Privacy Policy
What we store
- Account — identity from our authentication provider, plan and billing status.
- Content you create — workflows, agents, knowledge bases, uploaded files, chat and agent conversations.
- Credentials — encrypted at rest with AES-256-GCM, write-only after saving (see Security).
- Operational records — usage and error events used to run and debug the service. These carry identifiers, counts, durations and costs. They deliberately do not carry prompts, completions, file contents or credential values.
Processors we rely on
Running the product requires sending some data to these third parties:
- Model providers (OpenAI, Anthropic, Google, xAI) — receive the prompts and content you send to them, for the model you choose.
- Authentication provider — identity and session management.
- Payment processor — billing details. We never see or store full card numbers.
- Cloud infrastructure — hosting, databases and object storage.
What we do not do
- We do not sell your data.
- We do not train models on your content.
- We do not put your prompts, completions or file contents into our operational logs.
Retention periods
Needs counsel. The system has real retention behaviour (deleted content is soft-deleted then swept; operational events age out on a schedule; generated images expire), but committing to specific windows in a public policy is a legal decision, not an engineering one.
Your rights, jurisdiction and international transfers
Needs counsel — GDPR/CCPA rights language, the governing jurisdiction, the legal entity name and address, transfer mechanisms, and the DPA offer all have to be drafted by a lawyer.
Contact for privacy requests
Needs a monitored privacy address before publication. Until then, use the contact page.
Last updated 2026-08-16.