{"api_version":"0.1","type":"privacy-policy","id":"https://aittadb.com/privacy","data":{"title":"Privacy Policy","deployment":"https://aittadb.com","controller":{"name":"Jaakko Heusala","contact_name":"Jaakko Heusala","email":"jheusala@iki.fi"},"sections":[{"id":"scope","title":"Scope and operator","paragraphs":["This policy describes personal data processed by this AittaDB deployment. The named operator decides why and how Hosted Data is processed and is responsible for this deployment's privacy practices.","AittaDB is reusable software. Other deployments and third-party applications using this service can have different operators, purposes, and privacy notices."]},{"id":"data","title":"Data we process","paragraphs":["AittaDB core collects the identity, authorization, security, and operational information needed to provide the service. Application content is stored when you or an authorized client chooses to submit it."],"items":["The email address and optional display name supplied server-side by ChatGPT Sites when you sign in, together with a separate locally generated UUID and timestamps.","OAuth clients, requested scopes, authorization and consent state, token metadata, hashed opaque credentials, and access-token revocation identifiers.","JSON records, logical keys, files, file metadata, immutable application events, and other content that you or an authorized application choose to store.","Internal account-deletion job state containing the local subject, coarse state, claim attempt, and timestamps. An eligible signed-in user can start this state through a protected account-deletion request; no job details are returned.","Redacted audit events and pseudonymous rate-limit identifiers used for security, abuse prevention, and reliability."]},{"id":"sources","title":"Where data comes from","paragraphs":["ChatGPT Sites supplies the signed-in email signal and optional name through trusted server-side identity headers. AittaDB's current adapter does not read or store a profile photo, ChatGPT credentials, conversations, Projects, Library files, connectors, subscriptions, billing, or API quota.","Stored application content comes from you or an application you authorize. Protocol, security, and timestamp data is generated when the service handles requests."]},{"id":"purposes","title":"Purposes and legal bases","paragraphs":["The operator uses this data to create and protect your local AittaDB identity; issue AittaDB sessions; perform approved OAuth and OpenID Connect operations; provide isolated records, files, and event streams; prevent abuse; investigate security and reliability problems; and meet applicable legal obligations.","Where the GDPR applies, the operator generally relies on processing necessary to provide the service you request and on legitimate interests in operating, securing, and preventing abuse of this deployment. Other legal bases can apply when required by the deployment's circumstances. OAuth approval is an authorization control and is not, by itself, a statement that consent is the data-protection legal basis."]},{"id":"sharing","title":"Recipients and authorized applications","paragraphs":["OpenAI hosts ChatGPT Sites and may process Hosted Data to host, maintain, and support this deployment under the terms and data-processing agreement applicable to the operator's account.","An authorized application receives the local subject and only claims covered by approved AittaDB scopes. Email and name are released only through the corresponding approved scopes. Records, files, and application events stay isolated to the signed-in user and the application client that owns that namespace.","The core service does not sell personal data or use advertising or analytics services. Information may also be disclosed where required or permitted by law. Third-party applications remain responsible for their own processing and privacy notices."]},{"id":"retention","title":"Retention and deletion","paragraphs":["Access tokens normally expire after 10 minutes, authorization codes after 5 minutes, device grants after 15 minutes, and refresh tokens after 30 days. These periods are deployment-configurable. Expired protocol rows become eligible for bounded, traffic-dependent cleanup and may remain until cleanup runs.","Application events carry a server-assigned expiry of 7 days by default for this deployment and become eligible for bounded cleanup afterward; eligibility is not immediate physical deletion. One-time administrator submission hashes become eligible after 15 minutes. Audit events become eligible after 90 days; account deletion clears their structured subject-derived actor attribution before removing the local identity while retaining the redacted