Last updated: July 2, 2026
Account data (name, email, password hash), organization and billing data (plan, invoices — card details are held by Stripe, not us), product content (agents, experts, knowledge documents, conversations, feedback), and operational data (logs, usage metering, audit events, IP addresses).
To operate the Service: run your agents against the model providers you configure, meter usage for billing, secure accounts (MFA, session management, rate limiting), send transactional email (verification codes, invitations, billing notices), and maintain audit logs.
Prompts, retrieved knowledge and conversation history are transmitted to the AI model providers configured for your organization (e.g. your own OpenAI or Anthropic keys) solely to generate responses. We do not sell your content or use it to train models.
Data is stored in MongoDB Atlas with encryption in transit and at rest. Sensitive secrets (provider keys, MFA seeds, connector tokens, webhook secrets) are additionally envelope-encrypted with a platform key. Access is role-gated and audited.
Conversation retention is configurable per organization (with a 30-day floor). You can export your data and request full account deletion in the app; deletion cascades through your content on a scheduled purge.
We share data only with the processors needed to run the Service: your configured AI providers, Stripe (billing), our email delivery provider, and infrastructure hosts. We do not sell personal data.
If you deploy agents to your own users, you are the controller of those conversations; we process them on your behalf. Deployed surfaces display an AI disclosure, and end-user satisfaction ratings are stored with the conversation.
Depending on your jurisdiction you may have rights to access, correct, export or delete your personal data. The in-app account page provides export and deletion; for anything else, open a support ticket.
We will announce material changes to this policy in the product or by email. Contact us via the in-app support module.