KEYSTONE Companion · Crown Mosaic Platform
KEYSTONE Privacy & Data Retention
Last updated: May 2026
This page explains how KEYSTONE, the conversational companion bound to your Crown Mosaic Platform diagnostic, handles your data: what is stored, how long it is kept, who can see it, and how to delete it. KEYSTONE is bound to your specific bound volume and nothing else. For general site privacy, see the Crown Mosaic privacy policy.
What we collect
When you use KEYSTONE, we collect:
- Conversation content: your questions, KEYSTONE’s answers, and the citation metadata that ties answers back to your bound volume.
- Session metadata: session timestamps, access-window expiry, tier, and the session identifier that scopes your data to you.
- Cost telemetry: per-question processing cost, for billing and service integrity.
- Anonymized cohort signals: derived structural signals (for example industry cluster or constraint code) with no direct identifiers, used only in aggregate.
We do not collect direct identifiers inside cohort data, browser fingerprints, IP-based behavioral analytics, or payment details beyond a processor reference.
How we use your data
Operationally, we use your data to answer your questions from your specific bound volume, to keep your conversation available within your access window, to bill correctly, and for quality review by Christopher Millson. In anonymized aggregate, cohort signals help improve KEYSTONE’s framework. We do not train Anthropic’s or any other AI model with your conversations, we do not sell or share your data, and we do not use it for advertising.
Data retention
Your conversation data is retained only for as long as it is needed to serve you:
| Data class | Retention | Access |
|---|---|---|
| Active conversation | Your 90-day access window (subscriptions refresh each quarter) | You and Christopher Millson |
| Post-window archive | A limited archive period after your window ends, then permanently deleted | Christopher Millson only |
| Session and billing metadata | Retained for billing and audit | Christopher Millson only |
| Anonymized cohort signals | Retained in aggregate (no personal data) | Internal analytics only |
| Cost telemetry | Up to 7 years (financial record-keeping) | Christopher Millson and accountant |
Deleting your data
You can request permanent deletion at any time. Email christopher@christophermillson.com with the subject “KEYSTONE memory deletion request” and your engagement reference. Your conversation data is permanently deleted within 7 business days and you receive an email confirmation. Data is also removed automatically at the end of its retention period. Deletion is permanent; there is no restoration after a permanent purge.
Data sharing
We do not share your conversation data with third parties, with three operational exceptions:
- Anthropic processes your questions and bound-volume context transiently to generate answers, and does not retain the content for training.
- Stripe handles payment information for billing only; no conversation content is shared.
- Cloudflare R2 stores your bound volume PDFs behind time-limited signed links; no conversation content is stored there.
For valid legal requests, we comply where legally required, resist overbroad requests, and notify you unless legally prohibited from doing so.
Your rights
- Access and portability: request an export of your conversation data in a standard format.
- Deletion: request permanent deletion at any time.
- Correction: flag any answer that seems wrong; the framework is reviewed and iterated.
- Object: opt out of anonymized cohort-signal contribution without losing any KEYSTONE features.
To exercise any of these, contact christopher@christophermillson.com.
Security
Your data is encrypted in transit and at rest. The operator audit used for service quality is restricted to Christopher Millson. Each session is scoped by a private identifier that prevents any other client’s data, or name, from appearing in your session.
Changes to this policy
We update this page when a material change affects how KEYSTONE handles data, when regulations change, or when an operational detail changes. For material changes, subscribers receive 30 days’ notice by email. The date at the top reflects the most recent revision.
Contact
Questions about KEYSTONE privacy or data retention:
christopher@christophermillson.com