Updated September 6, 2026. This notice covers the public Guth Labs website at guthlabs.ai. Guth Labs LLC operates this site. Contact us at legal@getguth.com with privacy questions or requests.
When you browse
Cloudflare hosts and protects this website. It processes network information such as IP addresses, requested pages, request times, browser information, and security signals to deliver pages, prevent abuse, and provide traffic reports. We use those reports to understand site traffic, including crawler requests. This processing supports our legitimate interests in running and securing the website.
This website does not load advertising pixels, session recording, or optional browser analytics scripts. Our interactive product examples run in your browser and use sample information. They do not send prompts to AI providers.
Cookies and browser storage
Local storage is information saved by this website in your browser. Our privacy notice lets you choose essential storage only or also remember your appearance preference. Both choices let you use the whole public website.
| Item | Purpose | Duration |
|---|---|---|
| guth-site-privacy-v1 | Remembers your privacy choice; no visitor identifier. | Choice expires after 180 days. You can clear it sooner. |
| guth-site-appearance | Remembers light or dark mode only if you choose “Remember appearance.” | Used while that choice is valid; removed if you switch to essential only. |
| Cloudflare security cookies | Cloudflare may use cookies when a security challenge or other protection requires them. | Depends on the protection used; see Cloudflare’s cookie information. |
We do not use these choices as permission for advertising or analytics tracking. You can reopen here or in any page’s footer. Choosing essential only withdraws permission to save appearance. You can also clear site storage through your browser. Previously saved records may remain in browser storage until overwritten or cleared, but an expired choice is not used.
When you contact us
The contact form prepares an email in your email app. It does not submit your message to our website. If you send the email, we receive your address and whatever information you include, and use it to answer your request and discuss possible work. Please do not send passwords, confidential customer records, or sensitive personal information in an initial inquiry.
We use our business email provider, Google Workspace, to handle correspondence. We keep correspondence while needed to respond, manage agreed work, and meet applicable record-keeping obligations. You can ask us to delete an inquiry that is no longer needed; legal obligations or an ongoing dispute may require some information to be retained.
Providers and international processing
Cloudflare and our email provider may process information in countries other than yours under their applicable service terms and data-protection arrangements. Read Cloudflare’s privacy policy and Google’s privacy policy for their practices. Following an external link takes you to a site with its own privacy terms.
Your rights
Depending on where you live, you may have rights to access, correct, delete, restrict, or object to the use of your personal information, or to receive a copy. You may also complain to your local data-protection authority. Email legal@getguth.com to make a request. We may need to confirm your identity before acting on it.
Account sign-in
The public field guides, instruments, and website remain available without an account. Existing Guth account holders can sign in to the account page. New account registration and payments are not enabled on this website. Existing account holders can use Notebook to save notes and upload files.
When you sign in, our Cloudflare-hosted authentication service sends your email address and password to our account provider, Supabase, to verify your account. The website does not save your password. Your browser receives an essential, secure, HTTP-only session cookie. The server stores your user ID, a short-lived access token, an expiry time, and a request-protection token in Cloudflare Durable Objects so it can verify protected requests.
The website session expires when its access token expires, with an eight-hour maximum. It cannot renew itself in the background. Session records are scheduled for deletion at expiry and removed on sign-out; provider infrastructure may retain operational backups under its own retention policies. Guth account records remain with Supabase separately from this website session. Signing out of this website does not delete your Guth account.
We limit sign-in requests using the connecting IP address to prevent abuse. Account access does not enable optional advertising or analytics tracking. See Supabase’s privacy policy for its practices. Apps and connected services have their own data uses and notices.
Notebook cloud library
Notebook uses the same website session to read and save your account’s notes, folder memberships, file metadata, version records and linked agent notebooks in Supabase. Uploaded file contents are stored in a private Supabase Storage bucket. The website verifies your account before issuing short-lived upload or download links for a specific file. Cloudflare handles these account-scoped requests; your browser transfers file bytes directly to Supabase using those links.
Unsaved edits and selected upload bytes remain in this page’s memory while it is open. They are not stored as a browser draft, and closing or reloading the page can lose unsaved work. Successful saves remain in your cloud library and its version history after sign-out. Linking a note or file to an agent records its destination; it does not prove that the agent has read or processed it. The web preview does not yet provide account-wide export or deletion controls; contact us for help with those requests.
Private reference catalogues can contain resource descriptions, filing categories and source locators. They are visible only through the associated account. A catalogue entry is a reference, not a copy of its source file. Imported app workspace archives are stored as original private files, including any drafts, version history and embedded content in the archive. The web reader does not activate links, run embedded code or automatically sync separate device files.
Agent API authorization
An existing account holder can approve a registered software client to read our public guide catalog through OAuth. This permission does not grant access to private notebooks, messages, or account records. We store client names, redirect addresses, owner identifiers, grants, and token records in a dedicated Cloudflare KV namespace to operate this authorization. Client registration expires after 24 hours; access tokens expire after 15 minutes and cannot be refreshed. Grant metadata may remain until revoked or removed. We use the connecting IP address to limit registration and token requests.
Clients can revoke tokens using the endpoint documented in our authorization instructions. Revocation may take time to propagate between locations. Signing out ends your browser session and does not revoke previously issued API tokens. Public browser tools send requests without account cookies and display the result on the page.
Owner-claimed agent access
An agent may request a temporary registration using an account email address. This does not create a human account or reveal whether that email is registered. We keep the email hint and hashes of the claim handles and confirmation code in a Cloudflare Durable Object for up to ten minutes. The existing account holder must sign in with the matching confirmed email and type the code to claim the request. We do not send a confirmation email for this flow.
On claim, we remove the email hint and code hash and retain the owner user ID, registration state, expiry, and token acceptance hashes for at most one hour. Expiry cleanup removes these identifying and credential-verification fields; infrastructure backups may follow provider retention policies. Provider client and grant records also use the OAuth storage described above. Access tokens last at most fifteen minutes, and the service assertion can obtain replacement tokens only within the original one-hour registration lifetime.
The owner can revoke the whole registration from its management URL. Agents can revoke individual tokens. Each registration token is checked against its live registration state before accessing the public guide API, so a revoked registration cannot continue through a stale provider token record. These permissions do not create a notebook, mailbox, or access to private data.