Privacy Policy
Last updated: 2026-09-29
1. Introduction
Cassius is a spatial AI workspace, currently in private beta. This policy explains what information we collect, how we use it, where it is stored, and who else handles it. It describes what the product does today, and it changes when the product does.
It covers cassius.chat and the Cassius application. If anything here is unclear, write to support@cassius.chat.
2. Information We Collect
Account Information
When you create an account we collect your email address and an account identifier, and from your first sign-in we hold a record of each active session. You may give us a name to show in your sidebar; it is optional, you can clear it at any time, and if you do not give one we show the first part of your email address instead. We do not ask for a phone number, a company, a postal address or a payment method, and the product has no field in which to give us one.
If you joined the waitlist before you had an account, we also hold the address you gave us and the date you gave it.
When you send us a report from the feedback form, we store it with your account.
Your Workspace
When you are signed in we store the arrangement of your workspaces: their names, the order you keep them in, which ones you have pinned, which one you were last looking at, and where each pane sits on the floor. That is what comes back when you sign in again, on any device. It is held in our database, hosted by Neon, and it is attached to your account and to nobody else’s.
Your Conversations And Notes
When you are signed in we also store what is inside those panes: your conversations (the messages you send and the replies the model gives, along with each conversation’s title and which model you chose) and the text of the notes you write. They are held in the same database, attached to your account and to nobody else’s, and they are what comes back when you reload or sign in on another device.
We keep them for as long as your account exists. When you delete a conversation or a note we mark it deleted immediately and stop serving it; the rows themselves are removed automatically, every day, once they are more than thirty days old. Deleting a workspace does not delete the conversations you were reading in it. A conversation belongs to you rather than to a workspace, and the same conversation can be open in several, so the workspace goes and the conversations stay. Deleting your whole account removes everything tied to it, and it is not marked or queued: see section 6.
The files you open are still held in your browser only. If you open a file’s eye, or attach a file to a message, its contents are sent to the model you chose, through the provider named in section 5, as part of that message; we do not store the file, and it is not sent otherwise.
When you are signed out we store nothing at all. Not the arrangement, not the contents: everything lives in the tab and ends with it. That is deliberate, and it is a feature rather than a gap: you can use Cassius without an account and leave nothing behind.
What you send to a model is transmitted to that model so it can answer you; we do not log it, we do not retain it, and we do not train anything on it. Section 5 names the provider that carries it.
Your Plan
If we give your account a plan without charge, we store which plan it is, that we gave it rather than you buying it, and when it began. It is attached to your account and to nobody else’s, and it is removed with your account. It decides which models you can use and how large your usage allowance is.
Usage Records
When you are signed in, every request we make to a model for you is recorded as a usage record. That includes replies you stopped or that failed, and the short requests that name a new workspace for you. A usage record holds when the request was made, whether it was for a reply or to name a workspace, which plan you were on and whether the request counted against your usage allowance, which model and which of its providers handled it, how many tokens it used, what it cost us and the most it could cost, whether it ran on our own account with that provider and, if so, what the provider billed us directly, how it ended, and the provider’s identifier for that request. It holds no message text and no identifier of the conversation, workspace or message it came from. Deleting a conversation does not remove its usage records; they are removed on the schedule in section 6.
Sign-in Records
When you sign in, we store one record of that session on our servers: a random session identifier, a reference to your account, and the times the session was created and last used. We do not store your device name, your browser’s user-agent string, or your location alongside it.
This record is what lets a session be ended. When you sign out, we delete it. When you reset your password, we delete every one of them, on every device, which is what makes a password reset actually lock out anyone who had access. When your account is deleted, they go with it.
Voice
Voice input uses the speech recognition built into your browser. Depending on your browser and its settings, the browser may send your audio to its maker’s speech service, such as Google for Chrome, Apple for Safari or Microsoft for Edge, or it may recognize speech on your device. Your audio never reaches our servers, and we do not store it. Only the words that land in the message box are yours to send.
Replies read aloud are spoken by your browser’s own voice. Depending on your browser and the voice it uses, the words may be spoken on your device or sent to your browser maker’s speech service. Nothing about a reply is sent to our servers to read it aloud.
Technical Information
A cookie is a small piece of data a site asks your browser to keep and hand back on later requests. Cassius uses cookies for four things, and every one of them is necessary to operate the service: remembering that you entered the beta code, keeping you signed in, showing who is signed in before a page has finished loading, and carrying a sign-in that is halfway through. Five cookies do that work and all five are ours: three are kept 30 days, and two are kept 10 minutes. We set no analytics, advertising or tracking cookie of any kind, we run no analytics, trackers, advertising pixels or session recording, and none of them lets a third party access any of your information.
