Sponge
Sponge privacy
Sponge keeps your library, documents, and research private until you choose to share or publish. This page lists what stays private, what becomes visible, and what analytics collect. It is not a substitute for a later legal policy if Sponge publishes one.
Private work and sharing
Documents, Inquiries, graph records, agent proposals, and accepted research effects remain private unless a separate public boundary is satisfied. A human can accept a proposal into a private research graph. Public encyclopedia use requires a second promotion review, eligible rights, an exact supported edition, explicit publication enablement, and a deliberate release.
A named member receives bounded access to a shared document or block only after sign-in and a live grant. The link alone does not grant access. A published document or block is a deliberate read-only checkpoint. Later private edits do not rewrite the published revision.
Only a reviewed artifact from a space with publications explicitly enabled can receive a public /k release locator. Discovery of those pages never guarantees ranking or citation.
Anonymous analytics
Public analytics on sponge.computer are limited to anonymous, cookieless page and error health on the canonical host, plus the campaign tags (such as utm_source) on the link that brought you to a public page. Private document and account locators are collapsed, and campaign tags on private pages are dropped. Sponge does not capture editor content, chat, search text, identity, replay, or broad DOM interaction in that analytics contract. Analytics waits for your acceptance where the regional policy requires it, or when the region is unknown. Elsewhere it can run without cookies before you respond. Declining stops analytics.
Agent memory
During semantic-memory shadow indexing, Sponge sends only bounded, rendered private source text to the EmbeddingGemma model through Cloudflare Workers AI. Cloudflare treats model inputs, outputs, and embeddings as Customer Content, and Sponge configures no Cloudflare storage for those requests. Derived vectors live in a separate Turso semantic cache and are purged with the working-memory session. Shadow results never alter recall ranking; canary and active semantic recall remain blocked.
The agent’s working memory for a document, the private notes it keeps for one conversation, is visible only to the document owner in the editor’s Memory panel. It expires with the session or when the owner chooses Forget now, and it is never shared, published, or used as evidence. See agent working memory.
Local source access
Hosted paper monitoring, paper sign-in, and browser notifications have been retired. Existing saved papers and passages remain private unless you deliberately share them. When you use GhostGet locally, it manages your browser credentials and service permissions. Sponge receives only the research material you choose to save.
Newsletter
If you use the footer newsletter form, your email address, your choice to subscribe to Sponge updates, the form source, and a short-lived Cloudflare Turnstile proof are sent to Hraness Accounts at account.hraness.com. Cloudflare verifies the anti-abuse proof. Hraness Accounts records dated consent and asks Resend to send a confirmation email from Sponge <newsletter@news.hraness.com> with the subject Confirm your Sponge subscription. You are not subscribed until you follow the confirmation link.
After confirmation, Sponge newsletters use the same product-specific sender and subjects beginning [Sponge]. Each newsletter includes a Sponge-specific unsubscribe link. Using it ends only the Sponge subscription without changing any other Hraness subscription. Submitting the form does not create a Suite account or grant Sponge workspace access, and the newsletter record remains separate from private research content.
Read sharing and visibility for the full public contract, or find product and account help.