1. Overview
This Privacy Policy explains how Ruby Peaks Digital Solutions LLC (“we,” “us,” or “our”) collects, uses, and shares information when you use CFR30 (the “Service”). CFR30 helps users research selected Title 30 CFR Metal/Nonmetal mine regulations, including through AI-assisted chat and related tooling.
2. Information we collect
Depending on how you use the Service, we may process:
- Chat and query content. Questions, messages, and related prompts you submit to the assistant.
- Technical data. IP address, browser type, device information, timestamps, and basic usage/log data from hosting and security layers.
- Account or contact information if you provide it (for example, email when requesting support).
- Configuration data for operators of a deployment (API keys and environment settings), which should be stored securely and not shared with us unless you intentionally provide them for support.
We do not intentionally collect special categories of sensitive personal data. Please do not submit personal information about miners, medical details, or confidential business data that is not necessary for your research question.
3. How we use information
We use information to:
- Provide, operate, and improve the Service;
- Retrieve relevant regulation excerpts and generate responses;
- Maintain security, prevent abuse, and troubleshoot issues;
- Comply with legal obligations; and
- Communicate with you about the Service when you contact us.
4. AI processing and retrieval
When you use chat or search features, your query may be:
- Converted into an embedding and compared against our indexed regulation corpus stored in a database (currently Supabase / PostgreSQL with vector search);
- Sent to a third-party large language model provider (for example, OpenAI, Anthropic, or Google, depending on configuration) to generate a response;
- Combined with retrieved CFR excerpts so the model can cite and summarize relevant sections.
Model providers process prompts and may retain limited operational logs according to their own policies and your contractual settings with them. We configure the Service to support research use; we do not sell your chat content.
5. Regulatory corpus
The Service indexes publicly available Code of Federal Regulations content obtained via eCFR developer APIs. That corpus is government publication text, not your personal data. Citations and links may point back to eCFR.gov.
6. Sharing of information
We may share information with:
- Service providers that host infrastructure, databases, analytics, or AI models needed to run CFR30;
- Professional advisors or authorities when required by law or to protect rights and safety;
- Successors in connection with a merger, acquisition, or asset transfer, subject to appropriate safeguards.
We do not sell personal information.
7. Cookies and similar technologies
The Service may use essential cookies or local storage required for security and basic functionality. If we add optional analytics cookies later, we will update this Policy and, where required, request consent.
8. Data retention
We retain information only as long as needed for the purposes described above, including security, debugging, legal compliance, and Service improvement. Chat logs (if stored) may be deleted or anonymized on a rolling schedule or upon verified request, subject to legal holds. Indexed CFR content is retained to operate retrieval features.
9. Security
We use reasonable administrative and technical measures appropriate to the nature of the Service, including access controls and encrypted transport (HTTPS). No method of transmission or storage is completely secure. You are responsible for protecting API keys and deployment credentials under your control.
10. Children’s privacy
The Service is intended for business and professional use and is not directed to children under 13 (or under 16 where applicable). We do not knowingly collect personal information from children.
11. Your rights and choices
Depending on where you live, you may have rights to access, correct, delete, or export personal information, or to object to certain processing. To make a request, contact us using the details below. We may need to verify your identity before responding. If you use a self-hosted or organization-managed deployment, your organization may be the controller for that instance—contact your administrator first.
12. International transfers
Providers we use may process data in the United States or other countries. Where required, we rely on appropriate transfer mechanisms offered by those providers.
13. Changes to this Policy
We may update this Privacy Policy from time to time. The “Last updated” date will reflect the latest revision. Continued use of the Service after an update means you acknowledge the revised Policy.
14. Contact
Privacy questions about CFR30: Ruby Peaks Digital Solutions LLC. For privacy requests related to a specific deployment, include enough detail for us to locate relevant records.