Privacy
Updated 11 October 2026.
Gullible is built to hold as little data as possible. There are no accounts, no cookies, no analytics and no advertising.
Who is responsible
Inari Suite, an individual acting in a non-professional capacity and established in the European Union, publishes Gullible and is the controller of the data described here. Write to inari-suite@proton.me for any question about your data.
What we process, and why
- Network data of each request. Your IP address, your User-Agent and the fetch headers your browser or agent sends. The server uses the IP address for one thing: a hash of it, salted and changed every day, held in memory, which limits how many sessions and requests one client can make per hour. It is never written to disk and the server keeps no access log. From the User-Agent we keep only a coarse family, such as a browser and its major version or the name of an AI fetcher, never the full string. Purpose: running the service and preventing abuse. Legal basis: our legitimate interests (article 6(1)(f) of the GDPR).
- Session data. A random session identifier, the page template and seed, the times of the visits and of the requests a trap received, the coarse User-Agent family, and the verdicts. Nothing in it names you, and we do not know who started a session. Purpose: showing you the results and measuring how AI agents behave. Legal basis: our legitimate interests.
- Text you paste. On the results page you may paste your agent's answer. The server looks for a code word in it and keeps only the yes or no. The text itself is not stored. A form on a trap page may also carry text typed by a visitor: the server reads only its reference field and discards the rest.
- Shared results. A share link shows a public summary: the agent family, the counts and the verdicts. It holds no identifier, and it is deleted after 30 days.
- Your messages. If you write to us, we use your address and your message to answer, and keep them for as long as the exchange needs and no more than 12 months after it ends.
What we do not do
We set no cookies and use no local storage. We run no analytics, no advertising and no profiling, and we do not sell or share data. The fonts are served from our own pages, so your browser contacts no third party to display them.
Who receives data, and where it goes
The application and the trap pages currently run on a server of linveo, LLC outside the European Union, for a private test period. Before the public launch we move them to a provider in the EU, under a data processing agreement. Until then, your IP address and request data reach a server outside the European Economic Area, and we have no data processing agreement with this provider.
The public showcase (landing page, methodology, about and legal pages) is served by GitHub Pages. GitHub receives the IP address and request data of its visitors under its own privacy statement. The same goes for the source code, issues and pull requests, which live on GitHub.
How long we keep it
- Sessions and everything attached to them: 90 days, then they are deleted.
- Shared results: 30 days.
- The daily hash of an IP address: in memory only, replaced every day and lost when the server restarts.
- Database backups: about two weeks.
Your rights
You may ask to access, correct or delete your data, to restrict its use, or to object to it (articles 15 to 21 of the GDPR). Because we store no name, no IP address and no other identifier, we usually cannot tell which records are yours (article 11). If you send us the link of a results page, we can find that session and delete it.
You may also complain to the CNIL, the French data protection authority, or to the authority of the country where you live. We take no decision about you by automated means.