The Membrane public site is a static, informational website. It is intentionally configured to collect as little information as practical and does not host the product's interactive demo or a production agent gateway.
1. What is configured on the site
The site code does not provide accounts, sign-in, contact forms, payment processing, or user-submitted content. It does not intentionally configure first-party analytics, tracking pixels, advertising technology, or first-party cookies.
The site does not collect production agent data, prompts, model responses, tool payloads, gateway receipts, credentials, or policy contents. Do not send sensitive information through public project links.
2. Information the hosting layer may process
When you request a page, the hosting/CDN provider may automatically process ordinary technical data needed to deliver and protect the site. This can include IP address, request time, requested URL, response status, user-agent or browser information, referring page, approximate network or regional information, and security signals. The project does not add application-level server logging to this static site.
The hosting/CDN provider may use essential cookies or similar mechanisms for security, traffic management, or abuse prevention. Those provider-controlled essentials are separate from first-party analytics or advertising cookies, which are not intentionally configured.
3. Local demo data
The interactive demo is launched by you and runs on your own machine. It uses ephemeral keys and in-memory state, and it simulates model and tool activity. Demo state is not sent to the public landing site. If you modify the software to connect external models, tools, logs, or storage, your configuration and those third parties determine how that data is processed.
4. External resources and links
The site loads font files from Google Fonts. A request to that service may expose ordinary connection information such as your IP address and user agent to Google under its own privacy terms. The site also links to GitHub for source code, documentation, and public contact. Following a link takes you to a third party that applies its own privacy policy, cookies, retention practices, and account settings.
5. How information is used
Technical request data may be processed to deliver pages, maintain availability, prevent abuse, diagnose failures, and protect the site. The project does not use the landing site to build advertising profiles or sell personal information.
6. Retention
The site has no application database or account records. Any infrastructure logs are retained according to the hosting/CDN provider's configuration and operational needs. The project does not promise a fixed retention period for provider-managed logs because that period may change with provider settings and service requirements.
7. Security
Reasonable measures are used to keep the public site limited and static, but no internet service is completely secure. Do not submit credentials, private prompts, security reports, personal data, or other sensitive material through public GitHub issues.
8. Your choices and rights
You can browse the source repository without using the landing site, block third-party font requests in your browser, and manage provider-controlled cookies through your browser settings. Depending on where you live, you may have rights concerning personal information, such as access, correction, deletion, restriction, or objection. Because the site has no accounts, include enough non-sensitive detail in a request to identify the relevant visit or record, if any.
9. Changes
This policy may be updated as the site or its data practices change. Material updates will be reflected on this page by changing the effective date.
10. Contact
For privacy questions or requests, open a GitHub issue with only non-sensitive details. If your request cannot safely be made in public, ask in the issue for a private contact method without posting the sensitive information itself.
See also the Terms of Service.