Privacy
Privacy notice
What we collect, what we never collect, where it goes and how to have it deleted.
Last reviewed 31 August 2026
In short. We process the account, billing and decision-record data needed to run the service, never your agents' prompts, model outputs or training data. There is no third-party analytics and no advertising tracker on these sites. The detailed processor terms are in the data processing addendum.
What we process and how
What we process
Account identifiers and billing contact details; the decision records your agents generate, including the service, path, verdict and stage results; usage counts for metering; and API key fingerprints. We do not require or store your agents' prompts, model outputs or training data.
What we never store in the clear
API keys. They are held as SHA-256 fingerprints, so a database disclosure does not hand anyone a working credential. Card numbers never reach our servers at all -- they are entered on Stripe's own hosted page.
Where it is processed
United States, on infrastructure operated by the hosting provider named in the sub-processor list. The hosted deployment is single-region. If your data may not leave a jurisdiction, the self-hosted deployment processes nothing on our side.
How long we keep it
Decision records and evidence are retained for the life of the account so they remain available for an incident review, which is their entire purpose. Usage counters are retained for billing and reconciliation. Deletion on request is covered below.
Deletion
Write to the privacy address and we will delete your account data, including decision records and evidence, and confirm when it is done. Billing records are retained where tax and accounting law requires it, which we will identify specifically rather than citing a blanket exemption.
Isolation between customers
Every fabric store is tenant-scoped and the tenant is resolved from billing on the server -- never taken from a header the caller controls. Cross-tenant reads return a 404, not a 403, so an identifier cannot be probed for existence.
Sub-processors
Four, listed in full with what reaches each of them. There is no third-party LLM provider, no third-party analytics and no advertising tracker on either site.
Breach notification
We will notify affected customers without undue delay and in any case within 72 hours of becoming aware of a personal data breach, with what we know at the time rather than waiting for a complete picture.
Who else touches your data
Every third party that processes data for the hosted deployment is on the sub-processors page, with what reaches each of them. We publish a new one there before we use it.
Questions and requests
Access, correction and deletion requests, and any privacy question: privacy@cainstudio.online. Security reports go to the disclosure policy.
DPA · Sub-processors · Security · Terms