Privacy
What we receive, and what happens to it
This page covers the goca assistant — in the goca console and on our support page — support tickets, and the forms on go-ca.org.
Who to contact
Write to dev@go-ca.org for anything on this page, including deletion.
The assistant in the goca console
The assistant panel in the goca console (and in its demo) sends your messages to go-ca.org from your browser. They do not go through your goca installation, and your goca installation never contacts us. We receive:
- the email address you enter in the panel;
- your messages, and the earlier messages of the same panel conversation;
- whether you are in the console or the demo, the name of the console page you are on and, when you are signed in, the goca version;
- what every browser sends with a request: your IP address, the address of the page the request comes from, your browser's user agent and preferred language.
We never receive goca credentials or goca data — no login token, no CA names, certificates, keys or configuration — other than what you type into a message yourself. That is a property of the goca client, which sends only the fields listed above; we state it here so you can rely on it.
Your console's address. The address of the page a request comes from is your console's own address, which is often an internal hostname. Our software does not store it: it is not written to our database, and it does not appear in the copies of conversations we keep. If we ever need it, it will be used only for abuse handling and rate limiting, kept for at most 30 days, and never published, sold or used to identify customers for marketing.
The address you enter is not verified. It is how we tell conversations apart, how we apply usage limits, and where a ticket's confirmation link goes if the assistant files one for you.
The support page chat
The chat on our support page asks you to verify a work email address with a one-time code first. We receive that address, your messages, any text log file you choose to upload when the assistant asks for one, and what your browser sends with a request (as above).
What we use it for
- Answering you. An AI model writes the assistant's answers from the goca documentation.
- A copy for the goca team. A copy of assistant conversations, with the email address, goes to a private channel of the goca team, so that bugs, abuse and wrong answers can be caught.
- Tickets. When the assistant files a bug report or feature request for you, its title and status history are public at an unguessable link; the report body and your address are not.
- Limits and abuse. Your email address and IP address are used to apply usage limits and to block abuse.
- Improving goca. Conversations may be used to improve goca, its documentation and the assistant, including to train our AI models.
Email we send
Only mail you asked for or that belongs to something you started: a verification code you requested; for a ticket, its status changes (from the console, only after you confirm the one confirmation link we send); a decision on a download request. No newsletters and no marketing. Creating an assistant session sends no mail.
How long we keep it
- Conversations, tickets and email addresses: kept until you ask us to delete them.
- IP addresses in our rate-limit records: deleted by routine cleanup after one day.
- Console assistant sessions: valid for at most two hours; the record is deleted by routine cleanup one day after that.
Who processes it for us
- Cloudflare — hosts go-ca.org, its database and its bot protection (Turnstile).
- The AI model behind the assistant — run by us or by a provider we use. Conversations are sent to it to produce each answer.
- Telegram — carries the copy of support conversations to the goca team, and the team's notifications.
- Resend — sends our email.
- The assistant itself runs on a machine operated by the goca team.
Cookies
The assistant, in the console and on our site, sets no cookies and reads none. The only cookie our own code sets is the sign-in cookie of the architect track of the training center. Cloudflare, which hosts the site, may set its own security cookies as part of its bot protection.
Having your data deleted
Email dev@go-ca.org from the address in question and ask. No account is needed — there are none. We delete within 30 days.