legal · privacy

privacy.

plain language, no surprises. scimap is a durable record you own — here's what we keep, what we don't, and the control you have over it.

last updated · 2026

what we store

the research record you create: your graphs, nodes, links, runs, and the metadata each run pins (config, commit, seed, metrics, outcome).

your account basics — email and display name — and a salted hash + prefix of each API key. we never store a key in plaintext and can never show it again after it's created.

bring your own keys

scimap is BYOK. model and compute provider keys you connect are encrypted at rest and used only to act on your behalf. your provider bills you directly — scimap never holds a balance and does not meter your usage.

what we don't do

we don't sell your data, and we don't train models on your private graphs.

we don't expose your secrets to client-side code — keys live in an httpOnly session and server-side vault, never in the browser bundle.

your control

you can export your graph (json / markdown) and revoke any API key at any time; revocation is immediate.

deleting a graph removes its nodes, links, and runs. ask us to delete your account and we remove your stored record.

contact

questions about your data? reach the team and we'll help.

this summary describes current practice and may be updated; material changes will be noted here.