Privacy Policy

What we collect, why we collect it, and what you can ask us to do with it.

Last updated: 1 September 2026

Draft — pending legal review

This page describes our current intentions in plain language. It has not been reviewed by a lawyer and is not yet a binding agreement. If you need a definitive answer before relying on it, please get in touch.

What we collect

We try to hold as little as we can while still running the product.

  • Account details: your email address and name, and a one-way hash of your password — never the password itself.
  • Connection details: credentials and tokens for the systems you choose to connect, encrypted at rest.
  • Usage records: which requests were made and how much AI capacity they used, so we can meter plans and investigate problems.
  • Operational logs: request metadata such as timestamps and IP addresses, used to keep the service secure and working.

Why we collect it

To provide the service, to bill for it accurately, to keep accounts secure, and to diagnose faults. We do not sell your personal data, and we do not use the contents of your connected systems to advertise to you.

AI processing

To answer a request, the assistant sends the relevant part of your conversation and the data it needs from your connected systems to an AI model provider. If you bring your own API key, that traffic goes to your own account with that provider.

Only the context needed to answer the request is sent. Credentials and secrets are never included in a prompt.

How we protect it

The service is served over HTTPS only. Passwords are stored as bcrypt hashes, connected-system secrets are encrypted at rest, and password-reset links are stored only as hashes, are single-use and expire quickly. Access to production systems is restricted and audited.

How long we keep it

Account and connection data is kept while your account is open. Operational logs and usage records are kept for a limited period for security and billing purposes, and then removed. When you close your account we delete or anonymise your data, except where we are required to keep records.

Your choices

You can, at any time:

  • change your password, which also signs out every other session on your account
  • disconnect any connected system, which revokes the stored credentials
  • ask for a copy of your data, or ask us to delete it

Cookies and local storage

We store your session tokens in your browser so you stay signed in — in temporary storage for a normal sign-in, and in durable storage if you tick "remember me". We do not use third-party advertising trackers.

Contacting us

For any privacy question, including a request to access or delete your data, please get in touch and we will respond.

Questions about this page? Contact us.