Privacy policy.
This policy covers dracoforce.com. It describes what this site actually does — not what a template says a website usually does. Last updated 24 September 2026.
The short version
Everything below describes this site as it stands on 24 September 2026, and it is written from the code that runs it rather than from a description of that code. If something changes, this policy is updated before the change goes live, not after.
No visitor id and no activity record unless you accept in the cookie banner — then one first-party id, ours. No advertising cookies, ever.
No Google Analytics, no tag manager, no ad or social pixels. Nothing here follows you to other websites.
We do not sell personal information, and we do not share it for cross-context behavioural advertising.
What we collect
When you contact us. If you send the form on our contracts page, we receive the name, email address, organisation, area of interest and message you type, plus the page you sent it from. We use it to reply and to keep a record of the enquiry. That is the only reason we ask.
When you talk to DRACO. Your conversation with DRACO is held in your own browser, in per-tab session storage. It is cleared when you close the tab, and the Reset control clears it immediately. Message text is sent to our own service to generate a reply; while a conversation is active, that service keeps its recent messages in memory so it can answer in context, and they are not written to storage. None of it is sold, and it is not used to advertise to you.
Voice. Tap-to-talk uses your browser's own speech recognition. We receive the resulting text, never an audio recording — this site has no code that captures, uploads or stores raw audio. Where recognition happens is your browser's choice: some browsers process speech on-device, others send audio to their own service under their privacy terms, and that exchange is between you and your browser vendor.
Server logs. Our API keeps ordinary operational logs to run and secure the service. Error paths are passed through a redactor that strips email addresses and phone numbers before anything is written.
Accounts and activity
You can read every page, price every SKU and talk to DRACO without an account. If you want one, this is exactly what it involves.
How you sign in. With an email address and password, or a passkey — and with GitHub or Google when those are offered (they are not switched on yet). A provider tells us your email address and your profile name, and nothing else — and only if that provider has verified the address itself; an unverified one is refused. A password is stored as a slow one-way hash, never as text we could read. A passkey gives us a public key and no password at all, and the identifier stored on your device is a random value that carries no name or email in it — though your device also stores your email address and name alongside it, so it can show you which account the passkey is for. We ask for your email address and your full name, and that is the minimum the account needs.
The visitor cookie — only if you accept. When you first arrive we set no visitor cookie and record nothing. Only if you choose Accept all in the cookie banner, or turn Analytics & activity on under Manage, do we set one first-party cookie, named df_visitor. It holds a random identifier — no name, no email, nothing derived from you — and it lasts 400 days, which is the longest lifetime browsers will honour. It exists so we can tell a returning browser from a new one, and so a sign-up can be connected to the pages that led to it. It is set by our own site for our own use; it is not an advertising cookie, it is not shared with an ad network, and it does not follow you to any other website.
The other cookies, and why they need no permission. df_consent remembers the answer you gave in the banner — “all” or “essential”, nothing else — for 400 days, so we do not ask on every page. df_no_track is set when you say no, in the banner or with the switch below, and tells our server to stop. When you sign in, df_session keeps you signed in, and a passkey sign-in — or a GitHub or Google sign-in, when those are offered — uses a cookie that lasts a few minutes while it completes. None of them identifies you across visits; each exists so the site can do what you asked.
What we record — once you accept. A short, fixed list of things that happened, and nothing about what you typed:
- The kind of event, from a fixed list we control: page view, starting a sign-up, finishing a sign-up, sign-in, sign-out, opening the DRACO chat, sending a chat message, requesting a quote or a demo, starting or finishing a checkout, viewing a document, downloading a file. That is the whole list — thirteen — and it includes starting a sign-up you never finish. An event we do not recognise is refused rather than stored under a guessed label.
- The path of the page — /draconex/, not the query string after it.
- Where you came from, as the site and path only. Anything after the path is stripped before it is written, because that is where search terms and reset links live.
- A few labels, from a fixed list of exactly eight: a SKU, the area of interest you chose, which DRACO you spoke to, a product, a document name, how long something took, whether it succeeded, and which sign-in provider you used. Nothing else is accepted, and values are short text or numbers only.
- When it happened, and the visitor id above; plus your account and session id once you are signed in.
We do not record what you type. No form values, no message bodies, no keystrokes. Not filtered out afterwards — never collected, so there is nothing to leak, subpoena, or get wrong later.
