SQUAT Privacy Policy

What we collect, how we use it, and your rights.

Version v3 · Effective Prerelease version v3 - effective 9/9/2026
Prerelease version v3 - effective 9/9/2026
Pre-release. This policy will be updated prior to the official SQUAT launch.

1. Who we are and what this covers

Elucidate Ventures LLC, a Pennsylvania limited liability company doing business as Elucidate Digital ("Elucidate," "we," "us," "our"), operates SQUAT. Our address is 4569 Riverside Way, Philadelphia, PA 19127.

This policy explains what we do with personal information across the SQUAT website, accounts, hosted service, billing, support, and communications.

It does not cover the AI model providers, browser tools, identity providers, grounding sources, or other services you choose to connect. Those are governed by their own privacy policies, and their retention, logging, and training settings are under your control, not ours. Please review them before sending personal or confidential content through them.

2. The short version

  • SQUAT runs as an MCP server your own AI client connects to. We do not run the AI models — you do, on your own account and compute.
  • Your workspace content is encrypted before it is stored, with keys managed by the service.
  • We collect de-identified, aggregate usage analytics about how users use SQUAT, to help us improve the product. It is pseudonymized at the workspace level and metadata-only. It is on by default, and a workspace owner or admin can turn it off. See §6.
  • We do not sell or share personal information for cross-context behavioral advertising.
  • You can export everything, at any tier, at any time, and you can request deletion. See §9.
  • California residents have specific rights. See §10.

3. The two roles we play

As a business / independent controller. For your account, workspace administration, licensing, billing, fraud prevention, security, audit records, legal compliance, service communications, and our own product analytics, we decide why and how the information is processed. This policy governs that processing.

As a service provider / processor. For the personal information you place into Customer Content — personas, source material, interview transcripts, scenarios, missions, playbooks, registered grounding-source content, dialogue, artifacts, results, reports — you decide the purposes and means, and we process on your documented instructions. The Data Processing Addendum governs that processing where applicable.

If you put other people's personal information into SQUAT, you are responsible for the notices, permissions, consents, and lawful bases that requires, and for handling those people's requests. We will assist you — see §10.5.

4. What we collect

CategoryExamplesWhere it comes from
AccountName, email, authentication identifier, workspace, role, seat, country, account statusYou, at signup
BillingPurchase and subscription metadata, plan, entitlement, receipt records, billing addressStripe handles all charges. We never receive or store full card numbers. We retain the records needed for tax, legal, and regulatory compliance — in our own systems or at providers like Stripe.
Legal acceptanceDocument type and version, server and reported local time, timezone, IP address and device information from the accepting connection, acceptance methodRecorded when you accept the EULA, Terms, or acknowledge this policy
License and accessLicense key metadata, seat and device registrations, entitlements, client type, registered IPYour connected clients
Service activityRequests, tool names, timestamps, client, plugin version, IP address, device identifiers, security eventsAutomatically, in use
Audit recordsActing workspace license or verified user, action, target identifiers, request identifier, time, outcomeAutomatically, for key operations. Customer content is never copied into an audit row.
SupportSupport cases, correspondence, feedback, preferences, and any support-access authorization and its useYou, and the support flow
Journey analyticsDe-identified, aggregate, metadata-only progress signals — see §6Automatically, unless the workspace has opted out
Customer ContentPersonas, source material, scenarios, missions, playbooks, product context, artifacts, dialogue, transcripts, results, findings, issues, summaries, reportsYou, and your AI client

Customer Content may contain personal information about your workspace members, research participants, customers, employees, creators, public figures, or other people. We do not require you to put raw identity information into a transcript in order to process a deletion request for that person — see §10.5.

Grounding sources you register (for example a document library your agent reads on your behalf) are connected through your client, with your credentials, which we never hold. Content your agent brings from a registered source into your workspace is Customer Content, and we process it only to provide the operations you request.

Sensitive information. We do not ask for, and SQUAT is not designed to hold, government identifiers, financial account numbers, precise geolocation, biometric or genetic data, health records, or children's data. Do not place them in Customer Content.

5. Why we use it

We use information to: create and administer accounts, workspaces, roles, seats, licenses, and purchases; operate, secure, troubleshoot, and improve the Service; route the content you direct us to route to the providers you selected; store, order, protect, and return your Customer Content and Output; prevent abuse, enforce plan limits, investigate incidents, and maintain audit records; provide support when you authorize it; process payments and send transactional messages; comply with law and protect legal rights; and send marketing only where you have separately opted in.

