- We collect what we need to answer your enquiries and run Shelob: contact details you give us, usage records, technical logs, and the places and searches you use the service for.
- We do not sell personal information or share it for advertising, our code sets no cookies, and we use no analytics or advertising trackers.
- Our servers are in Australia. Our service providers are in the United States and the European Union, and are listed below.
- You can ask to see, correct or delete your information at hello@shelob.ai.
Who we are and what this covers
Shelob is operated by Iterators Pty Ltd, an Australian company ("Iterators", "we", "us"). This policy covers the website at shelob.ai, the app and Studio at app.shelob.ai, the REST API, the MCP service, the Shelob skill and exports (together, "Shelob"). For the personal information described here, Iterators is the controller: the APP entity under Australian law, and the business under US state laws.
We handle personal information in accordance with the Australian Privacy Principles in the Privacy Act 1988 (Cth), and, where they apply to us, the EU and UK General Data Protection Regulation and US state privacy laws, including the California Consumer Privacy Act.
What we collect
When you contact us
- Frontier AI enquiry form: your name, work email, company or lab, role, intended use, timeframe, priority locations, stack or delivery requirements, and your description of what you need. We also record when you submitted it and the country your request came from, as determined from your IP address by our hosting provider.
- Email: whatever you include when you email us, including your name, email address and message.
When you use the app and Studio
- The app has no sign-in, and we do not create an account for you.
- The searches you run, the coordinates and areas you look at or draw, and the pages you open are processed to answer you. Many of these travel in web addresses, so they appear in our access logs with your IP address and browser details.
- Collections and saved dataset shortlists are kept in your browser's local storage. They are not sent to us.
- Maps are drawn by third-party map providers (section 5), which receive your IP address and the map areas you view.
When you use the API
- Your API key identifies your plan. We store only a one-way hash of it for rate limiting and monthly usage counting, with your plan and usage totals.
- Requests are logged with the calling address, the route and its query parameters, and the response status.
- We keep the customer and billing details needed to issue and manage your key and plan.
When you use the MCP service
- You sign in through Cloudflare Access, using a sign-in method we have enabled. Cloudflare receives your email address or other sign-in identifier and your IP address to authenticate you, and records each sign-in in logs that we can view.
- Cloudflare then gives your AI client a signed access token. From it we use a subject identifier, the client identifier, scopes, expiry and issuer. We do not read your email address from the token, and we keep only a shortened one-way hash of the identifier, briefly, to apply rate limits.
- The questions and places your AI client sends to Shelob are processed to answer them and appear in our access logs.
When you watch places
- The labels and areas you choose to watch, their change history, the webhook addresses and signing secrets you configure, and records of webhook deliveries. Change notifications are sent to the webhook address you set.
What we do not collect
- We use no analytics, advertising or cross-site tracking tools.
- We do not ask for sensitive information, such as health, biometric or financial account details. Please do not include it in an enquiry or in your content.
- The app does not ask for your device's location.
How we use it, and our legal bases
| Purpose | Legal basis (EU and UK GDPR) |
|---|---|
| Responding to enquiries and preparing agreements | Steps at your request before a contract; our legitimate interest in answering enquiries |
| Providing Shelob: searches, API and MCP calls, watching places, webhooks | Performance of our contract with you or your organisation |
| Authentication, rate limits, usage counting and billing | Performance of contract; our legitimate interest in protecting the service |
| Security, abuse prevention and operational monitoring | Our legitimate interest in a secure, reliable service |
| Understanding and improving Shelob from usage records and logs | Our legitimate interest in developing the service |
| Enforcing our terms, and establishing, exercising or defending legal claims | Our legitimate interest in protecting our rights |
| Record-keeping and complying with the law | Legal obligation |
| Product news and marketing emails | Your consent, which you can withdraw at any time |
We may also create aggregated or de-identified information from what we collect, such as usage volumes and performance statistics, and use it for any lawful purpose. It does not identify you.
We do not make decisions about you based solely on automated processing that produce legal or similarly significant effects.
International transfers
Shelob's servers are in Australia. Our service providers process information in the United States, the European Union and other countries where they operate, so your information may be transferred outside the country you are in.
For personal information from the EU, UK or Switzerland, we rely on appropriate safeguards. Cloudflare and Google are certified under the EU-U.S. Data Privacy Framework, its UK Extension and the Swiss-U.S. Data Privacy Framework. For other transfers we rely on the European Commission's Standard Contractual Clauses or the UK equivalent where our providers offer them, or on another lawful mechanism. For transfers out of Australia, we take reasonable steps to ensure our providers handle personal information consistently with the Australian Privacy Principles.