3. How We Use Information
We use what is described above only to provide and secure the service: to create your account, to sign you in and keep you signed in, to deliver your requests to the model you chose, to show you how much of your usage allowance you have used, to check what our model provider bills us against what we recorded, to work out what the service costs to run, and to protect the service from abuse.
We do not sell your information. We do not share it for advertising. We do not use your content to train models, and we train none.
4. Google User Data
This section describes what we do with data obtained from your Google Account when you choose to sign in with Google. It applies in addition to the rest of this policy, and our use of that data adheres to the Google API Services User Data Policy, including its Limited Use requirements.
What We Access
Your email address, whether Google has verified it, and an opaque account identifier issued by our authentication provider. We do not receive your name, your profile picture, your contacts, your calendar, your files, or anything else in your Google Account.
How We Use It
For one purpose: creating your Cassius account and signing you in. We use it for nothing else.
Where We Store It
Your identity and your sign-in tokens are held by our authentication provider, WorkOS. Your email address, your account identifier, your sign-in records and your workspace arrangement are held in our database, hosted by Neon. We never receive or store your Google password.
What We Share
Nothing beyond the processors named in section 5, each of which handles it only to operate the service on our behalf. We never sell Google user data, never transfer it to anyone for advertising, and never use it for advertising ourselves.
How To Have It Deleted
Delete your account from inside Cassius: open the command palette and choose “delete your account”. You will be asked to type your email address to confirm. Section 6 says exactly what is removed. You can also email support@cassius.chat from the address on your account and we will do it for you.
5. Service Providers
We use four service providers, and this is the complete list. Each processes data only to operate the service on our behalf.
- WorkOS
- Authentication. Holds your identity, your password if you set one, and sends the mail our sign-up and password-reset flows produce.
- Neon
- Our database. Holds your email address, account identifier and usage records.
- Vercel
- Hosting. Every request to Cassius arrives through Vercel.
- OpenRouter
- Model routing. Carries what you send to a model, and the model’s reply back.
What a model’s own provider does with what you send it is governed by that provider’s policy and not by this one.
Your browser’s speech recognition service, if it uses one for voice input, is your browser maker’s and not ours, and is governed by your browser maker’s policy.
6. Data Retention
We keep your account information for as long as your account exists. When you delete your account we remove it and everything attached to it: your workspaces, your conversations and every message in them, your notes, your usage records, your plan if we gave you one, the reports you sent us from the feedback form, every signed-in session, your waitlist entry if you have one, and your identity at WorkOS. That happens while you wait, not on a schedule, and it is not a mark: the rows are gone. Anything Cassius had put in your browser is cleared from it at the same moment, and every other tab you had open is signed out. There is no undo. A waitlist address you never turned into an account is held until the beta ends or until you ask us to remove it.
Our database provider keeps a restorable history of the database for up to seven days, so a removed row can remain there for up to seven days before it is gone for good.
Your workspace arrangement, your conversations and your notes are kept for as long as your account exists. When you delete a workspace, a conversation or a note we mark it deleted immediately and stop serving it; we remove it from the database automatically, every day, once it is more than thirty days old. The window is a safety net for a deletion you did not mean, not a feature, and nothing in the product offers to bring a deleted item back. Files you open are retained by us for no time at all, because we never receive them; a file you send to a model is carried to it and not kept.
Usage records are removed automatically, every day, once they are more than thirty-five days old. We also keep daily totals for each model, split by kind of request (a reply or naming a workspace), by plan and by whether it ran on our own account with the provider: what was spent on it, how many requests it served, how many tokens it used and how many characters of prompt text were sent to it on a given day. They hold no account identifier, and they are kept after an account is deleted.
A sign-in record lasts until you sign out, until the session’s own thirty-day lifetime ends, or until a password reset or account deletion removes it, whichever comes first. Cookies expire on the schedule in section 2.
7. Security
Every request to Cassius is served over an encrypted connection, and our responses instruct browsers never to use an unencrypted one. Your session cookie is encrypted and authenticated before it is set, so neither a script in your browser nor a party in transit can read or alter it. We never receive or hold a plaintext password: passwords are handled by WorkOS, which stores them hashed.
No system is perfectly secure and we do not claim otherwise. Cassius is beta software and should be treated as such.
8. Your Rights
You can delete your account yourself, at any time, from the command palette inside Cassius. To ask for a copy of the information we hold about you, or to ask us to correct it, email support@cassius.chat from the address on your account and we will act on the request.
Depending on where you live you may have further rights under local law. Write to us and we will honour them.
9. Children’s Privacy
Cassius is not directed at children under 13, and we do not knowingly collect information from them. If you believe a child has given us information, write to us and we will delete it.
10. Changes To This Policy
When our practices change we change this page and update the date under its title. This page is the notice; there is no other version of this document.
11. Contact Us
Email support@cassius.chat.