Lacey · experimental AI

Privacy

Effective: August 6, 2026.

Plain-language notice. Not formal legal advice.

1. What we may store (cloud site)

  • Account details: name, email, and a hashed password (never plaintext), plus age + terms acceptance and a session cookie.
  • Messages you send and Lacey’s replies (chat logs for safety and debugging; secret material is refused and not studied).
  • Technical data such as approximate time, IP, and basic request info on the public server.
  • Optional images attached via Paperclip (beta).
  • Generated downloads temporarily under the server download folder when you ask for code files.
  • Optional PC device labels if you register a Windows Lacey install in Settings → Security (device id + label only — not your Windows password).

2. Lacey for Windows (local PC edition)

Signed-in users may download Lacey for Windows from Settings → Security. That build runs on your PC (not remote control from the cloud). Cloud chat still cannot control anyone’s computer.

  • On your machine: setup may write Start Menu/Desktop shortcuts, and an access.json that stores access mode (folder or full) and the allowed root path (default folder sandbox: %USERPROFILE%\LaceyWorkspace).
  • Confirms: dangerous actions (delete/overwrite, shutdown, lock, etc.) ask before running. Quitting Lacey from chat confirms, then exits.
  • Full PC mode requires typing ALLOW FULL during setup. Folder mode rejects paths outside the chosen root.
  • Not in the download: admin keys, website passwords, account databases, or SSH keys.
  • Uninstall / revoke: delete the install folder and shortcuts; remove access.json; revoke a listed device in Settings → Security; delete your website account anytime.

3. Where data lives

Cloud Lacey runs on a Hetzner VPS. Account signup data stays in the join gate (separate from chat). Lacey cannot read passwords, the account database, SSH keys, or admin keys. Local PC Lacey keeps chat/access data on your Windows machine under the install and workspace folders you chose.

4. What Lacey cannot see

Passwords, other users’ accounts, SSH/API/admin keys, and similar secrets are blocked from chat and never taught into Lacey’s shared memory.

5. What we don’t sell

We don’t sell your chats. Logs are for running Lacey, fixing bugs, and keeping the service safe.

6. Cookies

An HttpOnly Secure session cookie keeps you signed in after signup/sign-in. The PC zip download requires that signed-in session (guests get 401). No ad trackers.

7. Your choices

Don’t paste secrets into chat. Open Settings to download Lacey for Windows, manage devices, or delete your account by typing delete.

8. Third parties

Hosting (Hetzner), DNS, fonts CDN, or optional web/wiki fetches may process technical data under their policies when those features run.

9. Children

Lacey isn’t directed at children under 13. Contact the operator if you believe a child used the service.

← Back to Lacey · Terms