Privacy Policy
Last updated: 2026-08-26
LogiShell LTD, registered in England and Wales. Company registration is in progress; the registered number and office address appear here as soon as Companies House issues them. operates LogiShell. This policy explains what we collect, why, and what we can and cannot see.
1. Data we collect
Account data. Email address (if you sign up by email), name and avatar (if you sign in with Google or GitHub), and wallet address(es) you connect. A wallet address is a public identifier, but we treat it as personal data because it identifies you within our service.
Content you create. Graphs, blocks, files, runs, assistant conversations, and memory entries, unless marked private (section 3).
Operational data. IP address, user agent, timestamps, and error traces, retained for 90 days for security and debugging.
Payment records. Transaction identifier, sender address, amount, and timestamp for payments made in USDC on Base. Blockchain transactions are public and permanent by nature; we do not control that ledger and cannot erase entries from it.
We do not collect private keys or seed phrases; see Non-Custodial Disclosure.
2. Why we process it
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Providing the service, running your logic | Contract |
| Authentication and account security | Contract / legitimate interests |
| Preventing abuse and fraud | Legitimate interests |
| Processing payments and keeping records | Contract / legal obligation |
| Diagnostics: crashes and errors, without content | Consent |
| Product analytics: which features are used, without content | Consent |
| Marketing email | Consent (withdrawable at any time) |
The two consent switches. We ask once, on your first sign-in, and you can change the answer at any time in Settings, Privacy. Until you answer, we send nothing. What each switch covers:
- Diagnostics. That something failed, where in the product, and on which platform and version. Never the contents of your files, prompts, terminal output, or messages.
- Product analytics. That a feature was opened or a step completed, so we can tell which parts of the product are worth keeping. The list of events we accept is fixed in code and rejects anything not on it, so the promise is enforced by the software rather than by our care.
Two things stay on regardless, because they are not analytics and we say so plainly rather than hide them under a switch: records we must keep to bill you correctly and to enforce usage limits, and security logs. Both are covered by contract and legal obligation above, not by consent.
3. Private (end-to-end encrypted) objects
You may mark individual objects as private. Those objects are encrypted on your device with a key we never receive. For them:
What we cannot see: the content itself, in any form, at any time. We have no technical means of decrypting it.
What we can still see, and must, to operate the service:
- which account owns the object, and which workspace it belongs to;
- object type (graph, block, secret, file, conversation, memory entry);
- size of the encrypted payload;
- creation and modification timestamps;
- which unlock methods are enabled for it (wallet, passkey, recovery phrase, device) and the public identifier of each: for a wallet method, the wallet address.
Consequences you accept when marking an object private: it cannot be run on our servers, searched server-side, shared with your organisation, or processed by the assistant on our servers; and if you lose all your unlock methods it is permanently unrecoverable by anyone, including us.
4. Sub-processors
We use the following providers. Each processes data only to deliver its function:
| Provider | Function | Region |
|---|---|---|
| Cloudflare, Inc. | Hosting, edge compute, storage, CDN | Global |
| Neon, Inc. | Managed PostgreSQL | EU and US regions |
| Anthropic PBC | Assistant (LLM) responses, for content you send to it | US |
| Resend, Inc. | Transactional email (sign-in links, notifications) | US |
| WalletConnect / Reown | Relay for mobile wallet connections | Global |
| A Base network RPC provider | Signature verification and payment status | Global |
Content marked private is never sent to the assistant provider unless you explicitly decrypt it and choose to send it in that moment.
This list is kept current on this page. We will give 30 days' notice before adding a sub-processor that processes customer content.
5. International transfers
Data may be processed outside your country, including in the United States. We rely on the UK International Data Transfer Addendum together with the European Commission's Standard Contractual Clauses, or on an adequacy decision where one covers the country in question.
6. Retention
| Data | Retained |
|---|---|
| Account and content | Until you delete it, or 30 days after account closure |
| Encrypted objects | Same as above; deletion removes ciphertext and wrapped keys |
| Logs | 90 days |
| Payment records | Six years after the end of the accounting period, as UK tax law requires |
| Blockchain transactions | Permanent, on a public ledger outside our control |
7. Your rights
Where GDPR or UK GDPR applies you may request access, correction, deletion, restriction, portability, and object to processing based on legitimate interests. You may also complain to your supervisory authority.
One honest limit: for private objects we can export the ciphertext and delete it, but we cannot produce a readable copy: only you can decrypt it.
Requests: hello@logishell.com. We respond within 30 days.
If you are not satisfied with our answer you can complain to the UK Information Commissioner's Office (ico.org.uk), or to the supervisory authority where you live.
8. Cookies
We use strictly necessary cookies for sessions and security, and we store two small values on your device because you asked for them: which colour theme you chose, and whether the opening animation has already played in this tab.
We set no advertising cookies and no third-party analytics cookies, which is why this site shows you no cookie banner. Our own counters are kept on the server and are governed by the two switches in section 2; the country a request came from is supplied by our CDN and is not read from your device.
9. Children
The service is not directed to children under 16, and we do not knowingly collect their data.
10. Changes
We will post changes here and, for material changes, notify account holders by email at least 14 days in advance.
Contact: hello@logishell.com · Data controller: LogiShell LTD, registered in England and Wales. Company registration is in progress; the registered number and office address appear here as soon as Companies House issues them.