# Limitless privacy and data use

**Effective:** August 24, 2026

**Service:** Limitless Library, a Univeracity project

**Contact:** privacy@limitlesslibrary.com

This notice covers the official Limitless Library website and hosted service.
It does not cover work performed entirely by the open-source software on your
device. “Limitless,” “we,” and “us” below mean the operator of the official
Limitless Library service.

## The short version

Limitless can answer a short request without receiving your repository, full
prompt history, credentials, or local catalog. The current anonymous default
uses the objective for the immediate service query, does not persist or queue
the raw objective, and keeps only bounded integrity, decision, outcome, quota,
security, and aggregate facts.

We do not sell raw query streams, disclose identifiable customer requests to
other participants, or train a general model on task text without a separate
explicit opt-in.

## Your three independent choices

Limitless separates choices that should not be collapsed into one “private”
switch:

| Choice | Current values | What it controls |
| --- | --- | --- |
| Execution | Local or service | Whether the objective leaves the device for processing |
| Audience | Private, circle, organization, or public | Who may discover material you deliberately contribute |
| History | Local-only or service-persisted | Whether personal or organization query history is kept by the service |

Local-only history is the default. Service-persisted history requires an
account and an explicit choice when that feature is available. Audience never
turns a query, result, or local outcome into a contribution.

You may set defaults and narrower operation-, repository-, session-, circle-,
or organization-specific choices in supported clients. Widening a sharing
audience requires saved authorization. A material policy change requires new
acceptance rather than a quiet downgrade.

## What the hosted service processes

Depending on the feature, we may process:

- a short objective and typed receiver facts needed to find compatible work;
- an installation public key, opaque installation identifier, signed proofs,
  short-lived session authority, quota state, and account or organization
  identity if you later add one;
- request, result, release, and outcome digests; selected capability and index
  identifiers; timestamps; verification classes; and bounded lifecycle state;
- files, method text, source references, notices, and provenance that you
  explicitly submit for publication;
- security and network metadata needed to operate, rate-limit, investigate,
  and protect the service, including IP-derived abuse signals processed by our
  infrastructure provider; and
- messages and identity information you send when requesting support or
  exercising a legal right.

The current service is hosted on Cloudflare infrastructure. Other providers
may process data only as needed to operate the service, comply with law, or
support a feature you choose.

## What we do with it

We use this information to:

- answer queries and return signed selections or abstentions;
- verify identity, permissions, compatibility, integrity, delivery, and
  receiver-reported outcomes;
- admit, rank, deliver, revise, quarantine, and withdraw publications;
- enforce quotas, prevent abuse, investigate incidents, and meet legal duties;
- operate support, account, organization, and paid features when available;
  and
- improve retrieval, detect missing supply, measure reliability and avoided
  reconstruction, and produce reuse intelligence from protected aggregates.

Protected aggregates may be retained and used for product, research, and
commercial analysis. We do not use them to reconstruct an individual's raw
query, and we do not expose slices that reveal a person's or organization's
work. Any materially broader use requires a revised policy and, where
appropriate, explicit opt-in.

Where applicable law requires a legal basis, we process information to perform
the service agreement, with your explicit choice for optional history or
publication, for legitimate interests such as security and service
improvement that do not override your rights, and to comply with law. You may
withdraw a consent-based choice prospectively, but that does not undo lawful
processing already completed or an irrevocable public license.

## Current retention

| Data | Current retention |
| --- | --- |
| Raw objective under local-only history | Used for the immediate request; not persisted or queued |
| Short-lived session and replay authority | No more than 70 minutes |
| Decision and outcome projections | 30 days |
| Installation identity | Until disabled or deleted |
| Local history | Controlled by the user on their device |
| Service-persisted history | Account opt-in; retained until deleted when available |
| Public release content, provenance, lineage, and tombstones | Indefinite |
| Protected aggregate counters | Indefinite |
| Security, support, and legally required records | As reasonably necessary for that purpose |

Withdrawal hides a release from future selection. It cannot recall copies
already received, revoke an otherwise irrevocable reuse license, or erase the
minimal provenance and tombstone needed to prevent unsafe rediscovery.

## Publishing

Public publishing is governed by the separately accepted Limitless publication
policy. Public material may be indexed, cached, delivered, and retained
indefinitely. Optional HTTPS source references may travel with a source-free
method; local filesystem paths do not. Exact files transfer only when they are
explicitly included through the publication flow—Limitless does not treat
workspace access or a search result as permission to upload them.

Supported clients may offer **Automatic + Public** as a saved standing
authorization. If you deliberately enable it, qualifying methods can transfer
without a prompt for every item. A publication-policy change pauses that path
until you review and save against the new digest.

## When information is shared

We may share information:

- with infrastructure and service providers acting for us;
- with an organization or circle when you use that explicitly authorized
  scope;
- with the public when you publish admitted public material;
- when reasonably necessary to comply with law or protect people, rights, and
  the service; or
- as part of a merger, financing, acquisition, reorganization, or sale, subject
  to this notice and any required notice or choice.

We may process information in the United States and other countries where our
providers operate.

## Your choices and requests

You may keep execution and history local, avoid creating an account, stop using
the service, disable an installation, withdraw a publication, or request
access, correction, export, or deletion where applicable. Anonymous requests
may require proof that you control the relevant installation key. If that key
is lost, we may be unable to associate an anonymous record with you without
weakening someone else's privacy or security.

Contact privacy@limitlesslibrary.com. We may need enough information to verify
and complete the request. You may appeal a denied privacy request by replying
to the decision. Depending on where you live, you may also have rights to know,
correct, delete, obtain, or opt out of certain uses of personal data and to
complain to your local regulator. Limitless does not use personal data for
targeted advertising or sell personal data.

## Children

The hosted service is not directed to children under 13. Do not use it or
publish through it if applicable law does not allow you to consent to this
processing without a parent or guardian.

## Changes

The service advertises its effective technical data-use policy by revision and
digest. We will provide notice of material changes and require new acceptance
when the client policy requires it. We may make immediate changes needed for
law, security, or abuse prevention, but we will not silently apply a weaker
history or disclosure setting to an existing request.

**Privacy:** privacy@limitlesslibrary.com

**All other legal matters:** legal@limitlesslibrary.com
