The public site is simple
No analytics software, ad tracker, embedded chat, outside font request, or browser-storage requirement. The animations run in your browser. On load, the page asks the API for the seat count; that request carries no cookie and no personal data.
The contact form has a fixed audience
Send a message and the API stores what you typed: name, email, organisation, the message, and the time it arrived. The operator reads it in the admin view of the console; only addresses on the operator's admin list can open that view. The operations digest to idgafholdingsllc@gmail.com every two days carries a count, not the text.
Retention and deletion
Messages are kept while we may still need to answer them, and as our record of what was asked. Write to idgafholdingsllc@gmail.com to have yours deleted; we answer within thirty days and say what we did. Do not send credentials, proprietary payloads, or regulated data.
Hosted services
Accounts and API access are open at app.afaprotocol.com. Before the first sign-in code, the console shows three agreements the API serves with their version and hash: the beta terms, the acceptable use policy, and the privacy notice for the service. The record there holds structural fields and one-way digests, never raw prompts, code or secrets. The service privacy notice, with its version and content hash, is at privacy-notice.html, and the legal page lists all three. How the agreements are served