Trust
Legal
What INFAIX Core actually does with your information, written from the code rather than from a template — including the parts that are still undecided.
Documents
What applies to you.
These documents describe the service as it is built today, not as it is planned.
Your controls
What you can actually do.
Every control here works today, inside INFAIX. Controls that do not exist are labelled as gaps rather than shipped as buttons.
How this is written
Verified, or marked as undecided.
Every factual claim in these documents maps to something in the codebase. Where a fact was missing, the text says so instead of filling the gap.
Verified
Checked against the database schema, the Worker routes, and the behaviour the tests pin down. Storage, lifetimes and access rules are described as they actually are.
Marked, not guessed
Where a fact was missing, the document carries a marked item naming the question, and the collection below says who has to answer it. A gap is never smoothed over with plausible wording.
Kept true automatically
The service-status table in the Terms is generated from the same registry that drives the product directory, and the policy versions the signup form sends are the ones the server checks. Neither can drift away from what is running.
Outstanding
32 items awaiting owner, legal or product work.
Nothing in this list is a defect in the running product. Each one is a judgement or a missing feature that has been recorded rather than guessed at.
- OWNER DECISION REQUIRED
- 14Only INFAIX can settle these, usually with a business answer or counsel.
- LEGAL REVIEW REQUIRED
- 13Drafting questions for a lawyer. The text is left open rather than guessed.
- PRODUCT GAP
- 4A control the product does not have. Listed as a gap, never shipped as a control that does nothing.
- IMPLEMENTATION UNKNOWN
- 1The code does not establish the fact either way, so no claim is made.
Who INFAIX is, and who to ask
Nothing below is answered in the published documents, because nothing in the codebase answers it.
Identity of the entityOWNER DECISION REQUIREDlegal-entity
What is the full legal name of the entity that operates infaix.com, and what is its registered address?
As built: No legal entity, company number or address appears anywhere in this repository. The site identifies itself only as the INFAIX brand.
Privacy contact channelOWNER DECISION REQUIREDprivacy-contact
Which email address and postal address receive privacy requests, and who is the named data protection contact?
As built: Transactional mail is sent from noreply@infaix.com, which by name is not a monitored inbox. No monitored address exists in the repository.
Applicable regimeLEGAL REVIEW REQUIREDregime
Is INFAIX subject to the GDPR / UK GDPR, and if so which regulator is the lead supervisory authority?
As built: Unknown, and it depends on the entity and its establishment. The copy below is deliberately regime-neutral.
Lawful basisLEGAL REVIEW REQUIREDlawful-basis
For each processing purpose, which lawful basis applies, and is consent required for any of them?
As built: The implementation records what it does but not why it is lawful. Account creation relies on the person performing the act; newsletter consent is explicitly recorded as a consent event.
International transfersIMPLEMENTATION UNKNOWNtransfers
In which countries are the hosting, database, email and AI services located, and what transfer mechanism covers them?
As built: The code names the providers but stores no region, transfer mechanism or adequacy decision. A Cloudflare Workers/D1 account and a Resend account each resolve to a real region once created.
Processors and sub-processorsLEGAL REVIEW REQUIREDprocessors
Which organisations are formally engaged as processors, under what written terms, and are they listed anywhere public?
As built: Four services are reachable from the code: Cloudflare (hosting, database, edge), Resend (transactional email), an AI gateway behind AI_GATEWAY_URL, and the sibling Chat and Study products reached by signed handoff. Contract status is not recorded here.
Minimum ageOWNER DECISION REQUIREDage
What is the minimum age to hold an INFAIX account, and is an age assurance step required at signup?
As built: There is no age gate in the signup flow. Any person with a deliverable email address and a valid invitation-free signup can currently create an account.
How long data is kept
The system has no deletion jobs today. These are the periods that still need choosing.
Retention: legal acceptance recordsOWNER DECISION REQUIREDlegal-acceptance-retention
How long are legal acceptance records kept, and does deletion of an account erase the record of what was accepted?
As built: Registration writes one row per acknowledgement with the terms version, privacy version, source and timestamp. The table has a cascade from the account, so deleting the user row would remove it, but no deletion path exists yet and no retention rule is defined.
Retention: account dataOWNER DECISION REQUIREDretention-accounts
How long is account data kept after an account is closed, and what happens to it on deletion?
As built: There is no account deletion endpoint and no deletion job. Disabling an account cuts access immediately but leaves the row in place.
Retention: audit logOWNER DECISION REQUIREDretention-audit
How long are security and audit events retained?
As built: audit_log rows have no expiry and no pruning job. They are the evidence base for incidents and for account recovery, so the period is a real risk trade-off.
Retention: single-use tokensOWNER DECISION REQUIREDretention-tokens
How long are spent invitations, password resets and email verification rows kept?
As built: Consumed and expired token rows are status-flagged rather than deleted. There is no cleanup job.
Retention: sessions and countersOWNER DECISION REQUIREDretention-sessions
How long do expired sessions and rate-limit counters remain in the database?
As built: Sessions carry a 30-day sliding expiry and the schema is indexed for expiry pruning, but no scheduled job performs it. Rate-limit counters are equally unpruned.
Retention: newsletter recordsOWNER DECISION REQUIREDretention-newsletter
How long are newsletter consent records retained, including records of people who unsubscribed?
As built: Unsubscribing is a status change; the row is deliberately kept as a consent audit trail. The retention period for that trail is undecided.
Retention: AI conversationsOWNER DECISION REQUIREDretention-conversations
How long are AI conversations and messages kept, and is there a default deletion period?
