Legal
How gno.sh handles account data, published content, billing metadata, email delivery, logs, and reader analytics.
gno.sh is operated by Gordon Mickel, Switzerland. Contact: legal@gno.sh.
Pilot cohort keys never contain client or project names. Public pilot reports omit the internal cohort key and use a one-way opaque report identifier bound to the approved aggregate.
gno.sh currently relies on the following infrastructure providers:
If you publish a page as public, the published route, note content, metadata preview, and any included assets are intended to be publicly accessible. Do not publish personal, confidential, or regulated information unless you are entitled to disclose it.
A public snapshot may include a read-only agent projection containing deterministic Markdown, a manifest, and exact evidence locators. This projection contains only the material intentionally included in that public snapshot. Secret-link, invite-only, and encrypted spaces do not expose this projection. gno.sh does not currently offer a token-authenticated private agent API.
Current GNO artifacts include content-free collection egress lineage so you can verify which local boundary governed an export. gno.sh processes only the artifact you explicitly upload; it cannot inspect or synchronize the source collection. Tightening a local GNO policy does not recall an artifact already uploaded. Secret and encrypted links can be revoked or expired in Studio. Public-space deletion is not yet self-service; contact the abuse or privacy address for remote takedown. Local deletion and remote takedown are separate operations.
Encrypted artifacts are encrypted locally before upload. gno.sh stores and serves ciphertext; the passphrase and plaintext are not server inputs, and readers decrypt in their browser. I cannot recover a lost passphrase or server-decrypt an encrypted share. No subscription, support request, administrator action, or future private agent route changes that boundary.
The private design-partner pilot is opt-in. Its milestone receipts do not accept document content, query text, raw URLs, evidence spans, or free-form notes. A participant can opt out at any time; later milestone collection stops and their results are excluded from public reporting. Publication approval binds the exact current aggregate fingerprint; a later outcome invalidates that approval until the current aggregate is approved again. Event receipts are retained for at most 30 days. Consent records and de-identified cohort aggregates are retained for at most 365 days, unless earlier deletion is required.
Public pilot results require approval from every active participant, contain aggregate counts only, and suppress non-zero groups smaller than three. Individual participant keys and consent identifiers are never published.
gno.sh uses essential cookies and similar storage for authentication, session continuity, and security. It does not use advertising cookies.
Account and publish records are retained for as long as needed to operate the service, comply with legal obligations, resolve disputes, and enforce the Terms. You can request deletion of your account or published content, subject to legal and operational constraints.
Depending on where you are located, you may have rights to access, correct, delete, restrict, or object to processing of your personal data. To make a request, contact privacy@gno.sh.
I may update this Privacy Policy when the product, providers, or legal obligations change. Material changes will be reflected on this page.