Legal
Privacy Notice
Version 1 · Effective 2026-09-24
Engineering baseline — counsel review required before production launch.
The platform may process account identifiers, organization and team information, authentication and security events, API usage and request metadata, billing and subscription records, support communications, and configuration data needed to operate the service.
Data is used to provide and secure the service, authenticate users, meter API usage, bill customers, detect abuse and incidents, provide support, improve reliability, and generate optional analytics or AI-assisted recommendations where enabled.
Service providers and subprocessors may process limited data to provide infrastructure, payment, email, identity, monitoring, support, or AI functionality. Production disclosures must identify applicable subprocessors and contractual roles.
Retention periods should be configured by data category. Access, correction, deletion, export, opt-out, consent, and other privacy-right workflows apply according to jurisdiction and contract. Backup deletion may follow documented retention schedules rather than immediate physical erasure.
Security controls include access restrictions, encryption in transit, secret minimization, audit logging, MFA for administrators, tenant isolation, and tested backup and recovery procedures.
Production contact details, legal entity information, jurisdiction-specific notices, cookie disclosures, and rights-request instructions must be finalized before launch.