Privacy
Causality stores very little, and most of it only if you make an account. Asking a question, building a model and exploring it all work signed out. One thing is written down even then, and it is the first entry below.
Who is responsible
Causality is a study project, and the name and address below are stand-ins rather than a real person. The Imprint says the same. Everything else here describes what the application actually does, and all of it is checkable against the code this app is built from — with one exception, which is the contractual terms those providers offer, because a contract is not something code can show you.
Max Mustermann, Musterstraße 1, 12345 Musterstadt, Deutschland, is the controller for the data described here. For anything on this page — a copy of your data, a correction, deletion, or an objection — write to max.mustermann@example.com. You will get an answer within a month, which is the period the GDPR allows.
You can also complain to a data protection supervisory authority, in the EU country where you live or work, without going through me first.
Without an account
- Your question
- Sent to the AI provider to be interpreted and modelled. Held in your browser for the length of the visit and never written to the database. Closing the tab ends it — and the next entry says where in the browser it sits.
Basis: your request — this is the thing you asked the app to do. - The model you built, in this tab
- Your question, the scenario you confirmed and the model that came back are kept in this browser tab’s own storage, so that reloading the page does not throw away a model that took an AI call to build. It never leaves your browser: it is not sent anywhere, not written to the database, and not readable by another site or by another tab. Closing the tab deletes it, and starting over deletes it at once.
Basis: strictly necessary to provide what you asked for. It holds the thing you asked the app to make and nothing that identifies you, which is why you have not been asked to accept it. - A counter
- To stop one visitor exhausting the shared budget, requests are counted per client. Your IP address is not stored. What is stored is a hash of it, combined with a secret that is kept out of the database — so the value in the table cannot be turned back into an address by anyone who obtains the table. It is not fully anonymous data, and this page does not claim it is: it is your address with the link to you cut. Counters older than a day are deleted.
Basis: legitimate interest in not having the service exhausted or billed out by one client. - A session cookie
- Only once you start signing in, and only to complete and keep your sign-in. It holds your sign-in session, including what the authentication service knows about your account, and is sent only to this app. There are no analytics cookies, no advertising identifiers and no third-party trackers anywhere in this app, which is why you have never been asked to accept any.
Basis: strictly necessary to provide what you asked for.
With an account
- Your email address
- The only thing an account requires. It is how a sign-in link or a confirmation email reaches you, and what you sign in with.
- Sign-in records
- The authentication service keeps its own record of when the account was created and when it was last used, which can include the address you signed in from. That is part of how it detects abuse of sign-in, and it keeps these records under its own retention, which deleting your account here does not shorten.
Basis: legitimate interest in keeping accounts safe from abuse. - How you sign in
- With an emailed link, with a password, or with your Google account. A password is stored only by the authentication service, as a one-way hash; nobody, including us, can read it back. If you choose Google, Google confirms who you are and passes the authentication service your email address, your name, your profile picture and a Google account identifier. The service keeps these with your account, and they are part of your sign-in session; this app uses only the email address and never shows the name or picture. Google never sees a password for this app, and it learns nothing about your scenarios. Deleting your account here does not remove this app from your Google account; you can do that under the third-party connections in your Google account settings.
- Scenarios you save
- Only the ones you press Save on. Each is stored with the model it produced and the date. They are readable by you and by nobody else — the database itself enforces that, not just the app — unless you switch on sharing for one. Then anyone with its link can read that one scenario: the question you asked and the model it produced, never your email address. Switching sharing off ends the link at once, and deleting the scenario or your account removes it.
Basis for all of these: performing what an account is for. Without them there is no way to sign you in or give you your scenarios back.
All of it is kept until you delete it. There is no expiry and no analytics, and nothing is sold or shared, apart from a scenario you choose to share by link. If you stop using the account it will sit there, which is an honest description rather than a good policy: there is currently no automatic clear-out of dormant accounts.
Who else sees it
Five, named rather than counted. The AI and search services never learn who you are: nothing identifying is sent with your question. The host and the database do handle your identity, because that is what they are for — Vercel sees the address every request comes from, and Supabase keeps a saved scenario under your account.
- Vercel
- Hosts the application and keeps ordinary server logs of requests to it, for the period its plan sets (days, not months).
- Supabase
- The database and the sign-in service. Its email provider sends the sign-in link, so it handles your address.
- OpenRouter
- Routes each request to a model. It sees the text of your scenario in transit.
- Makes the Gemini models that read your scenario, grade the sources and build the model. It receives the text of your scenario through OpenRouter. Separately, if you sign in with Google, Google handles that sign-in under its own privacy policy and knows that you signed in to this app. It learns nothing about your scenarios.
- Parallel
- The web search service, reached through OpenRouter. It receives search terms derived from your scenario when the app looks for evidence.
All of them are in the United States, and the application itself runs in a US region, so your data leaves the EU. Transfers rest on the standard contractual clauses and equivalent terms each of those providers offers.
Your rights
You can ask for a copy of your data, have it corrected, have it deleted, take it elsewhere, restrict what is done with it, or object to it. Two of those are buttons; the rest are an email to the address above.
- A copy, to keep or move
- Download everything on your account page. It is a single file containing your address, everything the authentication service keeps with it (for a Google sign-in, all that Google passed on, such as the name, picture and Google account identifier), every scenario you saved, its date and whether it is shared, in a format another program can read.
- Deleting everything
- The same page has a control that removes your account and every scenario saved under it. It takes two presses and it is immediate. Nothing of yours is kept by this app, there is no grace period and there is no copy — so it cannot be undone, and you are told so before you press it. Two records outside the app follow their own retention: the authentication service’s sign-in log and the host’s request logs. To remove one scenario without closing the account, use Remove on the saved scenarios list.
- Everything else
- Correction, restriction and objection: write to max.mustermann@example.com.
Nothing here makes an automated decision about you. The app models a hypothetical about the world; it does not score, rank or judge the person asking.
What the AI does with it
How models are generated, what the evidence grades mean and what this app will not claim are covered under AI & evidence.