events. One-minute rate-limit counters become eligible after five minutes. Local identities, remembered consents, client metadata, and other application content do not share one automatic expiry period.","Authorized users and applications can delete individual records and files. An eligible signed-in user can also request deletion of the current local AittaDB account after same-origin, CSRF, explicit-phrase, and short-lived account-bound confirmation checks. Administrators cannot start this operation. Acceptance blocks account access and new event writes immediately, then starts bounded deletion of owned credentials, records, application events, file metadata and objects, and the local identity. A protected status resource exposes only pending, running, retry, or completed. The completed state retains only a terminal pseudonymous idempotency tombstone with no automatic retention limit or direct public representation."]},{"id":"cookies","title":"Cookies and browser storage","paragraphs":["AittaDB sets a strictly necessary secure, HttpOnly, SameSite=Lax CSRF cookie for up to 15 minutes when browser forms need protection. After a successful administrator form submission, it may also set a secure, HttpOnly, SameSite=Strict encrypted result cookie for up to five minutes so the redirected page can show the result once without repeating the operation. A confidential or service client secret is encrypted in that cookie, never put in a URL or durable plaintext storage, and disappears after the first valid result read. Core AittaDB uses no advertising or analytics cookies and stores no authoritative state in localStorage or sessionStorage.","ChatGPT Sites and ChatGPT sign-in may use separate platform cookies governed by OpenAI's applicable terms and privacy information."]},{"id":"security","title":"Security and appropriate use","paragraphs":["AittaDB separates users and application clients, hashes bearer-equivalent opaque credentials, uses short-lived signed credentials, redacts credential-like audit data, and applies request, rate, and storage limits. No Internet service can guarantee absolute security.","Do not store payment-card data or protected health information in this service. Applications handling other sensitive personal data must establish an appropriate legal basis, safeguards, and notices before using AittaDB for that data."]},{"id":"international","title":"Hosting and international processing","paragraphs":["This deployment runs on ChatGPT Sites. Information may be processed in locations where OpenAI and any provider added by the operator operate, subject to the agreements and safeguards applicable to the deployment. AittaDB does not promise a particular hosting country or data-residency option."]},{"id":"rights","title":"Your rights","paragraphs":["Depending on applicable law, you may have rights to access, correct, erase, restrict, or object to processing; receive a portable copy; withdraw consent where consent is the legal basis; and complain to a data-protection authority. These rights can be subject to legal conditions and exceptions.","Contact the operator using the details above. The operator may need to verify your identity before acting on a request."]},{"id":"automation","title":"Automated decisions and changes","paragraphs":["AittaDB does not perform automated decision-making that produces legal or similarly significant effects. Automated security, quota, and rate-limit controls may temporarily reject requests.","The operator should review this policy whenever the deployment's data use, applications, providers, or configuration changes."]}],"references":[{"title":"ChatGPT Sites Terms","href":"https://openai.com/policies/chatgpt-sites-terms/"},{"title":"ChatGPT Sites Data Processing Addendum","href":"https://openai.com/policies/chatgpt-sites-data-processing-addendum/"},{"title":"European Commission privacy rights","href":"https://commission.europa.eu/law/law-topic/data-protection/information-individuals_en"}]},"links":[{"rel":["self"],"href":"https://aittadb.com/privacy","type":"application/vnd.aittadb+json"},{"rel":["service"],"href":"https://aittadb.com","type":"application/vnd.aittadb+json"},{"rel":["contact"],"href":"mailto:jheusala@iki.fi","title":"Contact the deployment operator"},{"rel":["terms"],"href":"https://openai.com/policies/chatgpt-sites-terms/","type":"text/html"},{"rel":["service-provider-privacy"],"href":"https://openai.com/policies/chatgpt-sites-data-processing-addendum/","type":"text/html"},{"rel":["privacy-rights"],"href":"https://commission.europa.eu/law/law-topic/data-protection/information-individuals_en","type":"text/html"},{"rel":["documentation"],"href":"https://aittadb.com/docs","type":"text/html"}],"actions":[]}