Privacy Policy
Effective date: August 2026
EntityO is operated by Stefan Asanin, Stockholm, Sweden. This policy explains what personal data we collect, why we collect it, how we store it, and what your rights are. We keep it honest and complete.
What we collect
We collect two categories of data:
Account data, collected when you register:
- Email address
- Password (stored as a bcrypt hash. We cannot recover your password)
- API key hash and prefix (stored securely. Full key shown once at creation)
- Usage counters: daily inference call count, reset date
- Account creation timestamp
EntityO world data, generated by your use of EntityO:
- Patterns: summaries of experiences you feed to EntityO
- Feedback entries: valence signals you provide on responses
- Inferences: conclusions derived from your accumulated patterns
- Entity state: bias, energy, connection weights
We do not collect names, phone numbers, payment information, location data, or device identifiers. We do not use cookies. We do not use analytics tracking. We do not use third-party advertising scripts.
Why we collect it
| Data | Purpose | Legal basis |
|---|---|---|
| Email address | Account authentication and service communications | Contract performance |
| Password hash | Secure account authentication | Contract performance |
| API key | Authenticating MCP server connections | Contract performance |
| EntityO world data | Providing the EntityO service: pattern accumulation, inference, query | Contract performance |
| Usage counters | Enforcing daily rate limits to control infrastructure costs | Legitimate interest |
| Waitlist email | Notifying you when early access is available | Consent |
How we store it
Account data is stored in a PostgreSQL database hosted by Neon, located in the European Union. Connections are encrypted. Access is restricted to the EntityO backend service.
EntityO world data (patterns, feedback, inferences, connections) is stored in a dedicated SQLite database hosted by Turso, in the Ireland (eu-west-1) region. Each user has an isolated database. Your data is not shared with or accessible by other users. Connections are encrypted.
Third-party data processors
| Processor | Purpose | Data shared | Location |
|---|---|---|---|
| Neon | Account database | Account data | EU |
| Turso | EntityO world database | World data | Ireland (EU) |
| Render | API and MCP server hosting | Request data in transit | EU (Frankfurt) |
| Vercel | Web app hosting | Request data in transit | Global CDN |
| Anthropic | Inference articulation (Claude Haiku) | Pattern summaries only, truncated to 60 characters. No raw stimulus content, no account data, no identifiers. | USA |
| Resend | Transactional email delivery | Email address | USA |
Note on Anthropic: When you run inference, EntityO sends truncated pattern summaries (maximum 60 characters each) to Claude Haiku to generate natural language descriptions of derived conclusions. We do not send raw stimulus content, account data, or any identifier that links the request to you. Anthropic processes this data under its Data Processing Agreement.
Data retention
Account data and EntityO world data are retained for as long as your account is active. When you delete your account, your account record is removed from Neon and your EntityO database is dropped from Turso within 24 hours. No backup copies are retained after deletion.
Waitlist email addresses are retained until early access notification is sent, or until you ask us to remove you.
Your rights under GDPR and the EU Data Act
You have the following rights regarding your personal data:
- Right of access (Article 15) — you can request a copy of all data we hold about you. Use the Export function in Settings at app.entityo.com/settings to download a complete JSON export immediately. Or email us and we will respond within 30 days.
- Right to rectification (Article 16) — you can correct inaccurate data. For account data, email us. For EntityO world data, you can delete individual patterns through the app.
- Right to erasure (Article 17) — you can delete your account and all associated data at any time from Settings. Deletion is immediate and permanent.
- Right to data portability (Article 20 / EU Data Act) — you can export all your data in machine-readable JSON format at any time from Settings. No request needed. The export is self-serve and immediate.
- Right to object (Article 21) — you can object to processing based on legitimate interest. Email us and we will respond within 30 days.
- Right to withdraw consent — for processing based on consent (waitlist), you can withdraw at any time by emailing us. This does not affect the lawfulness of processing before withdrawal.
To exercise any right, email hello@entityo.com. We respond within 30 days. If you are unsatisfied with our response, you have the right to lodge a complaint with the Swedish Authority for Privacy Protection (IMY) at imy.se.
International data transfers
Anthropic (Claude Haiku) and Resend are based in the USA. Transfers to these processors are made under the EU Standard Contractual Clauses (SCCs) as part of their respective Data Processing Agreements. No other data is transferred outside the EU.
Security
All connections to EntityO services are encrypted via HTTPS/TLS. Passwords are hashed with bcrypt and are not recoverable. API keys are stored as bcrypt hashes. Only the prefix is stored in plaintext. Your EntityO database is isolated from all other users and accessible only via a per-database authentication token.
Children
EntityO is not directed at children under 16. We do not knowingly collect data from anyone under 16. If you believe a child has provided us with personal data, email us and we will delete it promptly.
Data controller
Stefan Asanin
Stockholm, Sweden
hello@entityo.com
Changes to this policy
If we change this policy materially, we will update the effective date above and notify registered users by email. We will not reduce your rights under this policy without your explicit consent.
Questions? Email hello@entityo.com. We will reply.