Privacy and data
Where your data lives
Your Constitution, drafts, amendments and the Record live in your own Notion workspace. You own them, can edit them with tools you already use, and can take them with you.
What Constitute stores
- Your account and timezone.
- Encrypted credentials: your Notion tokens and any Typefully or Buffer key. Each tenant has its own data key, wrapped by a platform key. Plaintext is never returned to the browser, logged, or put in an error message.
- Publishing settings, billing records and operational job state.
- A search index of your Articles. It is a disposable cache: dropping it and re-syncing from Notion restores everything with no data loss.
- Agent keys, stored as a hash. They are shown once and can’t be recovered.
- An audit log of what your delegates did.
What Constitute does not do
- It runs no generative model on its servers. The only model it calls is an embedding model, to make your Articles searchable.
- It does not train on your data.
- It never publishes anything you haven’t ratified.
Leaving
On disconnect or deletion, secrets are revoked and deleted immediately, and the search index, caches and connection rows are deleted within 24 hours. The audit log and billing records are kept for the legal retention period. Your Notion is untouched.
Control
Every delegate has an explicit set of scopes, visible in Settings with its last use. You can revoke any key at any time, and pause publishing with one toggle.