Privacy
DRAFTWhat the control plane stores, where it stores it, and what it does not do with it.
Draft. This draft states current behaviour of the software. It has not been reviewed by a lawyer and is not yet a privacy notice you can rely on for compliance.
What the control plane stores about you
Your account: email address, a password hash, whether the address is verified, and your active sessions. Passwords are never stored in a readable form.
Your organizations: name, region, plan, membership and role, pending invitations, and the environments and stacks that belong to them.
An audit log of control-plane actions — who did what, and when. It exists so an organization can answer that question about itself.
Per-tenant isolation
Your environment's data lives in a database provisioned for that environment, not in a shared table keyed by a tenant column. The control plane holds the account and organization records described above; your contacts, events and sends live in your own instance.
Provider keys are encrypted at rest
Third-party credentials you supply are encrypted before they are written, using AES-256-GCM with a key derived from a control-plane secret, and are decrypted only to operate your environments. A tampered or truncated value fails closed rather than returning a partial secret.
Region choice
You pick European Union or United States when you create an organization, and the data stays in that region's infrastructure. The region is fixed at creation: moving a tenant between regions is a migration, not a setting.
What we do not do
Your data is not sold, and it is not shared with advertisers or data brokers.
The control plane runs no analytics, advertising or session-recording scripts. It sets one cookie, the session cookie that keeps you signed in.
Email we send you
Verification codes, invitations and account notices. In development these are written to the server log rather than sent; in production they go out through our own email provider, not through a key of yours.
Not written yet
These clauses are left to the lawyer pass rather than drafted here. Until they exist, this document does not cover them.
- — Named subprocessors and their locations
- — Retention periods per data category
- — Data subject rights and how to exercise them
- — Data processing agreement and standard contractual clauses
- — Breach notification commitments
- — Contact point for privacy requests