Terms of Service

Version 2026-07-18 · Effective 2026-07-18

What Cairn is

Cairn is a bi-temporal memory service. You store messages and derived timeline events; Cairn answers from those records. It is not a general chatbot and does not invent history from model weights when your archive has no matching record.

Your account

You must provide a working email address and verify it before using product features. You are responsible for keeping your password confidential and for activity under your account. You must be able to form a binding contract where you live; we do not knowingly offer the service to children under 13.

Documents you upload

You can upload PDFs. Cairn reads the text and derives timeline events from it. If a page has no text layer — a scan or a photographed page — it is read by optical character recognition (OCR) that runs on our own servers using the open-source Tesseract engine. No third party sees the file for OCR.

The uploaded file itself is not kept, and neither is the document as a whole. What is kept is the file name, the events derived from the document, and for each event the passage it was read from — the table row or sentence that produced it, which is what later answers quote and cite. Text that produced no event is not retained anywhere, so a document cannot be re-read or re-extracted once it has been processed.

The document’s text is sent to a model provider while it is being processed, to find dates and events in it — the narrative and the rows of any table alike. Each table row is turned into a sentence and read individually, so a long table means many separate reads. See the Privacy Policy for who processes what, and when.

One part is not left to the model: a record’s date is taken from the document’s own text rather than inferred — which makes it the document’s date and not a guess, but not necessarily the right one, because Cairn can read it from the wrong cell. A date Cairn cannot read produces no record at all rather than a guessed one. What the row means — its title, its type, the details — is the model’s reading of it, and can be wrong in the ordinary way any reading can be wrong.

Cairn does not store the prompts it sends or the responses it receives — only a count of calls made.

A record states what the document asserted. Cairn does not check an assertion against the rest of the document, or against anything else in your archive. If a report’s narrative says a site is clear while its own table says otherwise, Cairn records the narrative and will repeat it back to you with a citation. Citations show what your archive records, not that the record is correct — they establish where a statement came from, not whether it is true. This matters most for documents you did not write yourself.

Acceptable use

You agree not to:

  • Attempt to access another user’s timeline or circumvent access controls
  • Abuse email ingest, verification, or other automated endpoints
  • Upload unlawful content or content you do not have rights to store
  • Reverse engineer or disrupt the service except as allowed by law

Plans and billing

Published prices are on the pricing page.

Payments are non-refundable, including for partial periods. Cancelling stops future billing; it does not refund the current period. This does not affect refund or cancellation rights you have under applicable law.

Published prices are on the pricing page.

Your content

You retain rights to the content you submit. You grant Cairn a limited license to store, process, and display that content solely to operate the service for you (extraction, retrieval, export formats you request, and related operations described in the Privacy Policy).

How long we keep your data

Indefinitely, until you delete it. Cairn does not expire, archive, or age out your records on a schedule — a memory layer whose contents quietly disappeared after a year would not be one. There is no retention period to configure and none running in the background.

Deletion is yours to trigger, at two granularities: a single message and everything derived from it, or the whole account. Both are described in the Privacy Policy, including the parts that survive and why.

Service changes and availability

We may change or discontinue features with reasonable notice when practical. The service is provided “as is.” We aim for reliability but do not guarantee uninterrupted availability.

If Cairn stops running, your archive is portable and you do not need us to get it. Settings → Export all data produces a single JSON file containing your messages, the events derived from them, their projects, links and corrections, with original and recorded timestamps preserved, plus your answer history and its citations. Every export carries a manifest — a count of each collection and a SHA-256 digest of the contents — so you or anyone you hand the file to can confirm nothing was lost or altered, using the file alone, without asking us.

Export works today and is not conditional on a wind-down. We recommend taking one whenever the archive matters to you. The Privacy Policy states exactly what the export covers, what it does not, and what the manifest does and does not prove.

Limitation of liability

To the fullest extent permitted by law, Cairn and its operators are not liable for indirect, incidental, or consequential damages, or for loss of data beyond our obligation to use reasonable care. Nothing here limits rights that cannot be waived under applicable law.

Contact

Questions about these terms: support@cairn-ai.com.