route, status, duration). We never log API keys, password hashes, or raw upload bytes.
  • Sign-in records — for each attempt to sign in to an account or the operator console we record the time, whether it succeeded, the email address submitted, and a salted hash of the IP address. We keep the hash, never the address itself. This is a security measure: it is how we notice someone trying passwords against your account.
  • Site analytics, only if you agree — see Cookies below. Nothing is recorded about your visit unless you accept.

Cookies

We use three cookies and no third-party trackers. There is no advertising network, no analytics vendor, and no cross-site profile.

  • Session cookies (gnosys_user, gnosys_session) — strictly necessary. They keep you signed in. Without them the product cannot work, so they do not require consent.
  • Consent cookie (gnosys_consent) — remembers the choice you made about the analytics cookie, so we ask once instead of on every page. Strictly necessary in the sense that it exists to honour a "no".
  • Analytics cookie (gnosys_vid) — only set if you press Accept. It holds a random identifier and nothing else. We use it to count how many distinct people visit the site and which page they arrived on. It is never joined to your account, never shared, and never used to build a profile or target advertising.

If you decline, no identifier is created and no record of your visit is written — we keep only an anonymous tally of how many people accepted versus declined, so we can tell whether our visitor numbers are meaningful. You can change your mind at any time by clearing cookies for this site, which brings the banner back.

How we use it

Solely to operate the service: to run your propose→evaluate→ certify loop, to score predictions you request, to enforce quotas, and to bill usage. We do not sell data, and we do not train shared models on one customer's data for another customer's benefit.

Isolation

Each tenant's datasets, runs, and labels are stored under a per-tenant namespace and scoped by tenant on every read. API access is bearer-token authenticated; a token only ever resolves to its own tenant.

Retention & deletion

You can delete a dataset at any time, and we honour deletion requests for your uploaded data and labels on the schedule you set. When you close an account we remove your data within a bounded window. Audit records that make a result reproducible (pre-registration digests, gold-snapshot hashes, run manifests) are retained without the underlying raw text where you have asked for the raw data to be removed.

Sub-processors

We use a small number of infrastructure providers (hosting, database, object storage) and an LLM provider to run the platform models. We will keep an up-to-date list available on request and notify design partners of material changes under their agreement.

Your choices

You can decline the analytics cookie and still use every part of the site — nothing is withheld and no feature degrades. You can export your audit artifacts, request a copy or deletion of your data, and opt into a private deployment (see Security) where your data never leaves your environment.

Contact

Privacy questions and data requests: kodycoppock@gmail.com.

We'd like to set one cookie to count unique visits. It stores a random id and nothing else — no third parties, no advertising, no profile. Privacy