RabbitSoftware Back to project overview

Website privacy policy / effective October 8, 2026

Website privacy policy

Website operator: Chase Allen Ringquist, RabbitSoftware. Contact: [email protected]. This policy covers the website and its hosted research tools, not the unrecovered original application.

This describes the recovered website's browser controls, not the missing original application's privacy policy or a guarantee about third-party services.

Reading the website

Pages and assets are served through Cloudflare. Requests necessarily reach the hosting service. Cloudflare may apply security checks, email protection, or analytics configured by the site owner. This page does not promise that hosting services collect no request metadata.

Hosted Research AI

Opening chat or typing a question does not send that question to the model. Each message requires a fresh approval. Editing the question, closing chat, or leaving Research AI resets approval.

After approval, your question, recent conversation from this tab, and the published research summaries are sent through the Cloudflare gateway to RabbitSoftware's Hugging Face hosted model. Cloudflare and the model provider process these requests; their service policies also apply. Provider retention and training practices have not been independently verified during website recovery.

Do not send personal, identifying, genomic, or biosignal data. The page blocks some common patterns before sending, but this check can miss sensitive information. Research answers are unverified and are not medical advice.

rabbit-web public web research

Each approved question in rabbit-web goes through a separate Cloudflare Worker to Tavily basic search. The question and up to five returned public snippets then go through the existing gateway to the Hugging Face model. Opening the page or typing never starts a search. No chat history or opened local records are included.

Source snippets are untrusted and can contain inaccurate content or malicious instructions. AI summaries are unverified. Tavily's and the hosting/model providers' policies also apply; their retention and training practices have not been independently verified.

The research Worker stores a UTC month counter and recent search-attempt times associated with a SHA-256 hash of the visitor's network IP, not query text. Hashing is pseudonymization, not anonymity. Times older than an hour are removed on the next admitted reservation; a new UTC month resets quota state on its first reservation. Until then, quota metadata remains stored. Provider and hosting request metadata may still be retained independently. Clearing the page does not erase provider requests.

Public corpus lookup and local chain files

The separate research corpus and local chain viewer keeps these operations distinct. Its metadata-only public corpus snapshot is served as a same-origin static website asset and searched locally in the current tab. Query text is not sent to the public API or AI. The checked public API does not permit cross-origin browser reads; the viewer avoids that CORS boundary rather than proxying searches or changing a Worker. Static asset requests still reach the website host.

The site owner can regenerate the public metadata snapshot with scripts/build-public-corpus.ps1. The script reads public corpus batch endpoints over HTTPS and includes only source, external identifier, title, source URL, and publication date. It excludes abstracts, arbitrary record fields, and account archives. The snapshot is limited to 1 MiB and 1,000 records; update time is displayed by the viewer.

Local JSON files are opened only after the visitor selects one, parsed in the current tab, and limited to 1 MiB. File contents are not uploaded, sent to an AI provider, or sent to the corpus API. DNA-format files are treated as private/potentially private, and their account identifier is never rendered. Other files' declared public classifications are not independently verified. Closing the file clears its displayed content from the page, but cannot erase the original file or hosting/request metadata.

Local chat and downloads

The page keeps conversation messages in the tab's memory. It does not automatically save them to browser storage. Clearing chat removes the displayed conversation and local research records from this page's memory; it does not erase requests already sent to a provider or files you downloaded.

Plain-text downloads are not encrypted. Optional encrypted-record downloads use AES-256-GCM and PBKDF2-SHA256 with 600,000 iterations. Passphrases are used in the browser and are not included in hosted questions. Opened records are read-only and are never added to model prompts.

The reconstructed record module supports only new recovery-format records. Preserve historical encrypted files unchanged. If you lose a passphrase, this page cannot recover it.

Links and local tools

The downloadable local browser agent listens only on 127.0.0.1. Offline mode makes no provider requests; each consented research search sends only the typed public query to Europe PMC or Tavily over HTTPS. Local records are never sent. Optional Tavily keys are entered through a hidden terminal prompt and kept in process memory until exit, not saved to disk or displayed in the browser. The agent keeps hourly attempt times in memory, cleared on restart, and creates no browser storage or persistent application history. Browser history and terminal scrollback may remain. Europe PMC privacy notice and Tavily's policy apply to provider requests.

The current read-only CLI download (v0.2.1) is delivered through Cloudflare like other files. Its local mode reads only the explicitly selected local file or bundled synthetic demo and makes no network requests. Optional public corpus and signed-account modes make read-only GET requests; no records are uploaded and the CLI does not send questions to AI. Signed-account access has not been verified with a user's device file. The CLI does not log a user into this website, which has no direct account login. It does not store a chat history. Terminal output may remain in terminal scrollback. Its declared public-record check is not a complete sensitive-data detector.

External links and email links open another service or your mail application. This site does not receive or forward reports sent through the listed reporting channels. It cannot inspect your terminal, private vault, or local chains, and it does not publish your chat to a chain.

Original policy and questions

To ask about your data, access, correction, or deletion, email the operator without sending private datasets. Clearing this tab removes its displayed results, not provider-held requests or downloaded files. The operator cannot promise deletion of third-party records outside their control. Provider policies: Cloudflare, Tavily, and Hugging Face. Applicable rights depend on your jurisdiction and the relevant provider.

The original application's privacy policy has not been recovered. Check project status for that limitation. For website questions, email [email protected]; do not include private datasets, credentials, or health records.