❖Privacy & Data Governance

Privacy Policy

Effective Date: October 1, 2026 · Version 1.2

The Sulcus Privacy Promise

We provide Memory-as-a-Service. Your memories belong entirely to you. We strictly do not use your stored memory records, prompts, or queries to train public foundation models, and we never sell your personal or organizational data.

1.Scope & Purpose

This Privacy Policy applies to the services, applications, and APIs provided by Digital Forge Studios Inc. under the Sulcus brand ("Sulcus", "we", "us", or "our"), including our cloud endpoints at api.sulcus.ca, the ChatGPT Plugin, Custom GPT Actions, MCP servers, and the web portal at sulcus.ca.

2. Information We Collect

When you or your AI agents interact with Sulcus, we collect the following categories of information:

  • Memory Records: The text, facts, preferences, decisions, code outlines, and directives explicitly stored via MCP tools (store_memory) or API requests.
  • Vector Embeddings: Mathematical vector projections derived from your stored text to facilitate semantic similarity recall.
  • Authentication & Account Data: User account credentials, email addresses (via Keycloak Cerberus), and hashed API keys required to isolate and authenticate your tenant partition.
  • Telemetry & Audit Logs: Operational health metrics such as request counts, query latencies, cache hit ratios, and thermodynamic decay tick timestamps.

3. How We Use Your Data

Your data is processed strictly for the following purposes:

  • Storing, organizing, and retrieving memory context across conversational sessions.
  • Executing hybrid semantic and full-text keyword searches to recall relevant facts.
  • Calculating thermodynamic heat decay and spreading activation across knowledge graph nodes.
  • Enforcing strict tenant isolation and access control.

4. Foundation Model Training Prohibition

Sulcus maintains an absolute prohibition against using customer data for model training. We do not use your stored memories, search queries, or user interactions to train, fine-tune, or reinforce public foundation models or third-party artificial intelligence engines.

5.Multi-Tenant Isolation & Security

  • Data in Transit: All communication between agents, ChatGPT, and our servers is encrypted using Transport Layer Security (TLS 1.3).
  • Data at Rest: Database volumes are encrypted at rest using industry-standard AES-256 encryption.
  • Secret Management: API keys are hashed using one-way cryptographic hashing algorithms (sha256) prior to storage; plaintext keys are never stored.
  • Existence Masking: Requests attempting to query another tenant's namespace return non-informative 404 Not Found errors to prevent entity enumeration.

6.Data Retention, Export & Deletion

You retain full ownership and control over your memory data at all times. You may:

  • Inspect and query your memories anytime via the web dashboard or MCP tools.
  • Delete individual memories or entire namespaces using forget_memory or the delete endpoint.
  • Request complete permanent deletion of your account and associated memory vectors by contacting our support team.

7. Contact Us

If you have any questions, privacy concerns, or data deletion requests, please reach out to us:

Digital Forge Studios Inc. (Sulcus)

Email: support@sulcus.ca

Website: https://sulcus.ca