Skip to main content
Nocturne Engine Logo Nocturne Engine
Home How It Works Commands GitHub
Workspace
arrow_back Back to Home
shield Privacy Policy description Terms of Service

Contents

  • 1. Overview & Scope
  • 2. Data We Collect
  • 3. Private Inference
  • 4. Storage & Media
  • 5. Zero-Log Sandboxing
  • 6. Cookies & Storage
  • 7. Rate Limits & Security
  • 8. Third-Party Services
  • 9. Age (16+) & Rights
  • 10. Contact & Updates
lock Data Transparency

Privacy Policy

Nocturne Engine is an open-source project committed to developer privacy. Here is exactly how your data, private model inferences, and sandboxed tools are handled.

calendar_today Last updated: October 2026 tag Version 2.4 verified_user Community Open Source
security
Private Compute Guarantee: Inferences on the official hosted instance run on private, self-hosted model backends. Your prompts and chats are never routed to commercial cloud providers for training or telemetry, and all tool execution is completely ephemeral with zero query logging.

01. Overview & Community Scope

This Privacy Policy applies to the official hosted instance of Nocturne Engine ("we", "us", or "the platform"), accessible via nocturne.darkfast.uk, its web chat workspace, and official Discord bot deployments.

Nocturne Engine is maintained strictly as a community open-source software project without a corporate legal entity. The platform is provided free of charge for experimentation, developer workflows, and personal use.

If you clone the repository to self-host your own instance of Nocturne Engine, you manage your own database, API keys, and compute resources; this policy applies specifically to the services hosted under the official domain.

02. Information We Collect

We collect only the bare minimum data required to deliver core chat and agent capabilities:

  • Account Identity: When logging into the Web Workspace, we authenticate your identity via Firebase Authentication using Google Sign-In. We store your public email address, display name, and avatar URL to identify your account and isolate your conversations. We never see or store passwords.
  • Prompts & Messages: The text prompts, queries, and instructions you submit to the model via the web chat console or Discord slash commands (/chat).
  • Multimodal Media: If you attach images to your prompts, they are processed in-memory and compressed with Sharp to optimize token count and streaming efficiency.
  • Discord Context: When interacting with our Discord bot, channel IDs and guild IDs are referenced to route responses to the correct channel and apply per-channel model presets (/model).
  • Operational Diagnostics: Temporary in-memory connection states and rate limiting counters to protect servers against DDoS and brute force.

03. Private Self-Hosted Inference

Unlike conventional AI frontends that proxy your queries to proprietary commercial cloud APIs, the official hosted instance of Nocturne Engine connects to self-hosted local model instances (such as llama.cpp or vLLM) deployed on private infrastructure.

  • Your prompts, generated code, and outputs remain exclusively on our private servers during generation.
  • We do not sell, rent, or distribute your conversations or personal data to advertisers, data brokers, or commercial LLM vendors.
  • Your conversations are never used to train foundational AI models.

04. Data Storage & Media Retention

Conversation history, generated session titles, and attached media are stored in a SQLite database on the server:

  • Retention Period: Conversation data is retained indefinitely until you manually delete it. This ensures you can review past conversations and resume work across sessions.
  • Media Lifecycle & Cleanup: Images uploaded for multimodal vision queries are tied directly to their parent conversation. When a conversation is deleted, all associated image data is immediately and permanently purged from database records.
  • Encrypted in Transit: All communications between your browser, Discord, and our backend are encrypted via modern TLS (HTTPS and Secure WebSockets).
  • User-Driven Deletion: You retain complete control over your conversation history. Deleting a conversation immediately drops the records from active storage.

05. Zero-Logging Sandboxed Tool Execution

Nocturne Engine features agentic capabilities, allowing the model to run JavaScript code or fetch live web information:

  • Isolated V8 Sandboxing: Untrusted code evaluations execute in memory-bounded isolates via isolated-vm (128MB limit) with strict CPU execution timeouts (1500ms). Sandboxed code has zero access to the host machine's filesystem, network, or environment variables.
  • Zero Query & Code Logging: Tool executions are completely ephemeral. We do not retain persistent logs of code executed inside the sandbox, nor do we log search queries dispatched to external search providers. Everything exists in memory only for the duration of the request.

06. Cookies & Browser Local Storage

Nocturne Engine adheres strictly to European ePrivacy Directive standards. We do not use tracking cookies, advertising pixels, or third-party behavioral analytics.

We use strictly necessary, functional browser storage to operate the interface:

  • nocturne-theme: Stores your light or dark mode visual preference in browser localStorage.
  • nocturne_auth_hint: Stores a lightweight session indicator to eliminate interface flicker while authentication states are resolving.
  • Firebase Auth Token Cache: Maintained in browser IndexedDB and localStorage solely to preserve your active authenticated login between page reloads.

07. Security Telemetry & Rate Limiting

To maintain system stability and prevent denial-of-service (DDoS) abuse, our backend API employs automated in-memory rate limiting (via express-rate-limit):

  • Client IP addresses are processed in volatile server memory solely to track request frequencies and block malicious automated bursts under legitimate security interest.
  • IP addresses are not permanently stored in the database, are never joined with user conversation transcripts, and are discarded after rate-limiting windows expire.

08. Third-Party Integrations

To deliver auxiliary services, minimal technical requests may be made to external platforms:

  • Firebase / Google Identity: Used strictly for secure user authentication into the web console.
  • Discord Gateway (Discord Inc.): Facilitates slash command handling and message dispatching within Discord.
  • Search Tools (Tavily, Giphy): If you or the model explicitly trigger a live web search or GIF lookup, the specific query term is dispatched to the respective API to retrieve results.

09. Age Requirement (16+) & User Rights

In compliance with European Union General Data Protection Regulation (GDPR) digital consent standards, Nocturne Engine is intended strictly for users aged 16 and older. We do not knowingly collect personal data from individuals under the age of 16.

As a user, you hold complete autonomy over your personal data:

  • Delete Conversations: You can delete any chat thread from the web workspace sidebar at any time.
  • Flush Discord Context: Running the /reset command in any Discord channel immediately clears conversational short-term memory for that context.
  • Full Account Wipe: You may request full deletion of your user account and all associated database records by opening a request on our GitHub support channel.

10. Contact & Policy Updates

We may update this Privacy Policy as new capabilities are released. Meaningful changes will always be accompanied by an updated date at the top of this page.

For questions, privacy inquiries, or data wipe requests, please open an issue on our official GitHub repository.

© 2026 Nocturne Engine - Open Source ISC License

GitHub Web Console Privacy Terms