Privacy
What this website records
This site uses no third-party analytics, no advertising and no tracking cookies. The only cookie is set when the site administrator signs in.
Visitor analytics
When a page is requested, the server records the page path, the time, the HTTP status, the response time,
the country reported by the network edge, the referring site, and the campaign parameters
utm_source, utm_medium and utm_campaign if they are present.
Other query parameters are discarded.
The analytics database does not contain your IP address. Instead the server derives a pseudonymous key from your address, your browser's user-agent string and the current month using a keyed hash. The key changes every month and cannot be reversed into an address. It lets us count approximate returning visitors within a month without identifying anyone. The same key, and never the address, is what the server writes in its own log lines about downloads.
Requests that look like automated crawlers are stored with a bot flag so they can be separated from human traffic.
Operational logs
The site runs behind Cloudflare on a server operated by DuNovo AB. Like every web service, those two systems keep short-lived connection logs that include the connecting IP address, used only to keep the service running and to investigate abuse. They are separate from the analytics described above, are not joined to it, and are not used to profile visitors. Cloudflare's own retention is set by Cloudflare's privacy policy; the origin server's connection logs are kept only as long as troubleshooting and abuse investigation need them and are then deleted.
Retention
- Detailed page-view records are deleted after 400 days.
- Pseudonymous visitor keys are deleted once no page-view record refers to them.
- Daily, non-identifying totals per page and country are kept indefinitely.
- Crash reports sent from the application are deleted after 400 days.
- Thank-you messages sent from the application are kept indefinitely.
Downloads
Download files, including the optional AI model bundles the application fetches, are delivered through a content delivery network. Requests that reach our server are counted as download intents by file, and as approximate model bundle fetches by pseudonymous key; requests served from the network edge are not visible to us.
Crash and bug reports
If Cadri Commander hits an error it cannot recover from, it shows a dialog that asks whether to send a crash report to this website. Nothing is sent unless you press Send report. The dialog shows the complete report before you decide, and you can add a comment, save the report as a file or close the dialog without sending.
You can also use Help → Send bug report… without a crash. It includes your issue description and the same runtime information, without an exception. A report contains:
- for a crash, the error: the exception type, its message, the call stack and the chain of inner errors that led to it;
- the application: its version, whether it is a beta build, how long it had been running and which window it was in;
- the machine: the Windows version and build, the processor architecture, the .NET runtime version, the number of processors, the display count and scaling, the system language and whether the process was elevated;
- the application's own state: memory in use, thread count, which native components were loaded, and a handful of non-identifying settings (colour theme, one or two panes, view mode, which AI provider kinds are configured — never the endpoints or keys);
- your issue description or crash comment;
- your e-mail address, only if you fill in the optional contact field, so we can reply about the report. This address is preserved as entered, shown in the preview and included in local copies; it is not added to operational logs.
Before the report is shown to you, the application replaces file paths, URLs, IP addresses, your Windows user name
and anything shaped like a password, token, key or authorization header with placeholders such as
[path-1]; your description gets the same treatment when it is added. The optional contact e-mail is the explicit exception: it is kept so we can reply. The application never puts the
contents of your documents, their names, your folder names or anything the AI features indexed into a report on
purpose; the replacements are a text filter that catches the common shapes an error message may quote, not a
guarantee for every possible one. That is why the dialog shows the complete report, exactly as it will be sent,
so you can check it before you press Send.
A received report is stored on the origin server as one JSON file, together with the time it arrived, the
application's user-agent string and the country reported by the network edge. The sending IP address is not
written to the file. The server's own log records that a report arrived — its identifier, the application
version, the exception type and the country — in the same operational logs described above. Reports are read
by DuNovo AB to fix the bug and are deleted after 400 days. Each report carries a random identifier
so that a retried upload replaces nothing and creates no second copy. The application keeps a local copy of the
newest twenty reports its dialog showed you, sent or not, in its data folder under crash-reports.
Thanks sent from the application
The application's Help menu and About window have a button, Send thanks to the developer. Nothing is sent unless you press it. Pressing it sends the application's version number to this website, and we record it together with the time, the country the delivery network reports for the connection, and a keyed hash of your IP address. The hash lets us count a returning sender once and ignore a second press within five minutes; the address itself is not stored, and the hash cannot be turned back into it without the server's secret key. The service also accepts an optional short message, which the current application does not send. These records are kept indefinitely.
The Cadri Commander application
- No usage telemetry on a normal launch. The application does not report usage, settings or anything about your files. Diagnostic telemetry exists for troubleshooting and is sent only when you start the program with the
--otelcommand-line option and point it at a collector you choose. - Crash and bug reports are optional. The crash dialog and Help menu can send reports to this website as described above. Nothing is sent unless you choose to send it.
- Thanks are sent only when you press the button. Send thanks to the developer sends the version number as described above, and nothing else.
- Optional language models are downloaded on request. The AI features stay off until you configure them. A model bundle is downloaded only when you explicitly start that download, in the model setup wizard or in Settings, and it is fetched from this website.
- Remote AI providers see what you send them. If you configure a role (embedding, chat or reranking) to use a hosted provider, the text of the documents in the folders you allow for AI is sent to that provider under your own account. Roles set to Internal run on your PC and send nothing.
- Links to this website. The application links to this website for help, release notes and downloads. Following a link is an ordinary visit and is recorded as described above.
Contact
Questions about this policy go to support@dunovo.com. Cadri Commander is made by DuNovo AB.