We don't track you or what you do off site, we pretty much just track which of our doors open and when, we also try to guess if it's a human or bot opening the doors, we let the users drive this animation. Hop around our page, then set the window to last 15 minutes. Turn on realtime playback and watch the path you took light up.
Everything described below, happening now. Anonymous chains weave the site's real link topology; visitors who ignored the robots.txt and entered the maze descend it in red. The structure is regenerated from the maze's own generation math — not crawled — and no visitor's exact path is ever kept. The System notes the movement, not the source.
drag to orbit · wheel to zoom · open full screen ↗
This policy covers two things: how we handle information from people who visit this site, and how we handle information from clients we work with.
If you're a client, your contract also applies — and where the two overlap, your contract governs.
We run one narrow, deliberately anonymous form of movement-tracking, and no third-party analytics or advertising trackers at all. Here is exactly what it is. When a page opens, your browser mints a random token — the kind of thing that looks like a1b2c3d4-… — and holds it in your tab's session storage. That token names the visit, not you: it's derived from nothing about you, it isn't a cookie, it can't be matched to any other visit or device, and it's gone the moment you close the tab. As you move between pages, we record the route you moved to (just the path, never the query string) stamped with that token, so we can see a path through the site — tools → labs → home — as an anonymous shape. That's the whole of it: the movement, not the source. There is no login-less identity, no cross-session profile, no fingerprint.
Why we collect it: part of what this site does is watch how it gets traversed, and some of that traversal is rendered as a live, public exhibit. The human side of that exhibit is drawn only from these anonymous chains — a moving dot with no name attached. Because it lives in session storage and never leaves your tab beyond the routes themselves, there is nothing here to export, delete on request, or opt a specific person out of; closing the tab ends it.
The maze is the other, separate stream, and it's held to a stricter line. Part of this site is a defensive labyrinth served under a path that robots.txt tells crawlers to stay out of — humans don't wander in by accident; the only door is disallowed to robots and invisible to people. For maze traffic we do record anonymized characteristics of the visitor — a user-agent string, which standard headers were missing, and the origin network resolved from the IP (for example, "came from an AWS range"). We resolve that network in the moment and then discard the IP: the store learns "an AWS range visited," never "203.0.113.x visited." Separately, each maze request is hashed for an instant — IP plus the day's salt — to ask one question, same source, too fast? — and that hash lives in ephemeral memory and is never written anywhere. To be exact rather than flattering: hashing and resolving are still processing your IP for the instant it takes; what we promise is that we never retain it. Retention-zero, not touch-zero.
Two honesties about completeness. We accept losing a small fraction of these events by design — the system batches records in forgetful edge memory to keep costs near zero, and a batch that hasn't been saved yet simply evaporates. And well-behaved crawlers that honor the robots.txt disallow are never mazed and never forensically profiled; they're noted as having visited and respected the rules, and rate-limited like any normal traffic. The forensic layer is only ever applied to traffic that entered a place it was told not to.
If you reach out by email, we receive your name, email address, and whatever you include in your message. We use it to respond to you. We don't add you to mailing lists. We don't sell it. Inquiry emails are held for up to 12 months and deleted when no longer relevant.
We don't knowingly collect information from anyone under 13.
This site hosts free interactive tools — Surface Skimmer, Depth Skimmer, AART, and the rndLabs experiments. Using them sends what you type to them — a domain, a URL, text — to our serverless functions for processing.
Skim analysis runs through a large language model API (currently Anthropic's Claude). What you submit is processed to generate your result and is not written to a database by the skim tools. Standard serverless infrastructure logs may exist at the platform level.
Gated tools (Depth Skimmer, Client Vault) use access codes. Vault contents are encrypted and tied to your slot; vault handling for clients is covered by your contract.
AART runs entirely in your browser against public NYC Open Data — nothing you do in it leaves your machine unless you export and send it somewhere yourself.
/WS/ (WILDSPEAK) — the spatial AAC experiment — is local-first by design. Every word, space, and photo made in it is stored in your browser, on your device, and nowhere else. There is no server, no account, and no analytics behind it; nothing is uploaded, and we never see any of it. Its only network request is fetching the three.js graphics library from a CDN. The export button in its care panel is your backup — your data's only way off the device is you.
The same LLM limitation in "What's Outside Our Reach" applies here: don't submit anything to a free tool that you couldn't tolerate passing through an AI pipeline.
We don't use cookies. Not for tracking, not for analytics, not for advertising — none. The one piece of client-side state we do set is a random per-tab token in your browser's session storage (described under "Website Visitors"), which is not a cookie, is never sent to a third party, holds nothing about you, and is discarded when you close the tab. Nothing we set persists across sessions or follows you between sites.
Your contract covers data handling in full. The short version:
We hold your business data — files, operational context, project information — for as long as we're working together and afterward, so we can re-enter your project efficiently if you come back. You can request deletion or full handover at any time. We confirm in writing when it's done.
We don't share your data with anyone outside the engagement.
Patterns and insights developed while working on your project may inform how we improve our own tools and methods. Nothing client-identifiable is disclosed.
We may reference your engagement in our portfolio in general terms — "built an operations tool for a regional contractor" — unless you request confidentiality in writing before the project is complete.
We use AI-assisted tools — including large language models — as part of how we work. Before your data touches any of those tools, we ask you to identify anything sensitive. We anonymize or remove it before processing.
Data not flagged as sensitive is treated as general operational information.
When you request deletion, you have two options:
Files removed, cloud storage cleared, email correspondence deleted across all systems owned and operated by Relative Dynamics. Included at no charge.
Secure overwrite or SSD-level erase across all Relative Dynamics systems that touched your data. Nothing recoverable on our end. Available on request.
We confirm completion in writing either way.
Data that has entered LLM training pipelines cannot be retrieved or deleted — by anyone. If that level of protection matters to your operation, flag your sensitive data before scope is signed. That's the window. Not after.
Information gathered during pre-contact research — prospect analysis, digital landscape review, anything we looked at before you became a client — is retained by default. Deletion is available on request, priced on effort. The same LLM limitation applies to anything that passed through AI-assisted analysis during that phase.
We don't sell data. We don't broker it. We don't share it with advertisers.
AI-assisted tools including large language models are used in our development process. When analytics is active on this site, the tools involved will be listed here along with opt-out instructions.
If we become aware of a breach affecting your data, we'll notify you in writing as soon as we're able — targeting within 72 hours of discovery. We'll tell you what happened, what was affected, and what we're doing about it.
If a disruption outside our control — equipment failure, illness, natural disaster, or similar — affects our ability to respond to a data request or honor a notification timeline, we'll communicate as soon as circumstances allow. Timelines extend by the duration of the disruption. We won't go dark.
You can ask us to delete your data, hand it over, or tell you what we hold. We'll respond in writing within 5 business days where circumstances allow.
If you're in the EU or California, additional rights may apply under GDPR or CCPA. We'll honor them.
When this policy changes, the date at the top updates. Material changes — anything that affects how your data is handled — will be noted here with a plain description of what changed and when.
If something here isn't clear or you want to make a data request, reach out directly.
Contact us ↗