Celest · Privacy
Narrow boundaries,
stated plainly.
This notice covers Celest's public-site analytics and Learn retrieval services, covered free package-only Microsoft 365 agents, and support communications about the public website, this notice, or those covered packages. Those agents use Microsoft-hosted capabilities and do not transmit agent conversations or Customer Content to a Celest-operated product runtime.
Free Microsoft 365 package-only products
This product boundary applies only when an applicable Celest listing or immutable release record expressly identifies a free/included Celest Microsoft 365 agent or plugin as package-only and covered by this notice, with no Celest-hosted runtime or external service. A manifest link to this privacy URL, by itself, does not add a different product to this boundary.
These packages contain Celest-authored instructions, configuration, embedded knowledge, and documentation. Microsoft hosts their orchestration and their built-in capabilities. Depending on the package and the permissions available to the user, those Microsoft capabilities may work with user-provided files or the customer's Microsoft 365 content, including SharePoint and OneDrive files, Teams messages, meetings, or email.
A covered package-only agent does not send prompts, uploaded files, Microsoft 365 content, generated responses, or agent-conversation content to a Celest-operated API, MCP server, connector, database, inference service, or other product runtime. Celest does not operate durable product-content storage for a covered package and does not instrument it to transmit agent conversations or Customer Content to Celest.
Microsoft 365, Microsoft Copilot, Microsoft Graph, and other Microsoft services used by the packages are licensed, hosted, and operated by Microsoft. Their processing is governed by the customer's applicable agreements and data-protection documentation with Microsoft. Celest does not control or restate Microsoft's processing, retention, residency, security, or model-use commitments.
If an authorized distribution channel makes acquisition or application-usage reporting available to Celest, the fields made available may include the product and package version, acquisition or installation state, tenant or organization identifier, account or acceptor identifier, timestamp, and listing or release identifier. Celest uses only the fields the channel provides to understand distribution, maintain release and acceptance evidence, and support customers. Aggregate usage reports are used at an aggregate level. Identity-level fields are used only when the channel supplies them for acquisition, support, or release evidence. These channel records are retained only as long as reasonably necessary for those purposes and applicable legal or accounting obligations. A covered package does not transmit agent conversations or Customer Content to Celest for that reporting.
Website analytics
Cloudflare hosts and protects this site. Like any delivery and security provider, it receives ordinary request information needed to serve traffic and defend the service. Celest uses aggregate edge information to understand route availability, request volume, and crawler activity.
On Celest pages, a small script records reviewed product and banner interactions: landing.team_demo_open opens the Day One team experience, landing.estate_review_open opens the Estate Review product, estate_review.request_intent starts an Estate Review request, and landing.contact_intent starts a general contact email. Each event contains a fixed event name, its page and placement, one reviewed referring-source category, and campaign labels selected from a finite public vocabulary when they are present in the URL. The analytics event does not receive a submitted name or website, generated content, artifact content, demo-session identifier, or other freeform user submission. Cloudflare Workers Analytics Engine supplies the observation time. The demo host itself does not load this analytics script.
On the Agent Workbench landing page, workbench.ad_measurement_allow and workbench.ad_measurement_deny count clicks on Allow and Don't allow. workbench.signup_without_choice counts Sign up clicks while that banner is unanswered. These are aggregate click counts, not records of who made a choice or completed signup. They remain separate from optional reports to OpenAI; declining or ignoring that choice does not send a conversion report to OpenAI.
The exact public event contract is available in the analytics manifest.
What we do not collect automatically through analytics
- Analytics cookies, local-storage identifiers, or persistent visitor IDs
- Device or browser fingerprints
- Raw IP addresses or raw user-agent strings in the Celest analytics dataset
- Full referrer URLs, query strings, or search terms
- Email addresses, names, company names, form text, or clipboard contents through analytics
- Submitted display names or company URLs from the Day One journey
- Demo or session identifiers
- Generated content, artifact content, or receipt content
- MCP questions, tool arguments, resource contents, or tool results
- Third-party advertising, retargeting, session-replay, or identity-resolution pixels
How we use the signal
We use aggregate measurements to answer a narrow set of questions: whether people and agents can reach the canonical resources, which public paths lead to team-demo exploration, Estate Review interest, or contact intent, how visitors use the Workbench banner's choices or continue to sign up without answering it, and whether the Learn MCP surface is useful. A click that opens an email client is only contact intent; Celest treats an email actually received and qualified by a founder as the business outcome.
