Privacy
What we hold, and what you can ask us to do about it.
Written in plain English on purpose. If anything here is unclear, ask us and we will answer in the same language.
Last updated 30 August 2026 / Version 1.1
01 / Who we are
The controller.
Holocron builds and operates the Holocron platform. Where this policy says we, us or Holocron, it means the Holocron company that provides your service, which is named in the agreement your organisation signs with us. If you want our registration details before that point, ask and we will send them.
For anything in this policy, or to exercise one of the rights in section 09, write to privacy@holocron.global. We are not currently required to appoint a data protection officer. If that changes, this section will name them.
02 / What this covers
Two different relationships.
This policy covers both, and they are governed by different rules, so it is worth being clear which one you are in.
You visit the site or contact us
We decide what happens to your details, so we are the controller. Sections 03 to 09 apply to you.
Your organisation uses Holocron
Your organisation decides what goes into the platform, so they are the controller and we are the processor acting on their instructions. What we may do with that content is set by the data processing agreement we sign with them, not by this policy. Section 05 describes it, and the agreement wins if the two ever disagree.
03 / What we collect
Four things, and nothing else.
We do not buy personal data, we do not sell it, and we do not use it for advertising.
04 / Why, and on what basis
The lawful bases.
| What | Why | Basis |
|---|---|---|
| Your enquiry | To reply to you and, if it goes further, to arrange a demo | Legitimate interests, and steps before a contract |
| Server logs | To keep the site available and secure | Legitimate interests |
| Account details | To run the service your organisation bought | Contract, and our customer's instructions |
| Customer content | To do the work your organisation asked the platform to do | Our customer's instructions under the data processing agreement |
05 / Artificial intelligence
What the models do and do not get.
Holocron uses large language models supplied by third parties to do the work in the platform. This is the part of the policy most people want, so it is stated plainly.
We do not train on your content
Nothing your organisation puts into Holocron is used to train or fine tune a model, ours or a vendor's. We do not build a proprietary model out of your work.
The providers, by name
Holocron sends work to OpenAI and Anthropic through their commercial APIs. Both exclude API content from model training by default, and both are bound to us by a data processing agreement. If we add, remove or change a provider, this section changes with it.
Content is sent to be processed
To produce an answer, the relevant part of your content is transmitted to the provider, processed, and returned. A provider may hold it briefly to detect abuse, and no longer than 30 days, after which it is deleted. Nothing is kept for reuse. Where a provider offers processing in the region agreed with your organisation, that is where it runs; otherwise section 08 applies.
A person is always accountable
Holocron drafts, proposes and files. It does not make final decisions about people, and there is no automated decision making with legal or similarly significant effects. Every action is attributable in the audit trail.
06 / Google Workspace
Calendar and Drive, if you connect them.
Connecting a Google account is optional, done by each person for themselves, and off until you choose it. Google holds anyone who reads this data to a particular standard, so it is set out here in full rather than folded into the sections above.
| What we ask for | Why | What happens to it |
|---|---|---|
| Your Google email address | To show you which account is connected, and to reconnect it | Held with the connection until you disconnect |
| Your calendar, read only | So Aria knows what is in your week while you are talking to her | Read fresh each time and never stored. Two days back, seven days ahead, twenty five events at most |
| Individual Drive files you pick | So Aria can read a document you hand her | Held privately to you until you remove it or disconnect |
The Limited Use commitment
Holocron's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
No model is trained on it
Nothing we receive from Google is used to train or fine tune any model, ours or a vendor's. This is stated separately from section 05 because Google requires it to be, and it holds for your calendar and your Drive files alike.
We cannot browse your Drive
We ask for the narrowest Drive permission Google offers. It reaches one file at a time, only the ones you pick yourself, and it does not extend to the folder around them. Everything else in your Drive is invisible to us, and a file you hand Aria stays private to you rather than going to your whole organisation.
Disconnecting takes it back
Disconnecting deletes the Drive content we hold and then hands the permission back to Google, in that order, so there is no moment where the access is gone but the content is not. You can also do it from your own Google account settings at any time.
Where it goes to be processed. A Drive file you hand Aria is stored by our database provider, turned into search embeddings by OpenAI, ranked for relevance by Cohere when you ask something it answers, and read by Anthropic to write the reply. Your calendar goes to Anthropic only, as part of the conversation, and never to the others. These are the same suppliers listed in section 07, doing the same jobs, and none of them may use any of it for their own purposes.
We keep diagnostic traces of Aria's work so we can debug it. Calendar entries are deliberately held out of those traces, which record how many events were in the window and nothing about what they were, because a meeting title outlives the conversation it was read in. Content from a Drive file can appear in a trace where it was part of an answer.
07 / Who else sees it
Sub processors.
We use a small number of suppliers to run the service: cloud hosting and infrastructure, the model providers named in section 05, email delivery, and error monitoring. Each is bound by a written agreement, may only act on our instructions, and may not use anything for its own purposes.
The current list, naming each supplier, what it does and the country it processes in, forms part of the data processing agreement and is available from privacy@holocron.global on request. We tell customers before we add or replace one, so there is time to object.
We also disclose information where the law requires it, and to professional advisers under a duty of confidence. If Holocron is ever sold or merged, information may transfer with the business, and you will be told.
08 / Where it is held, and for how long
Residency and retention.
Customer content is held in the region agreed with your organisation at onboarding, and we will not move it to another region without telling you first. Where information leaves the United Kingdom or the European Economic Area, we rely on the UK International Data Transfer Addendum or the European Commission's Standard Contractual Clauses, with a transfer risk assessment behind them.
Enquiries. 24 months from our last exchange, unless it becomes a customer relationship.
Account records. The life of the agreement.
Customer content. Deleted on your organisation's instruction, and in any case within 30 days of the agreement ending. Backups are purged within 90.
Bug reports and feature requests. Kept while we still need them to fix or build the thing they describe. Any screenshot attached is deleted with the rest of your customer content.
Server logs. 90 days.
09 / Your rights
What you can ask for.
Under UK and EU data protection law, and under the Saudi Personal Data Protection Law, you can ask us for a copy of what we hold, ask us to correct it, ask us to delete it, ask us to restrict what we do with it, object to us relying on legitimate interests, and ask for it in a portable form.
Write to privacy@holocron.global and we will answer within one month. If your organisation is the customer and the request concerns platform content, we will pass it to them, because it is their decision to make.
If you are not satisfied you can complain to a regulator. In the United Kingdom that is the Information Commissioner's Office. In Saudi Arabia it is the Saudi Data and Artificial Intelligence Authority. In the European Economic Area it is your national authority.
10 / Cookies
This site sets none.
holocron.global uses no cookies, no analytics and no advertising or tracking scripts. There is nothing to consent to and no banner.
Nothing on this site is loaded from anyone else's servers either. The typefaces are served from holocron.global rather than called from Google, so visiting this page sends your IP address to us and to nobody else.
The platform is different, because it has to be. Signing in sets strictly necessary cookies that keep you signed in and protect the session, and connecting a Google account sets one more, for the length of that flow only, so the request cannot be forged. Those need no consent under the law and they are the only cookies we set. The platform also keeps a few preferences in your browser's own storage, such as your theme and whether the sidebar is open. Those never reach us. If we ever add anything that is not strictly necessary, we will ask you first.
11 / Security and changes
The rest of it.
How we protect information is set out on the security page, and in the data processing agreement we sign with each customer.
If we change this policy we will change the date at the top, and if the change is material we will tell customers directly rather than expecting anyone to notice.
Questions go to privacy@holocron.global.