Skip to content
The Membrane
Terms GitHub

Legal

Privacy Policy

Effective October 5, 2026

Short version: the project does not collect or keep your personal information, apart from a short-lived IP-based rate limit on the demo. The public site is static. The hosted demo sandbox keeps a temporary, anonymous session in memory and discards it. The software you run yourself sends nothing to us. This page says exactly what each part does, so you can check it against the source code.

The Membrane is owned and maintained by Dojopop Nishi LLC, a Wyoming limited liability company. In this policy, "the project" means Dojopop Nishi LLC and the Membrane it maintains.

1. The public site (membrane.dojopop.live)

The site is a set of static pages. It has no accounts, sign-in, forms, comments, payments, or analytics, and it sets no cookies of its own.

It does load fonts from Google Fonts, so your browser sends a request to Google that includes your IP address and browser details. Links to GitHub take you to GitHub, which has its own privacy practices. You can block either without losing any content.

The pages are served through Cloudflare. Cloudflare may process technical request data to deliver and protect the site, such as IP address, time, URL, browser, referrer, and security signals, and may use its own security cookies. The project adds no logging of its own.

2. The hosted demo sandbox (membrane-demo.dojopop.live)

The sandbox runs the gate code against simulated tools. Nothing you do there reaches Jira, Slack, GitHub, or any other service; its container has no route out to the internet.

What it handles while you use it:

  • A session cookie. A random, opaque identifier named membrane_demo_session, marked HttpOnly and SameSite=Strict, valid for 30 minutes. It identifies a browser tab's demo state, not you.
  • Demo state, in memory only. The keys, authorizations, receipts, and timeline for your session live in the server's memory. They expire 30 minutes after your last request and are wiped when the server restarts. Nothing is written to a database.
  • What you type. If you fill in the action form (tool, model, ticket, channel, message text up to 2,000 characters), that text is used to run the simulated action and may appear in the simulated result and receipts for your session. It is discarded with the session. The demo code does not log it.
  • Your IP address, for rate limiting. Requests are limited per minute (120 reads, 30 writes). The limiter uses the visitor IP address that Cloudflare passes along, keeps it in memory for about two minutes, and uses it for nothing else.

Do not type secrets, personal data, or anything confidential into the sandbox. It is a demonstration, and the infrastructure in front of it (Cloudflare and the tunnel) may keep its own request logs under its own terms.

3. Software you run yourself

The Membrane gate, the operator dashboard, the advisor, and the CLI run on your machines. The project has no telemetry, no usage reporting, and no way to see what you do with them. The only network connections they make are the ones you configure: your relay, your model API, the GitHub connector if you add a token, and any alarm or SIEM webhook you set.

The operator dashboard is read-only and listens on the loopback address only. It shows a bounded list of recent authorization decisions: time, allow or deny, the rule that matched, the kind of action, the gate's signing identity, the verified caller key when the caller proved it, and the scope when known. For denials it can show the model, tool, or repository name that was refused. Those names are text chosen by the caller, so the dashboard shortens and cleans them and never uses them to make a decision. It does not record prompts, model responses, credentials, or tool payloads.

The decision list holds the latest 500 entries in memory and clears when the gate restarts. Readings and alarms are calculated from that list. If you set an alarm webhook, alarm notices (kind, time, shortened caller key, a short summary) are sent to the address you chose, so that destination's privacy practices apply to them. The gate also publishes signed checkpoint and authorization events (hashes, scope identifiers, timestamps, model and tool allowlists) to the relay you configure.

You are the operator of your own deployment and are responsible for what it stores, who can read it, and how long it is kept.

4. What the project does not do

  • Sell or share personal information, or build advertising profiles.
  • Run first-party analytics, tracking pixels, or ad technology.
  • Collect production agent data, prompts, model output, tool payloads, receipts, credentials, or policies from anyone running the software.

5. How long things are kept

Sandbox sessions: up to 30 minutes after last use, then discarded. Rate-limit entries: about two minutes. The public site and sandbox have no application database. Logs kept by Cloudflare or other infrastructure providers follow those providers' settings, and the project cannot promise a retention period for them. For your own deployment, retention is whatever you configure.

6. Your choices

You can use the source code and run everything locally without visiting the site. You can block Google Fonts and cookies in your browser; the content still works. You can clear the sandbox cookie at any time, which abandons that session. Because there are no accounts and the sandbox state is anonymous and short-lived, there is usually nothing to look up or delete. If you believe the project holds personal information about you, open a GitHub issue with only non-sensitive details and ask for access, correction, or deletion.

7. Changes and contact

If the site or software changes how it handles data, this page will be updated and the effective date changed. Questions or requests: open an issue at github.com/Z0rlord/the-membrane. Issues are public, so leave out secrets and personal details; ask for a private channel in the issue if you need one.

See also the Terms of Service.

The Membrane

Terms of Service Privacy Policy