Privacy

What this site and the product actually collect, where it is processed, and how things get removed. Written from the running system, not from a template.

Visiting this site

athren.nl is served by Vercel. It sets no cookies and loads no analytics or advertising scripts, and the fonts are served from our own origin, so reading it tells no third party you were here. The hosting infrastructure keeps standard access logs, as any host does.

Booking a call

The booking form is the one thing on this site that receives anything. What you enter, your name, your email address, a company if you give one, what you describe and the time you pick, becomes a single email to us, delivered through Resend and answered by a person. It is not written to a database, and your address is used to reply to you and for nothing else.

Using the product

The product is invite only. What it processes is decided by what your workspace connects, and each mechanism below is the one the software enforces.

Your account
Sign in is handled by Supabase: an email address and password, or Google or GitHub sign in. Identity lives on a Supabase project in the European Union.
What it holds
What your workspace connects is mirrored: documents, messages and records from each source, read with the scopes shown on that provider’s consent screen, plus the search index and embeddings built from them and the record of every run.
What leaves
Answering a question sends the question and the retrieved evidence to the chat model provider, the OpenAI API today. Text is embedded on Scaleway’s managed endpoint in Paris. Every model call goes through one owned egress module and leaves a span on the ledger, so what left is on the record.
What it writes
Nothing, until a person allows it. A connection starts with no write grant, a write under an ask grant is proposed in full and executes only once a person approves it, and a standing grant is itself a recorded decision. Every executed write leaves a hash-linked entry in the audit chain.
Where it runs
The product database sits beside identity on the same EU Supabase project, the API runs on a Scaleway instance in Paris, and both this site and the app are served by Vercel.

Removal

Deletions follow the source: a document removed where it lives is tombstoned on the next reconcile and stops being surfaced. Erasure on request is recorded as it happens. Each erasure appends its own entry to the same audit chain governed writes use, naming what was held and what was removed as counts and identifiers, never as content, and an erasure that cannot record itself does not happen. Disconnecting a source means its grant is revoked and reads stop; today that is an action we take for you when you ask.

What this page does not say yet

Some of the formal facts a privacy policy normally carries are still being settled with counsel: the legal entity behind the working name and its registered address, exact retention periods, the formal list of subprocessors, and the legal bases for each processing purpose. Until they are settled they are not stated here, because a fact this page invents is worse than a gap it admits.

Questions, access requests and erasure requests go to lucas@athren.nl.