Privacy Policy
Last updated 2 September 2026.
What we collect
- Account data: email address, hashed password, organization name.
- Agent configuration you create: system prompts, tool grants, channel bindings, compliance settings.
- Run data: prompts and responses your deployed agents process, tool calls made, tokens used, cost, and latency — this is the run trace your agents generate, retained per your plan's retention floor.
- Credentials you provide: BYOK model keys and connector credentials (e.g. a Gmail service account, a Slack bot token) — encrypted at rest at the application layer before storage.
- Billing data, handled by our payment processor (see Sub-processors below) — we don't store card numbers ourselves.
Why we collect it
To operate the account and product you signed up for: running your agents, enforcing plan limits, billing, and — where your agent's compliance profile requires it — maintaining the audit trail EU AI Act Article 50 disclosure and retention rules call for.
Retention
Account data persists until you delete your account. Run traces and usage data follow your plan's retention floor (see pricing), enforced by a scheduled purge — not kept indefinitely by default, and not retroactively shortened if you downgrade.
Sub-processors
We use a small number of vendors to operate the service — model inference providers, hosting, and billing. The full list, with what each one sees, is available on request.
Your rights
You can access, export, or delete your account data by contacting us. If you're in the EU/UK, this includes the rights GDPR provides — access, rectification, erasure, and portability. We respond to verified requests as quickly as we reasonably can.
Contact
Questions about this policy: use the contact page.