Who We Are and Scope
Empirical is operated by Gauzza LLC ("Gauzza LLC," "Empirical," "we," "us," or "our"), a Pennsylvania limited liability company. This policy applies to the Empirical web portal, API, CLI, and MCP integrations (collectively, the "Service"). Where you use the Service on behalf of an organization, that organization is the account owner and is responsible for the lawfulness of the data its users submit.
Data We Collect
Account data: name, email address, authentication identifiers, and workspace membership.
Credential metadata: API key identifiers, key previews, OAuth token metadata, and scopes granted. We do not display full API keys or tokens after initial issuance.
Memory content: text, tags, and structured data you or your integrations intentionally save to the Service.
Usage and device data: IP address, browser/user-agent, request timestamps, endpoints called, and error diagnostics, collected via server logs and cookies described below.
Billing data: plan tier, transaction history, and billing contact details. Full payment card numbers are handled by our payment processor and are never stored on our servers.
Cookies and Similar Technologies
We use strictly necessary cookies to maintain your authenticated session and protect against cross-site request forgery. These cannot be disabled without breaking login.
We use a limited set of functional cookies to remember interface preferences (e.g., theme).
We do not use third-party advertising or cross-site tracking cookies. If this changes, we will update this policy and, where required by law, request your consent before setting non-essential cookies.
How We Use Data
We process data to: provide authentication and account management; store, index, and retrieve memory content on your behalf; power search, ranking, and graph features; process payments and manage subscriptions; monitor system health and prevent abuse; and provide customer support. We use OpenAI and Anthropic APIs to process memory content for extraction, ranking, and generation features — see Subprocessors below. We do not sell your personal data, and we do not use your memory content to train third-party foundation models.
Legal Bases for Processing (EEA/UK Users)
Where the GDPR or UK GDPR applies, we process your data on the following bases: performance of a contract (providing the Service you signed up for), legitimate interests (security, abuse prevention, service improvement, weighed against your rights), consent (non-essential cookies, marketing communications), and legal obligation (tax, accounting, and law-enforcement requests).
Health Information and Sensitive Data
Empirical is a general-purpose memory infrastructure product. We are not a HIPAA covered entity, and we do not currently offer signed Business Associate Agreements (BAAs) with our infrastructure subprocessors. Accordingly, you should not submit protected health information (PHI), as defined under HIPAA, or other regulated health data to the Service unless and until a BAA is in place between you and Gauzza LLC.
We apply the same technical safeguards (encryption in transit and at rest, access controls, audit logging) to all memory content regardless of category, but these safeguards alone do not constitute HIPAA compliance for your use case. If you have a use case that involves PHI, contact us before submitting that data so we can evaluate a BAA.
You are responsible for not submitting other special categories of data (e.g., government ID numbers, financial account credentials, biometric data) unless you have independently confirmed the Service is an appropriate place to store them.
Subprocessors and Infrastructure
We rely on the following categories of subprocessors to deliver the Service: cloud database hosting (MongoDB Atlas), authentication (Firebase Authentication / Google), payment processing (Stripe), large-language-model processing of memory content for extraction and retrieval features (OpenAI, Anthropic), and application hosting/infrastructure (Namecheap-hosted servers and self-operated hardware).
Each subprocessor is contractually or contractually-by-terms-of-service restricted from using your data for purposes other than providing services to us, except as those providers' own terms describe (for example, standard API-usage terms of the LLM providers we use). We will maintain and provide an up-to-date subprocessor list on request.
If we add or replace a subprocessor in a way that materially changes how your data is processed, we will update this policy and, for enterprise customers under a separate data processing agreement, provide notice as required by that agreement.
Data Sharing
We share personal data with subprocessors as described above, with law enforcement or regulators when required by valid legal process, with a successor entity in connection with a merger, acquisition, or asset sale (subject to this policy or a materially similar one), and with your explicit consent. We do not sell personal data or share it with third parties for their own advertising purposes.
International Data Transfers
Our infrastructure and subprocessors may process data in the United States. Where we transfer personal data out of the EEA, UK, or Switzerland, we rely on appropriate safeguards such as Standard Contractual Clauses or the subprocessor's own certified transfer mechanism.
Data Retention
We retain account and memory data for as long as your account is active. Following account deletion, we remove memory content and personal data from production systems within 30 days, except where retention is required for fraud prevention, legal compliance, tax/accounting records, or resolution of disputes, in which case we retain only the minimum data necessary and for no longer than required. Backups are rotated out of retention on our standard backup cycle, not to exceed 90 days after deletion.
Security Practices
We apply encryption in transit (TLS) and at rest, role- and token-based access controls, and audit logging designed to protect data against unauthorized access. No system is guaranteed to be perfectly secure. In the event of a data breach affecting your personal data, we will notify affected account owners without undue delay and in accordance with applicable law.
Children's Privacy
The Service is not directed to, and is not intended for use by, individuals under the age of 16. We do not knowingly collect personal data from children under 16. If we learn that we have collected personal data from a child under 16 without verified parental consent, we will delete it. If you believe a child has provided us data, contact us using the details below.
Your Rights and Requests
Depending on your location, you may have the right to access, correct, export, or delete your personal data; restrict or object to certain processing; and withdraw consent where processing is consent-based. California residents have rights under the CCPA/CPRA, including the right to know, delete, correct, and opt out of "sale" or "sharing" of personal information — we do not sell or share personal information as defined by the CCPA.
To exercise these rights, email hello@gauzza.com from your account email address. We will verify your identity before acting on the request and will respond within the timeframe required by applicable law (generally 30 days, or 45 days for CCPA requests).
You may also lodge a complaint with your local data protection authority if you believe our processing does not comply with applicable law.
Policy Changes
We may update this policy from time to time. Material changes will be reflected by an updated effective date above, and where required by law, we will provide additional notice (e.g., email) before the change takes effect. Continued use of the Service after an updated effective date constitutes acknowledgment of the revised policy.
Contact
Questions or requests regarding this policy can be sent to hello@gauzza.com. Gauzza LLC ("Gauzza LLC," "Empirical," "we," "us," or "our") is the data controller for personal data processed through the Service.
