Privacy policy
What we actually process
Running your agents means we hold a few different kinds of information about your business, always inside your own workspace:
- Business facts you give us directly — your company name, country, VAT number, billing details, working hours and similar settings, entered once during setup.
- How you want things written — your preferred tone, language and a short style note, used only to shape the wording an agent produces, never to change what it is allowed to do.
- Documents you upload — project notes, timesheets and similar internal material you choose to give an agent so it has something real to work from.
- What your agents did, and why — every proposal, every approval or rejection, and a record of the exact instructions and knowledge behind each one. Our internal audit trail stores pointers to that record, not a second copy of its content — removing the content later does not remove the trail of what was decided.
- Connections to your other tools — a pointer to where an access token for a tool you connect is kept, never the token itself, inside our records or in a log.
Where it is processed
Your workspace data is stored in Frankfurt, Germany — a named country location, not a general “Europe” region that could quietly move your data somewhere else. Some processing steps — running the underlying language models, turning your documents into a form we can search by meaning — are carried out by outside companies. Every one of them is listed, by name, on our sub-processors page, along with where each of them processes data and whether an agreement covering that processing is actually signed yet.
What we do not do
We do not sell your data. We do not use your business data to train a general-purpose model. Support staff can see that something happened without special consent, but seeing the actual content of what happened is a separate permission we ask you for, and every support session is time-limited, logged, and can never approve anything on your behalf.
Your rights
You can ask us to erase your data. Doing so empties the content we hold — your documents, what an agent remembered, the detail of past proposals — while the audit trail of decisions still shows that something happened and when, because that trail was never the content itself. The exact legal basis for third-party contact data, the automated-decision exclusion, and formal breach wording are the parts of this page still waiting on legal review.
If something goes wrong
If we discover a data breach affecting you, we notify you within 24 hours of finding out. You are the one who owes your own regulator a report; our job is to get you what you need to do that, fast and in plain words.