How long we keep it
| Information | How long |
|---|---|
| Enquiries and emails that do not lead to an agreement | Up to 2 years after our last contact |
| Customer correspondence, agreements and billing records | For the relationship, then up to 7 years for legal, tax and accounting obligations |
| Website operational logs (Cloudflare Workers) | Up to 7 days |
| Access logs on our servers: IP address, browser details and requested URLs, which can include search terms | Size-limited rotating logs, overwritten as new entries are written |
| MCP sign-in records held by Cloudflare Access: your email or sign-in identifier and IP address | As set by Cloudflare’s retention for Access logs |
| Rate-limit records: hashed key, IP address or MCP identifier | About 1 minute |
| Monthly usage counts per API key | Until 7 days after the end of the month |
| Watched places, change history, webhook settings and delivery records | Until you delete them, or 30 days after your access ends |
| Collections and shortlists saved in your browser | In your browser until you clear them; we never receive them |
| Database backups containing the service data above | Replaced as backups rotate; a deletion reaches the backups when the backup holding the data expires |
We may keep information for longer where the law requires it, to establish, exercise or defend legal claims, to enforce our agreements, or to prevent fraud and abuse. When we no longer need information, we delete or de-identify it.
Security
We take reasonable steps to protect personal information from misuse, interference, loss and unauthorised access, modification or disclosure. These include encrypted connections, storing API keys and identifiers only as one-way hashes, and limiting access to the people who need it. No system is perfectly secure. If a data breach is likely to result in serious harm, we will notify you and the relevant regulator as the law requires, including under Australia's Notifiable Data Breaches scheme and the GDPR.
Personal information in the Shelob catalogue
Shelob catalogues spatial data published by governments and other public sources, and every record keeps its source and licence. Some published datasets may contain information about identifiable people.
If you believe a record we serve contains personal information about you, email hello@shelob.ai with the record's Shelob identifier or source link. We will review it and may correct, restrict or remove it.
We do not use the catalogue to profile individuals, and our Terms of Service forbid customers from using Shelob to track or profile people.
Your rights
Everyone
You can ask for access to the personal information we hold about you, ask us to correct it, and ask us to delete it. We may decline or limit a request where the law allows, for example where we must keep information to meet a legal obligation, to protect legal rights, or where a request is manifestly unfounded or excessive, and we will tell you why. You can browse the website and use the app without identifying yourself; we need contact details to reply to an enquiry. To make a request, email hello@shelob.ai. We may need to verify your identity first, and we respond within a reasonable time, usually within 30 days.
Australia
You have rights of access and correction under the Australian Privacy Principles. If you are not satisfied with how we handle a complaint, you can contact the Office of the Australian Information Commissioner at oaic.gov.au.
European Union, United Kingdom and Switzerland
You have the right to access, rectify and erase your personal data, to restrict or object to our processing of it, to data portability, and to withdraw consent at any time where we rely on consent. You can complain to your local data protection authority, or in the UK to the Information Commissioner's Office. We respond within one month, which can be extended by two further months for complex requests.
California
To the extent the California Consumer Privacy Act applies to us, California residents have the right to know what personal information we collect, use and disclose; to delete it; to correct it; to opt out of its sale or sharing; and to limit the use of sensitive personal information. We do not sell or share personal information and do not use or disclose sensitive personal information, so there is nothing to opt out of or limit. We will not discriminate against you for exercising your rights. You may use an authorised agent; we may ask the agent for proof of authority and ask you to verify your identity. We treat a Global Privacy Control signal as a request to opt out of sale or sharing.
In the past 12 months we have collected the following categories of personal information, for the purposes in section 3, from you, your devices, your AI clients and our hosting provider:
| Category | Examples | Disclosed for a business purpose |
|---|---|---|
| Identifiers | Name, email address, IP address, API key (stored hashed), sign-in subject identifier | Yes, to our service providers |
| Professional or employment information | Company or lab and role, from enquiries | Yes, to our service providers |
| Internet or network activity | Pages and API routes requested, search terms, browser details, usage counts | Yes, to our service providers |
| Geolocation data | Country derived from IP address; coordinates and areas you search, draw or watch (these describe places, not your own location) | Yes, to our service providers |
| Commercial information | Plan and usage records | Yes, to our service providers |
| Sensitive personal information | Not collected | Not applicable |
Other US states
If you live in a US state with a comprehensive privacy law, such as Virginia, Colorado, Connecticut, Utah, Texas or Oregon, you may have rights to access, correct, delete and obtain a copy of your personal data, and to opt out of targeted advertising, sale and profiling. We do not sell personal data, use it for targeted advertising, or profile people in ways that produce legal or similarly significant effects. If we decline your request, you may appeal by emailing hello@shelob.ai with "Appeal" in the subject line. We will respond within the time the law requires, and if you disagree with the outcome you may contact your state Attorney General.
Children
Shelob is intended for adults and businesses and is not directed at children. We do not knowingly collect personal information from anyone under 16. If you believe a child has given us personal information, contact us and we will delete it.
Changes to this policy
We may update this policy. The date at the top shows when it last changed. If we make a material change, we will take reasonable steps to tell customers, such as by email or in the service, before it takes effect.
Contact
Iterators Pty Ltd
Email: hello@shelob.ai