AI crawlers and MCP
Celest keeps discovery crawls, user-directed retrieval, and explicit MCP activity separate. User-agent strings can be spoofed, so we do not describe a crawler as provider-verified without additional network evidence.
For the public Learn MCP server, Celest records initialization, tool discovery, resource reads, and ask/similar retrieval metrics: operation, requested MCP pathname, outcome category, duration, result and source counts, source-domain category, and server version. Each retrieval result has a random result ID for correlating optional feedback; it is not a visitor or session identifier. Automatic telemetry does not copy questions, queries, retrieved passages, resource contents, or error messages.
The optional feedback tool records a result ID, a usefulness rating, an optional reason, and an optional note limited to 500 characters and 1,024 UTF-8 bytes. These voluntary notes are retained in Cloudflare Workers Analytics Engine for the same maximum three-month window as raw event observations. Do not include private conversation content, personal information, or credentials. Caller-reported feedback is advisory and is not a verified user outcome. Feedback is optional and must not take priority over the user’s task. MCP clients may send Celest-Analytics: omit to suppress both automatic telemetry and feedback storage. Preview hosts do not write production analytics.
When you use Learn's ask tool or A2A endpoint, Celest first searches its own published articles and site pages in a section index built from the same published files; that search runs inside Celest's Cloudflare Worker and sends nothing to a provider. For questions to the corpus-wide endpoint, Celest also sends your question to Exa to find and retrieve public Microsoft Learn pages; article-specific requests do not contact Exa. Exa may serve cached public results. Celest then sends the question, the article's title as scope context for article-specific requests, and the candidate excerpts with their source URLs (owned section text and any retrieved Microsoft Learn page text) to Microsoft Azure Foundry for one tool-free relevance-selection pass; when nothing was retrieved, that pass receives the question alone so the response can say why the search held back. Celest enables Responses API storage so the question, source material, selection activity, and provider response can be inspected for debugging and quality review. This is separate from the retrieval analytics above. The analytics opt-out does not disable this processing or response storage.
The similar tool and MCP Resources use Celest's published article corpus without a Foundry or Exa request. Public Learn has no access to your private tenant records; do not submit credentials or confidential information.
Microsoft's Azure AI data privacy documentation describes Responses API storage, deletion, and separate abuse-monitoring practices. The three-month analytics limit below does not apply to these stored provider responses. Contact Celest about a stored Learn request using its response ID when available; the ID helps us locate it for review or deletion.
Support communications
This section applies only to questions about the public website, this notice, or a covered package-only product. When someone emails [email protected], Celest receives the sender's address, message, and any voluntarily supplied attachments or contact details. Celest uses that information to respond, investigate the request, maintain ordinary business and security records, and comply with law. Support information is retained only as long as reasonably necessary for those purposes. This support-record retention is separate from the three-month raw analytics retention described below.
Support communications about Celest Helpdesk Triage or another product with a product-specific privacy notice are governed by that product's notice instead, including its retention and deletion terms.
Customers should minimize support submissions and should not send passwords, access tokens, regulated data, or unrelated Customer Content unless Celest has expressly agreed to an appropriate product-specific handling process.
Retention and providers
Raw first-party event observations are retained for no more than Cloudflare Workers Analytics Engine's current three-month window. Celest may retain longer-lived aggregate counts that cannot reasonably be used to reconstruct a person's browsing activity.
Cloudflare is the hosting, security, and analytics infrastructure provider for this public site. We do not send the analytics events described here to Google Analytics, Google Tag Manager, RB2B, or another advertising or identity-resolution provider.
Agent Workbench has a separate, optional advertising-measurement preference. Privacy choices lets you allow or decline it for this browser, independently of account creation. A preference cookie remembers the choice for up to 180 days across celest.dev and workbench.celest.dev. When allowed, the companion reports completed registrations to OpenAI with available ad-click and matching information, including a hash of the signup email and request metadata. This does not change or identify the first-party event counts described above. See the Workbench product privacy notice.
Your choices
Because this analytics model creates no durable browser identifier, there is no analytics profile for you to retrieve or delete from a cookie ID. Browser content blockers may prevent the optional landing-page event request without affecting the site. These first-party analytics counts are not joined to the optional Workbench advertising-measurement events.
If any of these boundaries changes, Celest will update this notice and, where relevant, the public event manifest before expanding Celest's collection. A future Celest-hosted or connected product will receive product-specific disclosures before this notice is relied on for that product. Questions or privacy requests can be sent to [email protected].