Trust
Who can reach your data, every company that processes it, everything stored on your device, and what happens to all of it if this company stops. Written to be checked rather than believed.
Last updated 22 August 2026
Who can read your notes, in the first person
What I can tell you is what I actually do. I have never opened anyone's graph out of curiosity, and I don't open one to see how the product is being used, to build a case study, or to find something to sell. The only reason I would look is a specific problem you have reported to me, for as long as that takes and no longer. If that ever needs to happen, I would rather ask you first.
I would rather you didn't have to take my word for any of it, which is what the rest of this page is about.
How many people can reach your data: 1
Every personal CRM has this number and almost none of them publish it. At a funded competitor it is some quantity of employees, support agents and vendors that nobody will tell you, and it grows every time they hire. Ours is on this page, and it changes here in the same commit that grants anybody else access — which is the only version of this promise worth making, because it is the one you can check later.
When someone does look, it leaves a mark — and where that stops
Now the limit, because a control you have misunderstood is worse than one you know the edge of. That log covers the admin panel, and the admin panel has no screen anywhere in it that displays a contact, a note or a fact — it shows accounts, plans and credit balances. Reaching the actual contents of your graph means going to the database directly, and that route is not covered by the log above. I would rather say so plainly than let a real control imply a wider promise than it makes.
Closing that gap is the next piece of work on this page: production credentials that live behind a separate break-glass step rather than in a daily shell, and a named database role whose sessions are logged the way the admin panel already is. When it ships, this paragraph changes.
What is not true, and won't be claimed here
Dhaga holds no SOC 2 report, no ISO 27001 certificate and no HIPAA attestation — do not store protected health information here. When one of those exists it will be named on this page with the date and the auditor, and until then nothing on this site will imply otherwise. The privacy page goes through the same ground in more detail.
Every company that touches your data, by name
| Company | What it does | What it sees | Where |
|---|---|---|---|
| Supabase | The primary Postgres database and its vector index | Your full graph — contacts, notes, facts, edges, embeddings | AWS ap-southeast-2 (Sydney) |
| Vercel | Application hosting, plus the two measurement scripts | Request metadata and redacted page paths. Never graph contents | Global edge; functions in Vercel's default region |
| Anthropic | The models behind extraction, search answers, drafts and briefs | The note text and contact fields an AI action is about | United States |
| Resend | Reminder, digest and transactional email | Your own email address and the message we send you | United States |
| Razorpay | Payments for customers billed in rupees | Billing identifiers, amount, plan. Never your graph | India |
| Stripe | Payments for customers billed outside India | Billing identifiers, amount, plan. Never your graph | United States |
Adding one is a 30-day-notice event — this table changes before the data moves, not after. Worth stating plainly: your graph rests in Sydney, not in India, so an Indian data-residency requirement is not met by Dhaga Cloud as it stands and needs the single-tenant deployment enterprise customers arrange with us instead.
Everything Dhaga stores on your device
| Name | Where | What it is for | Why no consent | How long |
|---|---|---|---|---|
| Better Auth session | Cookie | Keeps you signed in. HttpOnly, so no script can read it | Strictly necessary | Until you sign out or it expires |
| dhaga_signed_in | Cookie | A yes/no hint so the header renders signed-in controls without a flash. Carries no identity and grants no access | Strictly necessary | Mirrors the session |
| dhaga-price-currency | Cookie | The currency you picked on the pricing page | Preference you set | 1 year |
| Theme | Local storage | Light or dark, if you overrode your system setting | Preference you set | Until you clear it |
| Graph layout cache | Local storage | Node positions and view state, so your graph opens where you left it instead of recomputing. Positions only — never names | Strictly necessary | Until you clear it |
| Dismissals | Local storage | Which tour steps, banners and hints you have already closed, so they stay closed | Preference you set | Until you clear it |
| Time-zone notice | Session storage | That you dismissed the time-zone mismatch prompt for this browser session | Preference you set | This tab session |
| Analytics opt-out | Local storage | Set only if you turn measurement off. It exists purely to honour that refusal, which is what makes it necessary rather than optional | Strictly necessary | Until you clear it |
What we measure, and how to switch it off
[id], so what leaves your browser is /app/people/[id] — never who, and never what you typed into a filter.Because they store nothing on your device, they need no consent. They do need an off switch, which is this one:
Measure how this site performs
Checking your preference…
It takes effect immediately and covers the in-app performance beacon too. It is remembered on this device rather than on your account, deliberately: the person most likely to want it is reading this page without an account, and should not have to make one to refuse.
Leaving, and what deletion actually removes
Deleting a contact cascades through everything derived from it: notes, facts, graph edges and search index entries, rather than leaving orphaned copies behind. Deleting a note removes the facts extracted from it. Deleting your account removes the lot.
The honest footnote is backups. Dhaga Cloud keeps daily database backups and does not run point-in-time recovery, so a deleted record is gone from the live database immediately and persists in a backup only until that backup rotates. We are confirming the exact rotation window with our database host and will state it here rather than estimate it. Backups are encrypted, are never browsed, and exist only to restore the service after a failure.
If Dhaga is ever acquired, your data is not part of the deal
If Dhaga shuts down, you get warning and a working export
Reporting a security problem
Report in good faith and we will not pursue you — that means giving us 90 days before publishing, not accessing or altering data belonging to anyone but yourself, and not running attacks that degrade the service for other people. There is no paid bounty yet; there is credit on this page if you want it. The machine-readable version of this lives at /.well-known/security.txt.