Marketing consent is separate from transactional service messages, and you can withdraw it at any time without losing service communications.

6. Journey analytics — how we learn where the product is hard

We collect de-identified, aggregate usage analytics about how workspaces progress through SQUAT — where setup stalls, which steps get reached, where people give up — to help us improve the product. Here is exactly what that means.

It is pseudonymized at the workspace level. The analytics store is keyed by a random, opaque alias generated for each workspace. No workspace ID, workspace name, account ID, user ID, email, or any other joinable identifier ever enters that store. The alias-to-workspace mapping exists only on your own workspace record, and no reverse lookup is built. We do not collect person-level identifiers here at all.

It is metadata-only. What is recorded is: the first time each step of each journey was reached, the most recent derived progress snapshot, and four coarse dimensions — plan tier, client name (for example "Claude" or "LM Studio"), seat class, and environment. That is the complete list.

It never includes content. No prompts, no persona data, no source material, no scenario or mission text, no dialogue, no transcripts, no results, no report text, no names. The model you used is deliberately not collected — your inference runs on your own compute, we never observe it, and we chose not to record the declared model-policy strings because they are free text and could undermine the de-identification.

It is aggregate in use. We read it as funnel statistics across all participating workspaces. It is not a per-customer activity feed and is not used to make decisions about your account.

In-product suggestions are separate. SQUAT may use your own workspace's progress — data already in your workspace — to suggest a next step to you inside the product, for example at the end of a working session. That is the Service operating on your own data for you; it is not part of the aggregate analytics described here, and opting out of analytics does not affect it.

It is on by default, and you can turn it off. A workspace owner or admin can opt the entire workspace out at any time: in your AI client, ask to update the workspace with analytics opt-out enabled (the workspace_update tool's analyticsOptOut setting). The check runs before any analytics read or write, so once it is set, collection stops going forward for that workspace.

What opting out does not do. It stops future collection. Because the store is pseudonymized and aggregated with no reverse lookup, previously collected records cannot be located and removed on request — there is no key that points back to you. We consider this data de-identified, we maintain it as de-identified, and we do not attempt to re-identify it.

This is separate from any future benchmarking or cross-tenant comparison program. No such program is authorized by this policy; one would require its own explicit, revocable consent.

7. How we share information

We disclose personal information:

  • to service providers and subprocessors that host, protect, transmit, monitor, bill, or support the Service, under contracts restricting their use. Today these are Google (cloud infrastructure, database, key management, email relay via Google Workspace, and abuse prevention via reCAPTCHA) and Stripe (payments); we will update this policy when the list changes;
  • to the AI, browser, identity, grounding-source, and integration providers you connect, at your direction and only as needed for the operation you requested;
  • to authorized members of your workspace, according to their roles;
  • during a purpose-bound support operation that your workspace owner explicitly authorized (see §8);
  • when required by law, or where necessary to protect rights, safety, or security; and
  • in connection with a merger, acquisition, financing, or sale of assets, under confidentiality and with notice where required.

We do not sell personal information, and we do not share it for cross-context behavioral advertising, as those terms are defined under California law. We have not done so in the preceding twelve months.

8. Security, and what our encryption does and does not mean

The hosted service protects classified customer-content fields and hosted artifact files before they are persisted, using a per-workspace data encryption key wrapped by a cloud key-management key. Ordinary connected clients never see, hold, or need to manage that key. Access is gated by workspace, role, and capability checks, and key operations are audited.

Being precise about the boundary, because it matters: this is service-managed application encryption. It is not customer-held-key, not zero-knowledge, and not end-to-end encryption. An authorized service runtime can decrypt content in order to perform the operations you request. We say this plainly rather than implying more than the architecture delivers.

SQUAT encrypts by sensitivity, not by blanket rule, because the ledger's trend math needs some fields readable. Protected: persona profiles and briefings, source content and permission evidence, communication ranges and auditions, recruiting transcripts, scenario details, canonical dialogue, artifacts, evidence excerpts, missions and panel subjects, intent-ruling text, persona and participant names, customer labels, client type, and product build. Readable operational metadata: item IDs, creation dates, statuses, severities, scores, counts, timestamps, versions, and information on licensed users.

