SystemLens
Privacy Policy
This policy explains what SystemLens collects, why it is used, when it is shared, and the choices available to you. SystemLens chat sends your messages to the model providers described in Section 4; core workspace features remain available when chat is unavailable.
Effective July 13, 2026 · Version 1.0
1. Who operates SystemLens
Regenerative Constructs LLC, a Massachusetts limited liability company, operates SystemLens. In this policy, “SystemLens,” “we,” and “us” refer to Regenerative Constructs LLC. Questions or privacy requests may be sent to reggie@regco.tech.
2. Information we collect
- Identity and account data: your verified Google subject, verified email, basic profile fields returned by Google, internal user ID, role, session state, and optional two-factor status.
- Membership data: your verified Whop subject and email, company/product/plan identifiers, membership status, provider event identifiers and times, and commercial events needed to activate, suspend, or reconcile access. Payment-card details are handled by Whop, not stored by SystemLens.
- Workspace data: profile details you choose to provide, context and corrections, tasks, knowledge items, reviews, check-ins, saved results, support requests, access requests, and approved context-manifest references.
- Security and operations data: session and enrollment records, network addresses used for rate limiting and waitlist abuse prevention, timestamps, audit events, error classes, and service-health records. We do not need your password from Google or Whop.
- Communications: information you send when asking for help, requesting access, or otherwise contacting us.
3. How we use information
We use information only as reasonably necessary to:
- authenticate you, link verified identities, and prevent silent account merges;
- confirm Whop membership and provide the matching SystemLens entitlement;
- create, operate, personalize, secure, and support your workspace;
- process your corrections, requests, and reviewed context-seeding jobs;
- enforce allowances, feature gates, tenant isolation, and high-risk step-up checks;
- detect misuse, investigate errors, preserve audit evidence, and comply with law; and
- improve the service using operational and feedback information that we are permitted to use.
We do not treat unknown information as fact. Where the workspace displays an inference, it should be labeled so you can correct or remove it.
4. AI and model providers
You are talking to an AI agent. When you chat with your agent, what you write is sent to third-party model-hosting providers (today, routed via OpenRouter to OpenAI models) that generate the response on our behalf. Documents you connect may also be embedded for search using a hosted embedding model.
These providers act as our processors — providers of generative AI model-inference and embedding services, located in the United States. Which one serves a given message can vary by model and by automatic routing.
Under their commercial terms your inputs and outputs are not used to train their models. Retention is a separate matter and we will not overstate it: providers keep conversation data for a limited period — commonly up to 30 days — for abuse monitoring, longer if a conversation is flagged for safety review, and some models we use are not eligible for zero-retention at all. If you want to know which provider handled your data, ask and we will tell you.
Providers change as models improve. We keep a current internal record of every provider that processes your data, and will name the ones handling yours if you ask. If a change would alter what happens to your data — a new purpose, training use, or longer retention — we will tell you before it takes effect rather than changing this policy quietly.
Generated material may be incomplete or wrong. It is assistance, not medical, legal, financial, or other professional advice.
5. When information is shared
We may disclose the minimum information needed to the following recipients:
- Google for authentication under Google’s own privacy terms;
- Whop for identity linking, membership, checkout, cancellation, and commercial records under Whop’s own privacy terms;
- Infrastructure and support providers that host, secure, transmit, back up, or help operate SystemLens under appropriate access limits;
- Generative AI and embedding providers that produce your agent’s responses;
- Email delivery providers so your agent can send you its introduction and any message you ask it to send;
- Authorities or affected parties when reasonably necessary to comply with law, protect rights and safety, investigate abuse, or secure the service; and
- A successor organization in a merger, financing, reorganization, or sale, subject to appropriate confidentiality and notice where required.
We do not sell personal information or use private workspace content for cross-context behavioral advertising as part of the initial SystemLens service.
6. Cookies and local device storage
SystemLens uses first-party, security-oriented cookies for Auth.js sessions, a bounded enrollment journey, OAuth state/PKCE, and two-factor verification. Enrollment and OAuth cookies are HttpOnly where designed so browser scripts cannot read the underlying token. The initial membership flow does not add third-party advertising trackers. Blocking required cookies can prevent sign-in or enrollment from working.
7. Retention and deletion
Pending enrollment records are designed to expire within 24 hours. We retain account, membership, workspace, security, support, and audit records for as long as needed to provide the service, preserve customer data through a membership interruption, meet security and accounting obligations, resolve disputes, and comply with law. Different records have different operational and legal retention needs; backup deletion may lag behind deletion in the live service.
You may request account or workspace deletion by contacting us. We will verify the request and explain records we must retain. Deleting SystemLens data does not by itself cancel a Whop subscription; commercial cancellation must also be completed through Whop.
8. Your choices and rights
- review and correct context, including removing information or correcting an inference;
- enable optional two-factor authentication and manage your Google or Whop authorization separately;
- request access, correction, deletion, or a portable copy where applicable;
- request human review of an access, suspension, or context decision; and
- decline optional connectors, outbound actions, or experimental previews.
Rights differ by location. We may need to verify your identity before completing a request, and authorized agents may be asked for proof of authority.
9. Security, children, and international access
We use access controls, encrypted transport, secret separation, audit records, provider signature checks, and tenant-scoped authorization intended to protect information. No system is perfectly secure, so we cannot guarantee absolute security.
SystemLens is not directed to children under 18, and we do not knowingly create Launch Pass accounts for them. If you believe a child provided information, contact us. The service is operated from the United States; access from elsewhere may involve transfer and processing in the United States and other locations used by approved providers.
10. Changes and contact
We may revise this policy as SystemLens changes. We will update the effective date and, when a change is material, provide notice appropriate to the service and applicable law. Contact reggie@regco.tech with questions or requests.