Privacy
What we hold, and for how long
What we collect
- Account. Your email and name, from the identity provider you sign in with, and which workspace you belong to.
- Usage metadata. For each captured call: the model, provider, token counts, latency, timing, and the identifiers you choose to send — a run id, an agent name, entity keys, a call site.
- Outcomes. The business events you report, and the identifiers you attach to them.
What we do not collect by default
Prompt and response content. It is off unless you turn it on per request, and it exists only to make replay and evaluation possible.
The identifiers you send are yours and we do not interpret them. If you send a customer id as an entity key, we hold that customer id — so send an id you are comfortable holding here, not an email address or a name.
Credentials
Provider keys you send on a proxied request are never stored. Keys you save in Settings are encrypted at rest and never returned by any read. Ingest keys are stored only as a hash. See Security for the detail.
Where it lives
Postgres, hosted by Neon in aws-us-east-2. Authentication is Neon's
managed service; the session and user records sit in the same database as
everything else.
Deletion
Ask and we remove your workspace and everything in it. Captured content, if you enabled it, also expires on the TTL you configure without you asking.