Skip to main content
Locus

Data Processing Agreement (DPA)

Last updated 2026-09-26.

A DPA is the contract that governs how a vendor (the "processor") handles personal data on a customer's (the "controller"'s) behalf — required under GDPR Article 28 and comparable data-protection laws whenever a business sends another business personal data to process. If you're evaluating Locus for your organization and your own compliance process requires a signed DPA before you can use a vendor, this page is for you.

Do you actually need one?

If everyone at your organization runs Locus with LOCUS_EMBEDDER=local, uses only desktop AI clients, and never creates a locus-web account, no personal data reaches us and a DPA has nothing to attach to. A DPA becomes relevant once your organization creates locus-web accounts (Locus Enterprise). Account data then reaches our infrastructure and is stored. If employees use managed embeddings, chunk text passes through our relay to Voyage AI. If they use remote connection, search requests, excerpts, file text, file paths and account/setup status pass through our relay (Vercel and Supabase Realtime). Both are in transit only, and we don't store that content. An employee who uses their own Voyage or OpenAI key sends chunk text to that provider directly, not through us.

Controller and processor roles

Under the draft, your organization is the controller — you decide what gets indexed and who your employees are. Locus (operated by Yonathan Levy) is the processor — we process the narrow slice of data described below solely to provide the service, never for advertising or resale, and we don't use it to train models. On managed embeddings, Voyage AI embeds chunk text under our account on its own terms; we are verifying Voyage's retention and training-use terms for that account, and the draft flags this as an open item.

The draft is built around Locus's real, shipped architecture, not a generic SaaS template: each employee runs their own local Locus instance, indexing files directly from disk (or an already-mounted network share) into a local vector store on their own machine. Your employees' raw files are never uploaded to Locus, under any plan. What reaches our infrastructure: account data for anyone with a locus-web account (stored); chunk text on managed embeddings, and search requests, excerpts and file text (an assistant can read a whole file piece by piece), file paths and account or setup status on remote connection (in transit only; we don't store them).

What the draft covers

  • Categories of data and data subjects. Your employees' account, subscription or seat, API-key and usage data. Also, in transit only, whatever personal data appears in chunk text (managed embeddings) or in search requests, excerpts, file text, file paths and account or setup status (remote connection). We can't identify or filter that in advance; you're responsible for what your employees are authorized to index.
  • Sub-processor list. The vendors that touch data covered by this DPA — see /subprocessors for the current, canonical list and what each one actually receives. The draft requires us to pass equivalent data-protection terms on to each sub-processor (GDPR Article 28(4)); checking each vendor's standard terms against that is still open.
  • Security measures. Row Level Security on every account-data table, hashed (never plaintext) API keys, 0700 permissions on the local data directory, and the rest of our current, honest security posture — see /security. Given our stage (pre-revenue, solo-founder-operated), these measures are real but modest, and the draft says so plainly rather than overclaiming.
  • Breach notification. We will notify you without undue delay after becoming aware of a personal data breach affecting data processed under the DPA, reporting on partial information first and supplementing as the investigation continues, rather than waiting to investigate fully before saying anything.
  • Data return and deletion. On termination, we will delete or return the account/subscription/API-key/usage metadata described above, at your written election, except where retention is legally required (e.g. local invoicing/tax records). We don't store file content, vectors or local indexes, and we don't keep chunk text or excerpts after a request completes, so there is nothing for us to delete or return on that front: deleting an employee's local data is entirely within that employee's own control (delete ~/.locus, or the configured LOCUS_DATA_DIR).
  • Cross-border transfers. Flagged, not resolved, in this draft. Our database is in Supabase's ap-southeast-2 (Sydney) region; remote-connection messages pass through Supabase's Realtime service, whose serving region is not pinned; and our hosting provider (Vercel) and embeddings sub-processor (Voyage AI) are US-based — all outside our own operating jurisdiction, and potentially outside yours too. The draft states this plainly rather than claiming a specific transfer mechanism (Standard Contractual Clauses, an adequacy decision) is already in place, because none has been reviewed by a lawyer yet.
  • Audit rights. As GDPR Article 28(3)(h) requires, we make available the information needed to demonstrate compliance. No SOC 2 report exists — see /security for exactly what our security posture is and isn't today.

What we never store, and what is covered in transit

The content of your employees' indexed files, their local indexes (the chunk text and vectors in each employee's ~/.locus directory), and any Notion content they connect are never stored by us. Chunk text (managed embeddings) and search requests, excerpts and file paths (remote connection) pass through our relay in transit; that transit processing is covered by this DPA.

Request the document

To request the DPA, contact yonilev2003@gmail.com, or use the contact form on /business if you're evaluating Locus for your organization.

Draft — this page summarizes an internal DPA draft that has not been reviewed by a lawyer and has not been executed with any customer. It is not itself the agreement, and nothing here is a binding representation of Locus's legal obligations.