Skip to main content
Project Golden Age wolf
Project Golden AgeKnowledge Vault
HomeAboutGulaqSupport UsDownload gulaq
Project Golden Age

gulaq

Data Safety

A plain English summary of what data gulaq stores, where it is stored, and what is never collected or uploaded.

Effective: June 24, 2026

Short version: Your AI chats, workspaces, and vault files stay on your device. Supabase receives only account metadata, plan status, device info, and privacy-safe event codes — never the contents of your vault.

Data Stored on Your Device (Local)

Data typeWhere storedUploaded to cloud?
Saved AI conversations (messages, prompts, responses)Local SQLite vault on your SSDNo
Chat exports (JSON, Markdown)Your local filesystemNo
Browser workspace data (tabs, windows, groups, pinned states)Local SQLite vault + chrome.storage.local cacheNo
Tab URLs and window geometry for saved workspacesLocal SQLite vaultNo
Local backup archivesYour local filesystemNo
Extension settings and preferenceschrome.storage.local / chrome.storage.syncOnly settings via chrome.storage.sync if enabled (Chrome-managed)

Data Sent to Supabase (Cloud)

Data typeWhyContains private vault content?
Account email and Supabase user IDAuthentication and account identificationNo
Google account ID (from OAuth)Google login supportNo
Auth session tokensMaintaining signed-in stateNo
Account / plan status (gulaq is currently free)Feature accessNo
Device registration (app/extension versions, OS)Device management and version-aware featuresNo
Feature flag requestsRemote feature configurationNo
Privacy-safe event codes (e.g. save_chat_success)Service reliability and feature usage trackingNo — event codes only, never chat text
Redacted error codesBug detection and reliabilityNo — error codes only, never private content

Data We Do Not Collect

The following data is never collected or uploaded by gulaq:

What is NOT collectedDetails
AI chat text, prompts, and responsesAll conversation content stays in your local vault
Full tab URLs or browser historyTab URLs saved only locally; no URL history is sent to cloud
Tab titles or workspace namesStored locally only
Browser cookies or session tokens for AI platformsgulaq does not have the cookies permission and cannot access these
Passwords or form dataNot requested, not accessible by the extension
Local vault database fileSQLite file stays on your SSD; never uploaded
Exported JSON / Markdown chat filesExport files stay on your local filesystem
ScreenshotsNot captured or sent anywhere
Google Gmail, Drive, or Calendar dataGoogle login requests only basic profile scopes
Data from websites outside the AI platform listContent scripts only run on 6 explicitly listed AI platform domains

Third Parties We Share Data With

gulaq shares only the account and operational data listed above with the service providers below. Your private vault content (AI chats, prompts, responses, workspaces, exports) is never shared with any of them.

Third partyWhat is sharedPurpose
Supabase, Inc.Account email, user ID, auth session tokens, device/version metadata, plan status, privacy-safe event/error codesAuthentication, accounts, device management, analytics
Google LLC (OAuth)Google basic profile (name, email, account ID) at sign-in“Sign in with Google” identity verification
Vercel Inc.Standard web-request metadata (IP, user agent) when visiting the websiteHosting the public website and legal pages
Payment provider (future)Billing/transaction data, only if paid tiers launch. Card details never touch gulaqProcessing payments for future paid features

Optional desktop AI features (off by default) may send chat text you choose to your own AI provider using your own API key — see the Privacy Policy for details.

Is User Data Sold?

No. Project Golden Age does not sell user data to third parties. We do not share identifiable user data with advertisers or data brokers.

Advertising

gulaq does not use advertising networks within the Chrome extension. The extension does not run AdSense or any third-party ad SDK. If sponsored content is introduced in future versions, it will not use private vault content for targeting and will be clearly disclosed.

Security

  • Supabase service role keys are never included in the client extension or desktop app.
  • Row Level Security (RLS) ensures users can only access their own Supabase records.
  • Local vault content is only accessible via native messaging to the local desktop app — it is not exposed to the internet.
  • The extension Content Security Policy prevents external script injection.

Data Questions

Contact: backtothegoldenage@gmail.com

Full details: gulaq Privacy Policy · Delete Account & Data

Project Golden Age
Project Golden Age

Reviving the builder spirit of civilization through AI, knowledge, and creation.

Local-first · Privacy by design

Company

  • Home
  • About
  • Contact
  • Support Us

Products

  • gulaq
  • Install

Legal

  • Privacy Policy
  • Terms of Use
  • Contact

gulaq Policies

  • Privacy Policy
  • Terms of Use
  • Permissions
  • Data Safety
  • Support
  • Delete Account
  • CWS Disclosures

© 2026 Project Golden Age. All rights reserved.

Built local-first