Keystone Privacy

KEYSTONE Companion · Crown Mosaic Platform

KEYSTONE Privacy & Data Retention

Last updated: May 2026

This page explains how KEYSTONE, the conversational companion bound to your Crown Mosaic Platform diagnostic, handles your data: what is stored, how long it is kept, who can see it, and how to delete it. KEYSTONE is bound to your specific bound volume and nothing else. For general site privacy, see the Crown Mosaic privacy policy.

The short version
Your conversations are bound to your own session, visible only to you and Christopher Millson, never used to train any AI model, and never sold or shared. You can request permanent deletion at any time. Data is retained only for your access window plus a limited archive, then removed.

What we collect

When you use KEYSTONE, we collect:

  • Conversation content: your questions, KEYSTONE’s answers, and the citation metadata that ties answers back to your bound volume.
  • Session metadata: session timestamps, access-window expiry, tier, and the session identifier that scopes your data to you.
  • Cost telemetry: per-question processing cost, for billing and service integrity.
  • Anonymized cohort signals: derived structural signals (for example industry cluster or constraint code) with no direct identifiers, used only in aggregate.

We do not collect direct identifiers inside cohort data, browser fingerprints, IP-based behavioral analytics, or payment details beyond a processor reference.

How we use your data

Operationally, we use your data to answer your questions from your specific bound volume, to keep your conversation available within your access window, to bill correctly, and for quality review by Christopher Millson. In anonymized aggregate, cohort signals help improve KEYSTONE’s framework. We do not train Anthropic’s or any other AI model with your conversations, we do not sell or share your data, and we do not use it for advertising.

Data retention

Your conversation data is retained only for as long as it is needed to serve you:

Data classRetentionAccess
Active conversationYour 90-day access window (subscriptions refresh each quarter)You and Christopher Millson
Post-window archiveA limited archive period after your window ends, then permanently deletedChristopher Millson only
Session and billing metadataRetained for billing and auditChristopher Millson only
Anonymized cohort signalsRetained in aggregate (no personal data)Internal analytics only
Cost telemetryUp to 7 years (financial record-keeping)Christopher Millson and accountant

Deleting your data

You can request permanent deletion at any time. Email christopher@christophermillson.com with the subject “KEYSTONE memory deletion request” and your engagement reference. Your conversation data is permanently deleted within 7 business days and you receive an email confirmation. Data is also removed automatically at the end of its retention period. Deletion is permanent; there is no restoration after a permanent purge.

Data sharing

We do not share your conversation data with third parties, with three operational exceptions:

  • Anthropic processes your questions and bound-volume context transiently to generate answers, and does not retain the content for training.
  • Stripe handles payment information for billing only; no conversation content is shared.
  • Cloudflare R2 stores your bound volume PDFs behind time-limited signed links; no conversation content is stored there.

For valid legal requests, we comply where legally required, resist overbroad requests, and notify you unless legally prohibited from doing so.

Your rights

  • Access and portability: request an export of your conversation data in a standard format.
  • Deletion: request permanent deletion at any time.
  • Correction: flag any answer that seems wrong; the framework is reviewed and iterated.
  • Object: opt out of anonymized cohort-signal contribution without losing any KEYSTONE features.

To exercise any of these, contact christopher@christophermillson.com.

Security

Your data is encrypted in transit and at rest. The operator audit used for service quality is restricted to Christopher Millson. Each session is scoped by a private identifier that prevents any other client’s data, or name, from appearing in your session.

Changes to this policy

We update this page when a material change affects how KEYSTONE handles data, when regulations change, or when an operational detail changes. For material changes, subscribers receive 30 days’ notice by email. The date at the top reflects the most recent revision.

Contact

Questions about KEYSTONE privacy or data retention:
christopher@christophermillson.com