Support access is off by default. No standing backdoor exists. A workspace owner — not an admin — may grant temporary, purpose-bound access to named protected fields for a named support case, for 15 minutes to 7 days, chosen by the workspace owner at grant time. The grant contains no key material, is audited on creation, use, and revocation, and can be revoked at any time. Revocation stops future use; it cannot retract information already lawfully viewed during the authorized case.

No system can guarantee absolute security. If a breach affects your personal information, we will notify you as applicable law requires.

9. Retention, export, and deletion

Retention. We keep information only as long as needed for the purposes in this policy, plus what law, disputes, security, and enforcement require. Some records outlive Customer Content: audit rows, legal-acceptance records, billing and tax records, security logs, and deletion certificates. Deletion certificates deliberately contain no deleted content.

Export. You can export your workspace at any tier, at any time, using the export tooling (export_request) — a readable portable profile and a complete full-backup profile including protected history, results, reports, trash, and artifacts. License records, OAuth state, and audit rows do not export.

Deletion. You can request deletion of specific resources, of a registered data-subject resource set, or of the workspace, through the deletion-request flow. The flow prepares the request, checks legal holds and references, requires the workspace owner's authorization, then executes — removing content from active systems and object storage, after which it expires from backups within the backup retention window (currently 30 days in production).

Soft-deleted rounds and items sit in a recoverable trash for 30 days. A purge requires a confirmation phrase that is unguessable, bound to the specific operation, and expiring — designed for a person to read and relay deliberately, not for automation to complete.

Legal holds suspend deletion for the records they cover. Technically shared source records and reports that cite deleted material may affect scope and timing; we will tell you when they do.

Lifecycle distinctions

Plan downgrades do not shorten retention windows already granted to historical work, including upgrade extensions. New work receives its creation-plan entitlement. Workspace offboarding and explicit deletion are separate lifecycle actions described in Terms §10. Archived data remains retained; purged data is deleted. Deletion records contain scope, authority, checks and outcome metadata rather than the deleted payload, and distinguish active-storage completion from pending backup expiry.

10. Your privacy rights

10.1 Rights available to everyone we serve

Whoever and wherever you are, you can ask us to: give you a copy of the personal information we hold about you; correct it if it is wrong; delete it; and stop sending you marketing. Use the request channel in §10.4. We will not discriminate against you for exercising any of these rights — no denial of service, no different price, no degraded quality.

10.2 California residents — CCPA / CPRA

If you are a California resident, you have the rights below. We honor these rights for all California residents who ask, and we have chosen to operate this way regardless of whether we currently meet the statute's applicability thresholds.

Right to know. You can ask us to disclose: the categories of personal information we collected about you; the categories of sources; the business or commercial purpose for collecting it; the categories of third parties to whom we disclosed it; and the specific pieces of personal information we hold. §§4, 5, and 7 of this policy give the standing answer; a request gets you your own records.

Right to delete. You can ask us to delete the personal information we collected from you. We will delete it, and direct our service providers to delete it, unless an exemption applies.

Right to correct. You can ask us to correct inaccurate personal information.

Right to portability. You can ask for your personal information in a portable, readily usable format. Our export tooling produces this for your workspace content; we provide any remaining account records in a readable format in response to your request.

Right to opt out of sale or sharing. We do not sell personal information and we do not share it for cross-context behavioral advertising, so there is nothing to opt out of. We will update this policy and provide a "Do Not Sell or Share My Personal Information" link if that ever changes.

Right to limit use of sensitive personal information. We do not collect sensitive personal information for purposes that trigger this right.

Right to non-discrimination. Exercising any of these rights costs you nothing and changes nothing about your service.

Authorized agents. You may use an authorized agent, who must provide written permission signed by you; we may also ask you to verify your own identity directly.

