SSENLAY
DemoDocsPricingContactSign in
Legal

Privacy Notice

How Senlay handles data when you browse the site, use the demo, create an account, or call the API.

Effective: July 11, 2026

Short version: Senlay uses account and request data to provide and secure the service. A provider key pasted into the demo travels through Senlay's server to the provider you choose; it is not sent directly from your browser. Full Senlay API keys are displayed once and are not returned in account profiles.

1. Who is responsible

Senlay operates the Senlay platform and is responsible for the processing described here. Privacy questions and requests can be sent to viktor@senlay.world.

2. Data we handle

Account and authentication data

  • Name, email address, password hash, sign-in provider identifiers, session records, account tier, and account timestamps.
  • Senlay API-key hashes, masked previews, labels, status, creation dates, and usage counters. A full API key is returned only when it is created.
  • For passwordless agent registration: agent name, optional owner email, credential hashes, masked previews, and a hashed recovery credential. New credentials are displayed only in the registration or authorized rotation response.

Requests and physical-world data

We process coordinates, selected activities or fields, search text, prompts, device or tracker telemetry you submit, request times, endpoint paths, response status, source-health results, and related operational metadata. Coordinates may be sent to upstream weather, marine, mapping, geocoding, satellite, or sensor providers needed to answer the request.

Bring-your-own model keys

  • Pasted demo key: your browser sends the key over HTTPS to Senlay. Senlay uses it server-side to proxy the selected model request. Pasted keys are not intentionally stored in Senlay's database. Session mode keeps the key in browser memory or session storage; “remember” mode stores it on that device until you remove it or clear site data.
  • Saved paid-tier key: if you explicitly save a model-provider key in your profile, Senlay encrypts it server-side. The dashboard later returns only a masked preview, not the full secret.
  • The selected model provider receives the prompt and relevant physical-world context under that provider's own terms and privacy notice.

Technical and support data

Our server and reverse proxy may record IP address, user agent, request path, status, timing, security events, and error details. We do not need full API keys or request bodies in ordinary access logs and ask users not to put secrets in prompts, URLs, support messages, or public posts. If you contact us, we process the contents and contact details needed to respond.

3. Browser storage and permissions

Senlay uses local storage or session storage for choices such as session sign-in, selected location, units, setup state, and an optional remembered provider key. Google sign-in may use short-lived state cookies or equivalent session controls. Geolocation is requested only after you activate a location control; your browser controls whether permission is granted.

4. Why we use data

  • Provide accounts, API access, physical-world responses, maps, model chat, and support.
  • Authenticate users, enforce quotas, prevent abuse, investigate failures, and protect the service.
  • Maintain source freshness, improve reliability, and understand aggregate service usage.
  • Meet legal obligations and enforce the Terms of Use.

5. Providers and disclosures

Depending on the feature and location, data may be processed by hosting and infrastructure vendors, identity providers, model providers you select, and environmental or mapping sources such as Open-Meteo, NOAA, OpenStreetMap/Nominatim, map-tile providers, satellite services, and configured commercial sensor networks. Coverage changes by location. We may also disclose data when legally required or necessary to protect users and the service. Senlay does not sell personal information.

6. Retention

Account and credential metadata is retained while the account is active and as needed for security, audit, backup, and legal purposes. Sessions expire or can be revoked. Operational logs and caches are retained only as long as reasonably needed for reliability and security. Browser-stored data remains until it expires or you remove it. Upstream providers apply their own retention rules.

7. Security

We use measures such as HTTPS, password hashing, hashed Senlay API keys, scoped sessions, masked key previews, encryption for explicitly saved model keys, rate limits, and restricted server-side secrets. No service can guarantee absolute security. Revoke or rotate a credential and contact us promptly if you suspect exposure.

8. Your choices and rights

You can deny geolocation, use manual coordinates, avoid “remember” mode, sign out, clear browser storage, revoke provider keys at their issuer, and request account access, correction, export, or deletion where applicable. Contact us using the address above. We may need to verify your identity before acting on a request.

9. Children, international use, and changes

Senlay is a developer and operational service and is not directed to children. Data may be processed in countries other than your own. We may update this notice as the service and its providers change; the effective date above identifies the current version.

SENLAY

Spot-level physical-world verification. Decision support only.

PrivacyTermsContactHome