What signing in links together. This is the part worth being plain about. If you have accepted, the visitor id is set before you have an account and stays the same afterwards. So when you sign in, the activity already recorded against that browser can be connected to you by name. That is deliberate — it is how we learn which pages lead to a conversation — and it means signing in is the moment anonymous browsing becomes identified browsing. If you have not accepted, there is nothing to connect: no id was set and nothing was recorded. If you would rather it did not happen, see below.
How long we keep it. 400 days, the same as the cookie — we do not keep behaviour for longer than the identifier that makes it useful. Activity older than that is deleted outright, not archived. And one thing you are entitled to know: there is no self-serve way to close an account yet. Write to support@dracoforce.com and a person closes it and deletes the activity tied to you — or, if you prefer, unlinks it from you rather than erasing it, in which case it keeps the visitor id until the 400 days run out. Either way it is a real request a person answers, not a form that does nothing.
How to say no — or change your mind. Recording is off until you turn it on, and each of these keeps it off:
- The cookie banner. Reject non-essential, or Manage with analytics off. Change your answer any time with Cookie preferences at the foot of every page.
- Your browser's own signal. If it sends Global Privacy Control or Do Not Track, we treat it as a standing no — it outranks even a click on Accept all — and you do not have to tell us twice.
- The switch below. One press and we stop, on this browser, for 400 days.
- Delete the df_visitor cookie, or block it. The trail restarts as a stranger, and nothing on this site breaks without it.
The decision is made on our server, not in the page, so it cannot be skipped by a script, an ad blocker, or our own next change. When you say no — in the banner or with the switch — we also delete the visitor cookie and stop issuing one — leaving a 400-day identifier in place after someone asked us to stop would be recording that they asked, which is the opposite of honouring it.
Checking…
Or email support@dracoforce.com and say so — we will switch it off for your account and delete what is already there.
DRACOWING CLOUD
If you run a Wing in our cloud rather than downloading it, you are asking us to host your work. This section says exactly what that will mean, because the download and the cloud make different promises and should — the native app keeps every piece of project content on your own hosts, and that has not changed.
What lives in your tenant. A cloud Wing is built to run in its own namespace in our Azure Government subscription, so the things it produces stay there: its checkpoints, its context graph, your evidence bundles, and the per-task workspaces it builds in — which are temporary and go away with the task. All of it is encrypted at rest under Azure Government platform-managed keys.
Your source code is not ours to keep. Repository content lives in your repository. TALONs read what they need for a task and push pull requests back to you. We do not retain your source beyond the task workspace it was checked out into.
What lives on our side. Your account, tenant, plan, wallet ledger, usage meters and audit log — the records that make a subscription work — sit in our database. So does a small graph of context so DRACO and the operatives can address you properly: your name, your projects, your preferences, partitioned per tenant. Secrets are held in a key vault and mounted into your namespace; they are never written into an environment dump.
Metering. Model usage is measured from the moment you sign up and start building, and burned from your egg wallet. What is metered is the usage — tokens by model class — not the content of what you built.
Taking it with you, or ending it. You will be able to export at any time: a graph export and an archive of your evidence bundles. If you delete, we delete the namespace and purge its volumes, and confirm that we did. Backups exist because losing your work would be worse than keeping it, so a deletion clears the live data immediately and ages out of backups on the ordinary backup cycle.
Who else sees it
We use service providers to run the business — for customer records, email delivery, payments and hosting. They act on our instructions and only for the purpose we engaged them for. We do not sell personal information to anyone, for any purpose.
Some pages link to sites we do not run — GitHub, LinkedIn, YouTube, X, Instagram, and our own product sites. Following a link takes you to that operator's terms and privacy policy, not ours. Nothing on this site embeds their trackers.
How long we keep it
Enquiries are kept while the conversation is open and for as long as we need them for our business records and legal obligations. Browser session storage is not ours to keep — it lives on your device and ends with your tab.
Your choices
You can ask us what we hold about you, ask for a copy, ask us to correct it, or ask us to delete it. Write to support@dracoforce.com and we will answer. Depending on where you live you may have additional rights under laws such as the GDPR or the CCPA; we honour those requests without making you argue for them.
Children
This is a business-to-government and business-to-business site. It is not directed at children and we do not knowingly collect information from them.
Changes and contact
If this policy changes materially we will update the date above and, where the change affects you, say so on the page. Questions, requests, or anything that looks wrong: support@dracoforce.com — DRACOFORCE, INC, Castle Rock, Colorado.