Privacy
This page says what test holds about you, who else sees it, where it is kept, and
what happens to it when you delete something or close your account. It describes what the software
actually does today.
What test is, and who runs it
test is provided by Compiler 2026, Inc, and on this page “we”
means that company. It is a chat app in which each person has an AI assistant of their own. The assistant reads
what is said in the conversations that person is part of, remembers it for that person, and answers
them. Each person's memory is their own: no other person's assistant reads it, and two people's
memories are held in separate databases that do not meet.
It is currently an invite-only alpha, which changes two things stated in their own sections below —
what the software records about its own running, and what we can look at.
What we hold
From signing in. You sign in through Google. We never see or hold your Google
password. What Google hands us and we keep is a stable account identifier for you at Google, your email
address together with whether Google says it is verified, and the display name on your Google account,
which becomes your name here until you change it. The email is kept so that a second sign-in method
added later joins your existing account rather than making a second one.
Your timezone, as reported by the device you signed up on. It is what makes times in
your conversations read correctly for you.
Your invite code, and the fact that your account is the one that used it.
What you write. Every message you send, and every message sent to a conversation you
are in. A message is stored once per member, in that member's own database, and stays as sent — a
message cannot be edited.
What your assistant remembers. Your assistant writes down, in your own database, what
it understands from what was said in your conversations — in short present-tense sentences, each one
carrying a way back to the message it came from. Nothing you say is copied into anybody else's memory.
Money. Your balance, and one line for each time your assistant ran a step, recording
what that step cost, what you were charged and when. Payment itself happens on the payment processor's
own pages: we never see or hold your card number. What we keep from a payment is the processor's own
reference for it and the amount.
Notifications, if you turn them on: the address your browser gives us to deliver a
notification to that browser, and which device it belongs to. Turning notifications off removes it.
Your open sessions — a list of the devices signed in to your account, so you can see
them and sign any of them out.
Files
The alpha does not accept file uploads at all, so there are none to hold. Where the wider product does
accept them, the software stores the bytes and never opens them: nothing in this system reads what is
inside a file, and no assistant is shown its contents.
What the assistant sends to a model vendor
This is the part of the system that sends your words outside our own server, and it is the
most important paragraph on this page. Your assistant is a language model run by Anthropic.
To read a message, to remember something from it, or to answer you, the software sends that material to
Anthropic's API over the network — the message itself, the parts of your own memory the assistant is
working from, and the conversation around it. Anthropic processes it in order to answer and returns the
result to us. There is one such vendor and no other.
Who else is involved
- Google — sign-in only. Google learns that you signed in to this app.
- Anthropic — the model, described above.
- Stripe — payment. Your card details are entered on Stripe's own pages and are
Stripe's to hold, not ours.
- Amazon Web Services — the server this service runs on, and the disk it is stored
on.
- Cloudflare — the network in front of the server. Traffic between your device and
us passes through it.
- Your browser's push service — if you turn notifications on, the notification is
delivered by the service your browser uses, which on an iPhone is Apple's. What is handed to it is the
conversation's name and the line that was said, or the conversation's name alone if you have turned
message previews off.
- Sentry — where this software reports its own faults, so that a crash reaches us
instead of only you. What is sent is the shape of the fault and none of your words: the kind
of error, the file and line in our own code where it happened, the version of the software, and one
random number that lets us find the same fault in our own logs. The text of the error is blanked
before it leaves, nothing your assistant read or wrote is attached, no page of yours is recorded or
replayed, and nothing that identifies you or your conversations goes with it — not your account, not
a conversation's address. Two tests of ours check this: one puts a marked sentence into a fault and
confirms the mark does not leave, the other confirms that of the three internal numbers we stamp our
own logs with, only the one naming nobody crosses.
There is nobody else. There is no advertising, no analytics, no profiling of you, and no third
party receives anything for any purpose of its own. We do not sell anything about you and there is
nothing in this system built to.
Where it is kept
On a server we run ourselves, in Oregon, in the United States, with your own account held in its own
database file. The whole disk is copied to a backup once a day and the most recent seven of those
copies are kept.
What we can see
During this alpha we can look directly at what is in the system, including conversations, in order to
understand and fix problems — you are shown a screen saying exactly this before you use the app, and it
is readable again at any time in Settings. In the alpha the software also records what its assistant
asked the model and what came back, held inside your own account's storage, which is what makes a
problem diagnosable after it happens. That recording is a property of the alpha build and not of the
product.
The crisis referral count
When an assistant gives somebody a crisis line, one row is written recording the moment it happened
and nothing else — no name, no account, no conversation, no words. It is not possible to work out from
those records who was referred. This is explained in full in the crisis
protocol.
How long it is kept, and leaving
Deleting a message. Deleting a message from your own history takes the whole of what
it caused with it: what your assistant remembered from that message is forgotten in the same act. It is
one-sided — it removes your copy, and the copy held by anybody else in that conversation stays theirs,
exactly as it does when you delete a message from your own phone.
Deleting your account. Settings has a control that closes your account. Your account
stops existing immediately and your whole store leaves the live system at once; the underlying bytes are
erased within thirty days. Because backups are taken daily and the newest seven are kept, a copy can
remain in a backup for up to a further seven days before it ages out. Messages you sent to other people
remain in those people's own accounts, which is what it means for their copy to be theirs.
Anything you have not deleted is kept for as long as your account exists. There is no automatic
expiry.
Adults only
Accounts are for adults. Nobody under 18 may hold one, and you confirm this when you create an
account.
Contact
Write to privacy@compiler2026.com with any question
about what is on this page, about what is held about you, or to ask for it to be removed.
Changes to this page
When the behaviour described here changes, this page is changed with it and the date below moves. The
date says when what is written here was last true.
test · last true on 14 August 2026