Commercial policy
Privacy policy
Candidate effective date: 6 August 2026 · Not active until public billing launches
The service is designed to retain the minimum metadata needed for delivery, billing, security, and reconciliation.
Data we plan to process
- Account identity and contact information.
- Project and endpoint identifiers chosen by the customer.
- Delivery metadata, hashes, decisions, permits, acknowledgements, failures, and audit events.
- Plan, entitlement, invoice, refund, and subscription identifiers received from Paddle.
- Security, rate-limit, and operational logs.
Data we do not need by default
Raw repository contents, task transcripts, provider credentials, payment-card details, and full message bodies are not required for the core orchestration record. Customers should store payloads in their own system and send bounded references.
Purpose and retention
Data is used to provide, secure, support, bill, and reconcile the service. Planned retention is 30 days for Pro audit events and 90 days for Team; billing and legally required records may be retained longer. Final deletion and export procedures must be operational before billing opens.
Processors and transfers
Planned processors include Paddle for commerce and the selected hosting provider for service delivery. A final subprocessor list, operator contact, and cross-border transfer statement will be published before launch.
Your choices
Customers will be able to request access, correction, export, or deletion through the support channel, subject to security and legal retention requirements.