Privacy
What we store, and what we never see
Most privacy policies are written to be defensible. This one is written to be checked, so it says where each piece of data physically goes. Driades is self-hostable and its data layers are read in place, which means a lot of what a policy usually has to cover simply never happens here.
Last updated 15 August 2026.
The short version
- What you draw on a canvas goes straight to the other people in the room. It does not pass through a server that keeps it.
- No cookies for tracking, no third-party analytics, no advertising network, no profiles sold to anyone.
- The only personal data we hold is what you typed into a form, or what an account needs to exist.
- You can ask for all of it back, or deleted, and we will do it.
The canvas
A room is peer to peer. The editing happens over WebRTC directly between the browsers in it, and the only thing our server does is introduce the peers to each other so they can open that connection. It keeps a list of who is in which room while the room is live, in memory, and forgets it when the last person leaves.
So the drawings, the notes, the measurements and the layer list are not stored by us and cannot be read by us. The practical consequence is worth knowing in both directions: it is private, and it also means we cannot recover a room you lost. If it matters, export it.
Your data layers
When you add a dataset, your browser reads it from wherever it already lives, using range requests to pull only the parts on screen. It is not uploaded to us and we never hold a copy. That does mean your browser talks to that host directly, so their logs will show a request from your address the same way any other web request would. The catalogue on the datasets page lists who each host is.
A file you drag in from your own machine is read in the browser and stays there.
Accounts
If you have an account we store your email address, a display name if you set one, when it was created, and when you last signed in. Passwords are stored as a scrypt hash, never as text, so nobody here can read yours. Signing in sets one cookie holding a random session token, which exists to keep you signed in and does nothing else.
You can also sign in through Keycloak, which we run ourselves on this same machine. It is the part that checks who you are, so it holds your address, your password hash and its own record of your sessions. It is not a third party and nothing about you is sent anywhere to make it work. Signing in that way still ends in the same cookie, and what we keep about you afterwards is the same short list as above.
We do not store card numbers. If and when payment happens it goes through a payment provider who handles the card, and we keep only the fact that a subscription exists.
If you connect an AI provider key, it is not stored by this service.
Forms
The waitlist, the sponsorship enquiry and the tree submission form all keep what you wrote: your name, your email, the subject and the message. Alongside it we store a shortened version of your IP address, cut to the first three groups for IPv4 or the first four for IPv6, which is enough to stop somebody flooding the form and not enough to identify you.
These go to a private inbox that only an operator can open. They are never published, and they are deliberately kept out of the public catalogue that the API and the MCP endpoint read from.
Cookies, and why there is no banner
Three cookies exist here and you will not be asked about any of them, which is not an oversight. A banner is required for cookies that are not necessary to provide the thing you asked for. Ours are:
- a session cookie, holding a random token, which is what keeps you signed in;
- a CSRF cookie, which exists so that another site cannot act as you;
- a short-lived login cookie, ten minutes, while you are being sent to the sign-in screen and back.
All three are strictly necessary in the sense the law means it: remove them and signing in stops working. None of them follow you, profile you, or say anything about you to anybody. Under article 22.2 of the Spanish LSSI, and the equivalent elsewhere in Europe, that kind is exempt from consent.
One thing that is not a cookie but is worth naming anyway, because a page
listing what is kept about you is wrong the moment it leaves something out:
your language choice is remembered in localStorage, under
driades_lang. It holds two letters. It exists so that choosing
English once is not undone by your browser announcing it prefers Spanish on
every visit, and it never leaves your device. Clearing your site data
forgets it, and the language is guessed from your browser again.
The usual reason a site needs a banner is analytics, and ours does not use cookies at all. So there is genuinely nothing to consent to. If that ever changes you will get a real choice rather than a wall of buttons weighted towards yes.
Analytics
We count visits with Plausible, which we run ourselves on our own machine. It sets no cookies, collects nothing personal, and cannot follow you to another site. Nothing is shared with a third party because there is no third party involved.
Inside the canvas we use its manual mode instead of the standard script, because a room URL contains the room id and the name someone chose. Sending that to analytics would leak the contents of a private room into a statistics page, so we send a fixed page name instead.
The MCP endpoint
Anything an assistant reads through driades.app/mcp is already
public on this site: the dataset catalogue, the trees, the documentation. It
needs no key because it exposes nothing that needs one, and every tool on it is
read-only.
Requests reach it through our web server, which keeps ordinary access logs containing the address, the time and the path, the same as for any page here. Your conversation with the assistant is not sent to us, and we do not keep the questions asked through it beyond those logs.
Who else is involved
The site is served through Cloudflare, which sees requests in transit as part of doing that. The servers are ours. There is no analytics vendor, no session recorder, no chat widget, no advertising and no data broker, and we are not planning to add any: sponsorship exists on this project so that surveillance does not have to.
Asking for your data
Write to [email protected] and ask for a copy of what we hold, a correction, or deletion. We will do it, and we will not ask why. If you are in the EU or the UK these are rights you already have under the GDPR, and this paragraph does not add conditions to them.
Form submissions are kept until they are dealt with and then cleared out. Account data lives as long as the account does.
Changes
If this changes we will change the date at the top. If it changes in a way that affects what we collect, we will say so on the updates page rather than quietly editing this one.
Driades is a h4ck1ng.science project, led by Carlos Vivar Rios. It is also open to self-hosting, and a copy you run yourself sends us nothing at all.