Gneiss.
  • Products
  • Blog
  • About
  • Support
← Back to home

Privacy Policy

Last updated: October 2, 2026

1. Overview

Gneiss Labs ("we", "us") publishes applications designed to help people improve themselves and connect with their communities. This policy covers this website and applies generally to our products. Individual applications may have their own privacy policies with product-specific details, available from each product's page.

2. This Website

This website does not use advertising trackers and does not require an account. We may use basic, privacy-respecting analytics to understand aggregate traffic. We do not sell visitor data.

3. Our Applications

Depending on the application and how you use it, we may collect:

  • Account information — if you create an account: name, email address
  • Usage data — feature usage and interaction metrics used to improve the product
  • Device data — device type, OS version, crash reports

We collect the minimum needed to operate each product. We do not use your data for advertising or sell it to third parties.

Music Discovery and Spotify

Spotify connection is optional. When enabled and authorized, we read your display name, available playlist names, and the contents of the playlist you choose. We use those songs as starting choices for the music discovery tool. We do not read your full listening history. Artist names may be sent to MusicBrainz to find independent genre tags. Spotify data is not used to train or run an AI model.

We store Spotify access and refresh tokens encrypted on the server. An HTTP-only cookie identifies your connection for up to 30 days. Imported playlist data is encrypted and kept for up to 7 days. New export records are encrypted and kept for up to 24 hours to let you reopen your result and prevent repeated playlist creation.

The current tool creates the final playlist in Spotify and does not save a separate shareable list here. Older generated lists remain available for up to 30 days to anyone with their view link; those views do not include the source playlist contents. Old export records can retain their original 30-day expiry. The browser can store your draft choices and export job ID for this tab session. Select Disconnect Spotify in the tool to remove your connection, imported preferences, export records, and generated lists based on those preferences. This does not delete playlists already created in your Spotify account. You can also remove the app's access from your Spotify account settings.

Feldspar model calls and web search

Feldspar sends your messages, instructions, and selected source passages to the model provider you choose. We store conversations, workflow records, prompts, replies, and call metrics in your account. Provider keys are encrypted on the server. No automatic deletion schedule is currently configured for call records.

When web search is enabled, Feldspar sends up to 600 characters and 75 words from your latest two user messages to Brave Search. Workflow search uses task text. System instructions and previous assistant or agent replies are excluded from the search query. We retain source links and retrieved passages in account records. Selected passages also reach your chosen model provider.

The Web search control will be on by default in the Feldspar UI when this feature is released. You can turn it off before sending a message or running a step. This choice is stored per account in this browser. Direct API callers must explicitly enable search. Search requires a synced provider key and is subject to a daily account allowance. Existing records remain stored when search is turned off. Do not put secrets in messages; automatic personal-data redaction is not yet available.

4. How We Use Information

  • Operate and improve our applications
  • Sync your data across devices where applicable (if signed in)
  • Diagnose crashes and fix bugs
  • Respond to support requests

5. Storage & Security

Data is stored using industry-standard encryption in transit and at rest, on trusted infrastructure providers. Data is primarily processed on servers in the United States.

6. Sharing

We do not sell your data. We may share it only with service providers who help us operate our products, when required by law, or in the event of a business transfer with 30 days' notice.

7. Your Rights

You may request to access, correct, or delete your personal data at any time by contacting support@gneisslabs.com. EU/EEA and UK users have additional rights under GDPR; California users have rights under CCPA. We respond within 30 days.

8. Children

Our products are not intended for children under 13 (or 16 in the EU). We do not knowingly collect data from children under these ages.

9. Changes

We may update this policy from time to time. Material changes will be posted here with at least 30 days' notice before taking effect.

10. Contact

For privacy-related questions or requests: support@gneisslabs.com


© 2026 Gneiss Labs. All rights reserved.

© 2026 Gneiss Labs  ·  gneisslabs.com  ·  Built by Han Jung