Account identity
When you sign in with GitHub or Google, we receive the provider account identifier and the profile fields the provider returns, normally your name, email address and avatar. We do not receive your provider password.
Loading Complexity
privacy.notice · updated 26 August 2026
This notice explains what the TR-Hash model lab, the research agent, the i64 completions gateway, LABO AI and your Complexity-ML account store, why it is needed, where it goes, and how you can export or delete it.
When you sign in with GitHub or Google, we receive the provider account identifier and the profile fields the provider returns, normally your name, email address and avatar. We do not receive your provider password.
Prompts you send to a TR-Hash checkpoint in the model lab go directly from your browser to the Hugging Face Space that hosts that model — they do not transit Complexity's own servers. Signed-in exchanges are saved as a conversation (up to 10 per account) in our database so you can resume them; as a guest, nothing is kept server-side.
Turning on Research mode in the model lab sends your question to a retrieval agent we operate ourselves, over MCP, on a Hugging Face-hosted server. It searches a bounded internal demo catalog and returns matching records as context for the model. That step never leaves Complexity-operated infrastructure and is not forwarded to any third-party LLM.
An i64 API key lets any client call our /v1/chat/completions proxy using a provider key you stored with us. We decrypt that key on the server only for the request you send, forward it to the provider you selected — OpenAI, Anthropic, Google or Mistral — and stream the response back without persisting the exchange.
Keys you add for Ask LABO or the i64 gateway (OpenAI, Anthropic, Google, Mistral) are encrypted before database storage. The interface only ever receives a short prefix and status, each secret is decrypted server-side solely to perform the request you initiated, and none are included in your data export.
Graphs, custom cards and presets are stored locally in your browser by default. They are not account cloud storage and are separate from model-lab conversation history. Deleting your account does not clear browser storage; use your browser controls to remove it from that device.
When you invoke Ask LABO, your prompt and the graph context needed for the plan are sent through the Complexity server to your configured provider using your stored key. Do not include personal or confidential data that is unnecessary for the request.
Controller
Boris Peyriguere / Complexity-ML
Paris, France
For a private rights request not covered by the self-service controls, contact the maintainer through the Complexity-ML organization contact channel. Never post identity documents or API keys in a public issue.
Complexity-ML contact →Account data is processed to authenticate you, run the model lab, the research agent and the i64 gateway, provide the account and agent features you request, secure access and prevent abuse. Service delivery is based on performance of the requested service; security and service integrity rely on legitimate interests. We do not use account data for advertising.
Data is handled by the service maintainer and by infrastructure providers needed to operate the service: Vercel for web hosting, the configured PostgreSQL/Neon infrastructure for account records, GitHub or Google for OAuth, Hugging Face for the TR-Hash model inference endpoints and the research agent's MCP server we operate, and OpenAI, Anthropic, Google or Mistral only when you invoke Ask LABO or the i64 gateway with a key for that provider. Those providers process data under their own terms and applicable transfer safeguards.
Account records, encrypted provider keys and saved model-lab conversations (up to 10 per account) are retained while your account exists, then removed when you use Delete account, subject to short-lived infrastructure backups and security logs controlled by hosting providers. Browser-local LABO data remains on that device until you clear it. Provider keys and i64 keys can be removed independently at any time. Prompts sent directly to a Hugging Face inference endpoint are handled under Hugging Face's own retention practices, not ours.
You can access a machine-readable copy of account data, remove a provider key, sign out, and permanently delete the account from Account settings. Depending on the applicable law, you may also request access, correction, restriction, objection or portability and lodge a complaint with the CNIL. Requests are handled without undue delay and normally within one month.
The service uses an authentication cookie required to keep you signed in. Authenticated LABO workspaces are stored in the account-scoped server database; guest workspaces are temporary and are not persisted in browser storage. No advertising cookies are set by Complexity. Third-party links and embedded services may apply their own policies.
Material changes will be reflected on this page with a new update date. If a change requires a new choice from you, it will be presented before the affected processing begins.