Legal
Privacy
Short, because the architecture does most of the privacy work. Last updated October 2, 2026.
Who we are
Laughing Hermit, Inc., a Delaware corporation, operates librocat Cloud and is the controller of the personal data described here. Contact: support@librocat.dev. This page covers librocat Cloud and the librocat.dev site. A librocat you self-host sends us nothing.
What we collect
Your account: your email address, a password stored only as a hash, and a display name taken from your email address. Each sign-in session records the IP address and browser it came from, to keep accounts secure. Your library: the concepts you and your agents write; the sources you keep (files you attach, and the text of documents, pages, and transcripts your agents read, so they can quote them later); the index built from them (search text, and one embedding per concept and per part of a source); a revision for every write; the review shelf's proposals; and the agents you approved. The ready-reference file: the questions your agents ask the library (search queries), what they found, and which concept answered, so a question asked again gets its answer first and Libro can report what found no answer. A query that looks like it carries a secret is never kept. Usage: counters (concepts, index credits, searches) to enforce your plan, and counts of sign-ups, connected agents, and activity, which we read only in aggregate. Payment: when you buy a plan, Link and Stripe collect your name, billing address, and payment details; we receive the plan and its billing status, never card numbers. Support: the emails you send us.
How we use it, and why
To provide Cloud under our agreement with you: to store, index, and serve your library, sign you in, bill your plan, and send the emails the service needs. To keep Cloud secure and working, which is our legitimate interest: rate limits, abuse prevention, fixing problems, and aggregate counts of how it is used. To send Libro's report (weekly on paid plans, monthly on Free) unless you turn it off. And where the law requires it. We do not sell your data, share it for advertising, or train models on it.
The models that read it
librocat's own models write nothing: your agent does the writing. When your agent leaves a concept's description or tags blank, the concept (title, type, body) and your library's tag names go to Jev, a small judgment model from TypeSafe, which picks a sentence and tags from them; only its picks are stored. After Libro's weekly review, Jev reads the titles, descriptions, tags, and the start of the body of up to 20 pairs of concepts that may say the same thing, of up to 20 concepts written or changed since the last review (to suggest review dates), and of the concepts behind up to 10 questions that found no answer. When your agent drafts a merge, Jev checks it against the two concepts it merges. Gemini Embedding 2, from Google, embeds each search's text, each concept's title, description, and the start of its body, and each kept source (attached files included), so agents find them by meaning and Libro finds duplicates. One vector per distinct question, concept, and part of a source is kept, and each is deleted with what it came from. These requests go through Vercel's AI Gateway, only to providers that do not train on them. Google serves Gemini Embedding 2 through its AI Studio: every request forbids training on it, but Google keeps requests for a limited time to detect abuse, and may process them outside the United States. On paid plans, librocat fetches a public web page itself only when you save a link to the reading list, and about once a week for the saved pages your concepts cite, to see whether they changed.
Who processes it
Vercel hosts the site and the MCP endpoint, counts visits to the public pages, and routes model requests through its AI Gateway. Convex stores the database and files, on Amazon Web Services, and runs the backend. Resend sends sign-in codes, Libro's report, and service emails. Stripe and Link handle payment; for purchases, Link is the merchant of record and processes your payment details as a controller, under Stripe's privacy policy. TypeSafe runs Jev. Google runs Gemini Embedding 2, and hosts our support mailbox in Google Workspace. No one else receives your data, unless the law requires it, or as part of a sale or merger of the service, which we would tell you about first.
Where it is processed
librocat is run from the United States, and your data is stored and processed there, wherever you use librocat from. Google may process embedding requests outside the United States, as described above.
How long we keep it
Your account and your libraries: until you delete them. Questions in the ready-reference file: 90 days. Sign-in sessions: until they expire or you sign out. Server logs: kept by our providers for a short time, at most 30 days, to run and secure the service. Delete index erases every concept, link, revision, question, and kept source at once. Delete this library, in Settings, removes a library. Delete account, in Billing, cancels any subscription and erases your account and every library you own. If we close an account, we erase its data within 30 days. Deleted data leaves our backups within 30 days. Payment records are kept as long as tax law requires.
Cookies
Essential cookies keep you signed in to the dashboard and secure the sign-in and agent-approval steps, and one more remembers whether the dashboard's sidebar is open. There are no analytics or advertising cookies. The pages you can open without signing in count visits with Vercel Web Analytics, which sets no cookie: it records the page's path (never its query), the site you came from, your country, and your device and browser type, and tells visitors apart by a hash of the request that is discarded after 24 hours. Nothing behind sign-in is counted: not the dashboard, not the screen where you approve an agent, not team invites.
Emails
We send sign-in and verification codes, notices about your account, your plan, and these policies, and, unless you turn it off, Libro's report. Every report has a link that stops it. Receipts and invoices come from Link. We do not send marketing email without your consent.
Your rights
You can see, export, and delete your data yourself: Export index downloads your whole library as an OKF zip, with your kept sources beside it, that `librocat push` copies into another librocat, Cloud or self-hosted; the delete buttons described above erase it. You can also ask us at support@librocat.dev to access, correct, delete, or move your personal data, to restrict or object to how we use it, or to withdraw a consent you gave. We answer within 30 days. Depending on where you live (for example the EU, the UK, or California), the law gives you these rights, and you can also complain to your data protection authority.
Children
librocat is not for children. We do not knowingly collect data from anyone under 16. If you believe a child gave us data, write to support@librocat.dev and we will delete it.
Security
The security page says what runs where, who can see your data, and how to report a problem.
Self-hosted librocat
librocat you self-host with Docker runs on your own server and sends us nothing. Your knowledge, and the models you choose for it, stay under your control. We never see it.
Changes
When this policy changes, the date at the top changes too. We email you about material changes at least 30 days before they apply.
Contact
Laughing Hermit, Inc., support@librocat.dev.