10.3 How we handle a request — the process

  1. You submit through the channel in §10.4.
  2. We acknowledge within 10 business days, confirming we received it and describing how we will process it.
  3. We verify it is really you, using a standard proportionate to the sensitivity of what you asked for: for a deletion or a specific-pieces disclosure, we match at least two or three data points against our records (for example, the account email plus a signed-in session or a workspace identifier) and, where reasonable, confirm through the email address on the account. We will not ask for more identity documentation than the request warrants, and we will not create an account for you just to verify you. If we cannot verify you, we will tell you why.
  4. We respond within 45 calendar days of receiving the request. If we need more time, we will tell you within that 45 days and take up to 45 more days — 90 days total at the outside.
  5. We distinguish our own information from sealed customer content. For personal information SQUAT holds in its business role, we evaluate and respond through the applicable privacy process. For sealed content controlled by a customer, we explain our service-provider role and provide the appropriate approved customer privacy contact when available; see §10.5. A referral does not execute deletion and is not reported as completed deletion. Internal owner-authorized workspace deletion is a separate operation.
  6. If we deny the request, in whole or in part, we tell you which exemption applies — for example a legal hold, a retention obligation, security and fraud-prevention records, or the fact that removing something would break another person's rights.
  7. Every request creates a support case — recording what was asked, when, how we verified it was you, what we did, and when we closed it. We keep those records for at least 24 months, and longer where a law that applies to us requires.

10.4 How to make a request

Submit your request through the support form at squat.pro/support, choosing the Data & privacy area. Tell us what you want (know / delete / correct / portability), and the email address associated with your account or the workspace involved. If you are acting for someone else, say so and include your authorization. The form is the channel we log and track.

10.5 If your data is in someone else's workspace

If a SQUAT customer placed information about you into their workspace — for example, you were interviewed and a persona was built from your transcript — that customer controls it, and you should contact them. They decide the purposes; we process on their instructions.

If you contact us instead, we explain that the request concerns content held for a customer and provide that customer's approved privacy contact where we can safely identify it. We do not inspect, unseal, search or delete sealed workspace content merely because a consumer submits a request to us. If the appropriate contact cannot be identified or safely provided, a privacy operator reviews the routing; we do not guess or disclose private workspace membership or account details.

This referral path does not remove our separate duties for information we hold in our business role, or our obligations under applicable law and our customer contracts. Authorized customer instructions and internal lifecycle operations are separate from a direct consumer referral. We record the actual routing or response, not a deletion we did not perform.

Source withdrawal, persona/project retirement, archival preservation and deletion are distinct operations. Withdrawal or retirement restricts future use while preserving historical records under their retention entitlement; a purge destroys the authorized content. Archive preserves data outside normal active operations, including where a retention requirement or hold applies.

10.6 Other U.S. states

Residents of other states with comprehensive privacy laws — including Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, and others — have comparable rights of access, correction, deletion, portability, and opt-out. We extend the same process in §10.3 to those requests, with the response deadline each state requires.

10.7 If you disagree with our decision

Reply to our response and ask us to reconsider; we will review it. California residents may also complain to the California Privacy Protection Agency or the California Attorney General.

11. Where information is processed, and our GDPR posture

We operate in the United States, and information is processed primarily there, including by our cloud providers and by the AI providers you connect. SQUAT is offered to United States customers.

Being direct about the EU: SQUAT is not currently offered to, marketed to, or targeted at people in the European Economic Area, the United Kingdom, or Switzerland. We do not have an EU establishment, and our catalog is denominated in U.S. dollars. We rely on the location you self-declare — the country you give at signup. Billing records (such as those created by a card payment) are kept separate from operating records. On that basis we do not consider the GDPR to apply to our own processing today, and we have not appointed an EU representative, adopted Standard Contractual Clauses, or completed a transfer impact assessment.

If our footprint changes — an EU establishment, EU-targeted marketing, or EU customers we accept knowingly — the GDPR analysis changes with it, and we will put the required mechanisms in place and update this policy before that happens. If you are in the EEA/UK today, please note that our practices are designed against U.S. law, and a customer who brings EU personal data into a workspace does so as controller under its own compliance obligations.

12. Children

The Service is for business use by adults. It is not directed to children, and we do not knowingly collect personal information from anyone under 18. If we learn we have, we will delete it. Do not place children's data into Customer Content.

13. Changes to this policy

If we make material changes, we will change the version, post the new policy at its published address, and — where the change is material to your rights — ask you to acknowledge the new version before continuing. Acceptance records are append-only and record exactly which version you saw.

14. Contact us

Elucidate Ventures LLC (d/b/a Elucidate Digital) Privacy requests: the support form at squat.pro/support (Data & privacy area) Mailing address: Elucidate Ventures LLC, 4569 Riverside Way, Philadelphia, PA 19127

Last updated September 9, 2026