SF2X · the brain that begins where you did

Privacy Policy

Version 1.0 · Effective 18 June 2026. Written in plain language for transparency. This is not legal advice, and SF2X recommends review by qualified counsel before you rely on it for compliance. Controller: Cameron Piper (operating as SF2X), an individual. Contact: campiper84@gmail.com (a dedicated privacy@sf2x.com address will be added at public launch).

SF2X is a small, independent project — built and run by one person. This policy explains, honestly, what we collect, why, who it's shared with, and the real, self-serve controls you have over it. Two things shape everything below: we never sell your data, and we never train any model on your private conversations.

On this page: 1 · No-account use 2 · What we collect 3 · How we use it & legal bases 4 · Your memory & the brain 5 · AI processing & outputs 6 · Who we share with 7 · Your rights 8 · International transfers 9 · Retention & security 10 · Children 11 · Changes & contact

1 · Talking to her without an account

You can use the public brain at sf2x.com without signing up. As a guest:

Safety, not therapy. Replies are screened by automated moderation. If you express distress or thoughts of self-harm, she may share crisis resources — in the US call or text 988; anywhere, findahelpline.com. She is an AI, not a counselor or a crisis service. In an emergency, contact your local emergency number (911 in the US) right away. See the Terms (Safety).

2 · What we collect if you create an account

Information you give us

Information collected automatically

What we do not collect

Passwords (there are none) · advertising identifiers · third-party tracking profiles · full payment-card numbers (if you ever buy something, card details go straight to Stripe and we never see them).

3 · How we use your data — and the legal basis

PurposeGDPR legal basis
Provide the service, sign you in, remember you (if you opted in)Performance of a contract; consent (for memory & birth data)
Rate-limit, detect abuse, run safety moderation, keep the service upLegitimate interests (security & integrity)
Compute your optional Origin SignatureConsent
Respond to your rights requests; keep records we're legally required to keepLegal obligation

We do not use your data for advertising, for sale to third parties, or to train our own models. You can withdraw consent at any time (see §7); that doesn't affect processing already done.

4 · Your memory & how the brain learns

This is the part most products get wrong, so we'll be exact:

5 · AI processing & outputs

6 · Who we share data with

Only the providers that run the service, each strictly to perform its function. We do not sell your data and do not share it for advertising.

ProviderRoleWhat it sees
OpenAIAI inference, embeddings, moderationThe text of messages/content sent for processing
SupabaseDatabase & passwordless authAccount data, your stored cells, consent records
CloudflareHosting, CDN, security, rate-limit storageNetwork requests, transient security signals
ResendTransactional email (your sign-in codes)Your email address + the code
Stripe (only if you make a payment)Payment processingPayment details (we never store card numbers)

We may also disclose data if required by law, or to protect rights, safety, and the integrity of the service.

7 · Your rights — and the real buttons that honor them

Most policies promise rights and bury them behind an email. SF2X ships them as one-click tools:

GDPR (EU/UK): access, rectification, erasure, restriction, portability, objection, and the right to lodge a complaint with your supervisory authority. California (CCPA/CPRA): know, delete, correct, and opt out of "sale"/"sharing" — which we do not do — with no discrimination for exercising your rights. To make any request, email campiper84@gmail.com. We aim to respond within the timeframe the law requires.

8 · Where your data is processed

SF2X is operated from, and most processing happens in, the United States (OpenAI, Supabase, Cloudflare's global edge). If you are in the EU/UK and your data is transferred to the US, it is done under appropriate safeguards such as Standard Contractual Clauses, as offered by our processors. (Specific transfer mechanisms will be confirmed with counsel and updated here.)

9 · Retention, deletion & security

Retention. Guest conversations are never stored on our servers. Member data is kept while your account is active and is deleted promptly when you erase it (we may retain limited records we are legally required to keep, e.g., for tax or to evidence a deletion). Operational logs are short-lived. Backups are rotated and purged on a rolling basis.

Security. Passwordless sign-in (nothing to leak) · cryptographically-scoped per-member isolation, verified by an automated test · row-level security and service-role-only data access · TLS in transit · least-privilege keys held only server-side · hard rate-limits and a daily spend ceiling to blunt abuse. No system is perfectly secure; if a breach affecting you occurs, we will notify you as the law requires.

10 · Children

SF2X is not directed to children under 13 (or the higher minimum age in your region, e.g., 16 in parts of the EU) and we do not knowingly collect their data. If you believe a child has provided us data, contact us and we will delete it.

11 · Changes & contact

We may update this policy; we'll change the version and effective date above and, for material changes, give notice (e.g., on the site or by email). Questions or requests: campiper84@gmail.com.