Privacy Policy

Last updated: July 30, 2026

1. What we collect

Account data: name, email address, and a hash of your password (we never store the password itself). Content you create:agents, tools, prompts, canvas configurations, and run history including inputs, outputs, and execution traces. Credentials you supply: LLM provider API keys and data-pipeline connection credentials, stored encrypted (AES-256-GCM) and decrypted only in memory to execute the work you request. Billing data: credit balance and transaction history; card details are processed by Stripe and never touch our servers. Operational data: logs and error reports needed to run the Service securely. Usage data: while you are signed in, we record which pages of the app you visit, along with sign-in times and the actions you take (creating and running agents and pipelines, running security scans). We store the page path only — never the query string, and record identifiers in the URL are replaced with a placeholder, so this shows which features were used rather than which specific records were opened. Page-view records are deleted after 90 days.

2. Why we record usage data

Usage data lets us support your account — answering “what happened when this failed?”, spotting abuse, and understanding which parts of the product are actually used. It is visible only to our administrators, is never sold or shared, and is not used for advertising or profiling. Pages you visit while signed out are not recorded.

3. How we use it

We use your data solely to provide the Service: executing your agents and pipelines, displaying your run history, processing credit purchases, sending transactional email (verification, password reset, team invitations), and keeping the platform secure. We do not sell your data or use it for advertising. We do not train models on Your Content.

4. Who we share it with

Data is shared only with the processors required to operate the Service: Railway (hosting and Postgres), CloudAMQP (message queue), Stripe (payments), Resend (transactional email), and Sentry (error monitoring). When your agents call an LLM provider (e.g. OpenAI or Anthropic), the prompt content of that run is sent to the provider you configured, under your own API key and that provider's terms. We disclose data if required by law.

5. Retention and deletion

Your data is retained while your account is active. Deleting your account from Settings permanently removes your account, agents, tools, runs, encrypted keys, and pipeline configurations from our production database. Backups age out on the hosting provider's rolling schedule. Billing records may be retained as required for tax and accounting law. Page-view records are deleted automatically after 90 days, whether or not you delete your account.

6. Security

Passwords are hashed with bcrypt. Sessions use secure, httpOnly cookies. Supplied API keys and pipeline credentials are encrypted at rest with AES-256-GCM. User-supplied code executes in a WebAssembly sandbox without host filesystem or network shell access. No system is perfectly secure — report suspected vulnerabilities to ftesei96@gmail.com.

7. Your rights

You can access and update your profile in Settings, export your agents and run data from the dashboard, and delete your account at any time. Depending on your jurisdiction you may have additional rights (access, rectification, erasure, portability, objection); to exercise them, contact ftesei96@gmail.com. We respond within 30 days.

8. Cookies

We use a single first-party session cookie for authentication and a theme preference. We do not use advertising or cross-site tracking cookies.

9. Changes

We will announce material changes to this policy on the site or by email before they take effect. Questions or requests: ftesei96@gmail.com.