PoietesCMD

Documentation

Privacy

PoietesCMD is software you run yourself. There is no PoietesCMD service that receives your data, and the people who wrote it have no access to an installation.

This site and the console

  • No analytics, no tracking cookies, no third-party scripts, no externally hosted fonts.
  • One cookie is set, after you sign in: the session cookie. It is required for the console to work.
  • The console's content security policy allows connections to its own origin only.

What an installation stores

Everything is in your PostgreSQL database and your data volume:

  • task instructions, plans, model answers, tool calls and their results;
  • files you upload to the workspace and artifacts tasks generate;
  • memory entries;
  • schedules and settings;
  • provider connections, with keys either referenced by environment variable name or stored encrypted;
  • the owner's password hash, session hashes, and an audit log that includes the network address of sign-in attempts.

Nothing is sent anywhere by the application except the two cases below.

What leaves your server

1. Requests to the model provider you chose. For each turn of a task, the worker sends the system prompt (rules, limits and the memory entries supplied to that task), the instruction, the tool definitions and the conversation so far, including tool results such as the contents of files the task read and pages it fetched. With a cloud provider this content is processed under that provider's terms and retention policy. With a local endpoint it goes to that endpoint and no further.

2. Requests made by fetch_url. When a task fetches a public page, the remote server sees your server's address and the URL. It is a plain GET request with a fixed user agent and no cookies.

Provider keys are sent only to the provider they belong to.

Deleting

  • A memory entry: removed from the database and from the saved context of tasks that used it. An audit line naming the entry stays with those tasks unless you choose to purge the title. See Memory.
  • A task: removes its transcript, events, approvals and checkpoints. You choose whether its artifacts are deleted too.
  • An artifact or a workspace file: the row and the file are removed.
  • A provider connection: its stored key is deleted with it.

Backups you made earlier still contain what was deleted later. See Backup and restore.

What was already sent to a model provider cannot be recalled from here. Check your provider's data controls.