As built: Conversations are scoped to the signed-in account and can be deleted one at a time through the product. There is no automatic expiry.
Retention: platform logsOWNER DECISION REQUIREDretention-logs
What log retention is configured at the Cloudflare edge, and does it match the audit and account retention decisions?
As built: Application logs are structured records written to the Worker log stream with no configured retention. Edge log retention lives in the Cloudflare dashboard and is not visible from the repository.
Controls that do not exist yet
Product gaps. They are listed as gaps rather than shipped as controls that do nothing.
Erasure requestsPRODUCT GAPerasure
How does someone request deletion of their data, and what is the response time?
As built: There is no self-service deletion control anywhere in the product. Until one exists, a request can only be handled manually.
Data exportPRODUCT GAPdata-export
Should people be able to download a copy of the data INFAIX holds about them?
As built: There is no export control. The account page shows profile fields inline, but that is a summary, not a portable copy of the record.
Access and rectification requestsPRODUCT GAPaccess-requests
What is the channel and deadline for a formal access or rectification request, distinct from using the product's own controls?
As built: The account page shows the stored profile and allows the display name to be corrected, which covers everyday use but is not a formal request mechanism.
Unsubscribing without an accountPRODUCT GAPmarketing-unsubscribe
How does someone who subscribed with only an email address — and never made an account — unsubscribe?
As built: Withdrawal is available to signed-in accounts from account preferences. A public, token-gated unsubscribe link is deliberately not implemented yet, because an ungated endpoint would let anyone remove anyone.
Communications and consent
What people can do for themselves today, and what still needs a channel or a decision.
Marketing send infrastructureOWNER DECISION REQUIREDmarketing-infrastructure
Which provider sends the newsletter, what is the double opt-in confirmation flow, and what is the sending frequency promise?
As built: Consent is recorded and stored as PENDING_CONFIRMATION, but no confirmation link and no marketing send path exist yet. Nothing is being sent. The transactional mailer is deliberately not reused for marketing.
Consent architecture for optional technologyOWNER DECISION REQUIREDconsent-architecture
If analytics or any other non-essential technology is ever introduced, what consent gate and which prior blocking are required before it loads?
As built: There are no analytics, advertising or tracking scripts in the codebase, and no consent state is stored in the browser. Nothing is gated because nothing optional is loaded.
Terms that need drafting decisions
Provisions that cannot be written honestly without a commercial or legal choice.
Termination and suspensionLEGAL REVIEW REQUIREDterms-termination
What are the notice periods and the grounds for suspending or terminating an account, and what happens to the account's data?
As built: An administrator can disable an account, which removes access immediately, including from live sessions. There is no notice mechanism and no deletion step.
Limitation of liabilityLEGAL REVIEW REQUIREDterms-liability
What liability cap and what exclusions apply, and do any carve-outs for consumer law or wilful misconduct have to be preserved?
As built: No liability position exists in the code. Nothing has been written into the terms on this point because a cap must be chosen deliberately, not defaulted.
Warranty disclaimerLEGAL REVIEW REQUIREDterms-warranty
How far can INFAIX disclaim fitness and availability, and which statutory warranties cannot be disclaimed?
As built: Several products in the ecosystem are marked planned and beta. The disclaimer below states the general position and is marked for review rather than hardened.
Intellectual property and user contentLEGAL REVIEW REQUIREDterms-ip
What licence, if any, is granted over content submitted to INFAIX products, and is the licence exclusive, perpetual or royalty-free?
As built: AI conversations are stored against the signed-in account so the product can work. No licence grant or feedback-licence term is implemented anywhere.
Trademarks and brand useLEGAL REVIEW REQUIREDterms-trademarks
Is there a trademark policy restricting use of the INFAIX and FORGE names and marks?
As built: The brand and its marks are owned by INFAIX. No permitted-use or restricted-use list is defined.
Availability commitmentsLEGAL REVIEW REQUIREDterms-availability
Is there any service level commitment for live products, and is it clearly separated from planned and beta products?
As built: Live products carry no uptime promise anywhere in the codebase. Planned products have no availability at all.
Governing law and forumOWNER DECISION REQUIREDterms-governing-law
Which law governs these terms, and which courts have jurisdiction?
As built: Unknown. It follows from the entity decision, so nothing has been written in.
Acceptable use detailLEGAL REVIEW REQUIREDterms-acceptable-use
Is there a separate acceptable use or AI usage policy, and should it be incorporated here or published separately?
As built: No automated use policy exists. The section below states a baseline drafted from the service's purpose and is marked for review.
AI output noticeLEGAL REVIEW REQUIREDai-output-notice
Does INFAIX AI need a product-specific notice about generated output, and what must it say?
As built: INFAIX AI is live but restricted. The service is proxied to a separate model gateway, and the terms state no position on generated output accuracy, fitness or downstream reliance. A generic disclaimer would not settle it.
Product-specific termsLEGAL REVIEW REQUIREDproduct-terms
Will Study, Atlas and Shop carry their own terms when they launch, or do these terms cover them?
As built: All three are planned and not operating. INFAIX Shop in particular is not a working service and nothing on this site invites anyone to buy from it.
Commerce compliance, before Shop launchesLEGAL REVIEW REQUIREDshop-commerce-compliance
Before INFAIX Shop takes a first order, which consumer, tax and payment obligations will it meet?
As built: Shop is planned and not operating, so no refund, shipping, payment or subscription terms have been written. Pricing and consumer guarantees, Australian Consumer Law handling, shipping, taxes, payment processor terms, PCI scope and the business contact details all remain undefined by design.