Privacy
last updated 5 August 2026
graph.zeuglab.com is a private surface operated by Zeug Lab. It is not a consumer product and has no public sign-up: you are reading this because someone gave you a link or an account. This page describes exactly what the system stores, which is not much.
What is collected
- Your email address, if you were invited or hold an account. It is used to send sign-in links and to decide which views you may open. Nothing else.
- A password hash, only if you choose to set a password. Hashed with scrypt and a per-password salt; the password itself is never stored and cannot be recovered from the hash — only replaced.
- A session cookie (
zg_session) — a signed token holding your principal type and which views you may open. It ishttpOnly,SameSite=Lax, and secure in production. - Share-link records — for links you were sent: a label, an expiry, when it was last opened and how many times. This exists so links can be revoked and audited.
- Content you create in the graph: node titles, descriptions, positions, statuses and connections.
What is not collected
- No analytics, no tracking pixels, no advertising identifiers, no session recording.
- No third-party cookies. The only cookie is the session one described above.
- No IP addresses or user agents in the application’s own records. Vercel keeps standard request logs as our hosting provider.
- Nothing is sold, rented, or shared for marketing. There is no marketing.
Who processes it
- Vercel — hosting and request logs.
- Resend — delivery of sign-in and password emails.
- A managed Postgres provider — storage of the records above.
These are infrastructure providers acting on our instructions. No other party receives your data.
How long it is kept
Sessions expire on their own — 90 days for the operator, 30 for team accounts, and at most the stated lifetime for a share link. Sign-in links expire in 15 minutes, password-reset links in an hour, and a reset link stops working the moment it is used. Account records are kept while the account exists and are deleted on request.
Your choices
Ask and we will show you everything held about you, correct it, or delete it. Removing an account deletes its email, password hash and share links. Signing out clears the cookie immediately; you can also clear it in your browser.
Security
Access is default-deny: every request is checked against an explicit capability before any content is returned, and automated principals can never widen access. Traffic is encrypted in transit. No system is perfect, and we will tell affected people promptly if something goes wrong.
Contact
Questions, corrections, or deletion requests: alex@zeuglab.com.