--- title: "Privacy" description: "What the site and API store, who can access the data, and how to request deletion." canonical: https://past.dev/privacy last-updated: 2026-10-10 --- # Privacy > What this site stores, what the API stores, who can see it, and how to have it deleted. Source: https://past.dev/privacy ยท Last updated 2026-09-24 ## Who we are past.dev is operated by Revo Inc.. The company does business as Past Corp.. ## This website The site stores your light or dark theme choice in your browser's local storage. This setting remains on your device and is required for the site to work the way you asked. Page views are counted in aggregate by Vercel Analytics, which does not use cookies and does not build a profile of you. The site sets one cookie of its own, `past_consent`, which records your choice in the consent banner for one year. It is written only after you choose. When analytics is on for you, PostHog sets analytics cookies and records the pages you view, the calls to action you click (such as Get API key), and the source of your first visit: referrer, campaign parameters, landing page and time. Events go to PostHog's EU servers. Autocapture is off. PostHog builds a person profile only when your first visit came from an ad or a tagged campaign link, and that profile holds the campaign. The paragraph on where you are, below, says when it is on. With analytics on, the site also stores the source of your first visit in local storage under `past_first_source` and attaches it to the booking link, so we know which channel brought you. When that first visit came from an ad or a tagged campaign link, the site also sets a cookie, `past_first_touch`, on past.dev and its subdomains for 90 days. It holds the campaign parameters, landing page and time of that visit, so that an account you create in the console is credited to that campaign. If you reject analytics later, the site removes it. The site also runs the LinkedIn Insight Tag, which sets advertising cookies. It tells us which of our LinkedIn ads led to a booking request, and it lets us show ads on LinkedIn to people who read this site. LinkedIn receives your visit and acts as a separate controller for it. Rejecting advertising stops it, and the paragraph on where you are, below, says when it loads without being accepted. The page-load pixel LinkedIn offers for browsers without JavaScript is deliberately not installed here, because it would fire before you could answer. With advertising on, the click identifier Google Ads adds to the link of an ad you arrived by is also kept with the source of your first visit, so that we can tell Google Ads when that click led to an account. With advertising rejected, it is not kept, and one kept before you rejected advertising is removed. The same holds for the click identifiers of ads on X and LinkedIn. The site also runs the X pixel. It tells us which of our ads on X led to a visit, and it lets us show ads again on X to people who read this site. X receives your visit and acts as a separate controller for it. It loads only with advertising on, and the audience it builds is held in our X ads account. The site also runs RB2B, which tries to identify the person behind a visit. RB2B matches your visit against its own identity database and may tell us a name, a work email address, a company and a LinkedIn profile, so that we can follow up with people who read this site. It identifies visitors in the United States only. RB2B is a separate controller for the data it holds, and you can ask it to remove you at rb2b.com. Rejecting advertising stops it, in the banner or later with "Do Not Sell or Share My Personal Information", and the paragraph on where you are, below, says when it loads without being accepted. Where you are decides when these load. In the EEA, the United Kingdom and Switzerland, and anywhere we cannot place you, nothing optional loads until you accept it in the banner. Everywhere else, including the United States, the banner is your notice and the trackers above run until you say otherwise: reject them in the banner, or reopen it at any time with the "Do Not Sell or Share My Personal Information" link at the foot of every page. That choice is kept in the `past_consent` cookie for a year, and it is honoured on every page from the moment you make it. If you are in the United States, you can opt out of what the laws of your state call the sale or sharing of personal information, and of targeted advertising, with either of those controls. We do not sell personal information for money, we do not knowingly collect anything from anyone under 16, and we do not use these tools to infer anything sensitive about you. A Global Privacy Control or Do Not Track signal is treated as rejection of every optional cookie, in every country, and the banner is not shown. To change a choice you already made, use "Do Not Sell or Share My Personal Information" at the foot of the page. The site is hosted by Vercel, which processes request logs including IP addresses to serve and protect it. ## Your account Anyone can create an account. Sign-up is self-serve at https://sso.past.dev/sign-up and nobody approves it. Sign-up and sign-in run on WorkOS, our identity provider, which holds your email address, your name if you give it, and your sign-in method. Your account stores your email address, your name, the organization it belongs to and its plan. When you sign up and each time you sign in, these details and your sign-in method go to Segment. Segment sends them to our product analytics tool and to Customer.io for email about your account and the product. If an ad or a tagged campaign link brought you to past.dev and the site set the `past_first_touch` cookie (see "This website"), your sign-up also records that campaign. The service records a few account events, such as creating a project, creating or revoking a key, and the first ingestion and recall of a project. These events never contain your memory content: no data point, query text or recall result. ## What the API stores The Memory API stores the text, timestamp, label, and project for each data point you send. It derives entities, facts, and relationships from that data. It keeps the source text so recall results can cite their source. It also stores the project keys, the organization's management key, and per-call usage records for the console dashboard. It does not ask for, and should not be sent, information about your end users beyond what the content itself contains. The people using your software never hold an account with us. ## Who can see it The server maps each API key to one project. Calls made with that key can access only that project's memory. The project identifier cannot be changed in a request. A data point can be scoped to an audience: `/api/v1/ingest` takes an `audience` slug and retrieval filters by it inside the engine. A point sent without one is visible to everything reading that project, so keep content with different authorization boundaries in separate projects or scope it explicitly. Audiences are created in the console or with `/api/v1/audiences`, and every recall names the `identity` it answers as. ## Training Your content is not used to train models. It is stored to process ingestion and recall requests. ## Deletion and retention Deleting a source deletes what was derived from it: the facts drawn from that text and the sentences that produced them go with it. A data point is deleted by the source id you gave it, through `/api/v1/data-points`, or with the rest of its ingestion through `DELETE /api/v1/ingest/{ingestionId}`. Retention terms for the paid tiers are set in your agreement. On any plan, ask and we will delete a project and everything derived from it. ## Subprocessors and where it runs The API uses infrastructure and language model providers. The current subprocessor list, hosting regions, and DPA are available on request. ## Startup program applications The startup program application sends what its form asks: your name, email and role, the company's name, website, country, founding year, team size, stage and funding range, and your answers about what you are building and need. It goes to our startup program channel on Slack, where a person reads it. Nothing from the form is written to a database, and nothing is sent to any other service. Slack holds the message under its own retention. Your IP address is held in memory for one minute to limit repeated requests, then discarded. To have an application deleted from the channel, write to support@past.dev. ## Contact To ask what we hold, to have it deleted, or to request the subprocessor list and a DPA, book a demo: https://past.dev/call