Skip to main content
Legal

Privacy Policy

Prompt content and upstream provider keys are not retained by RedactCloud.

Last updated: August 3, 2026

1. What RedactCloud does not retain

RedactCloud exists to keep sensitive data out of third-party AI systems. We apply the same standard to ourselves: prompt content, tool payloads, response payloads, and upstream provider keys are processed transiently and are not persisted by the application database or usage logs.

We do retain the account data and payload-free operational metadata described below.

2. Data we process on your behalf

Prompts routed through the proxy are inspected transiently to perform redaction, forwarded to the selected supported provider endpoint, and discarded. We retain aggregate metadata only: request counts, bytes processed, entity counts, latency, provider/protocol/status fields, and a request identifier.

3. Data we collect about your account

  • Account details — name, email address, and a hashed password.
  • First-touch attribution — campaign labels, referrer host, and landing path when available.
  • Conversion totals — daily aggregate counts for landing visits, CTA clicks, registrations, verifications, first API keys, and access requests. These counters do not store IP addresses, user agents, session identifiers, or prompt content.
  • Service telemetry — request identifiers, provider/protocol/status fields, API usage counters, and error diagnostics without payload content or provider credentials.
  • Account security data — session identifiers and, depending on deployment, IP address and user agent used to protect account sessions.
  • Billing data — Dodo Payments processes checkout and payment details as our merchant of record. RedactCloud retains only the Dodo customer, product, and subscription identifiers, subscription status, billing-period dates, and a one-way hash of each webhook payload. We do not store card or bank details.

4. Retention

Usage metadata is retained for up to 90 days. Production-access requests and daily aggregate conversion totals are retained for up to 365 days. Operational deployments may use shorter periods. Billing event identifiers and subscription records are retained while needed to provide paid access, resolve billing disputes, and meet legal obligations; raw billing webhook payloads are not retained. Expired coding-agent connection records are removed automatically. Session data is retained only for the session lifetime or an operationally necessary security period. Account records remain until closure is requested or they are otherwise no longer required.

5. What we never do

  • Persist raw prompt content in the application database or usage logs.
  • Use customer data to train models.
  • Retain upstream provider API keys.

6. Your rights

You may request access, correction, export, or deletion of your account data at any time by writing to privacy@redactcloud.com.

7. Sub-processors

We use infrastructure providers to operate the service. Dodo Payments acts as merchant of record for paid subscriptions and processes identity, payment, tax, invoice, and billing data under its own privacy policy. AI requests are governed by the selected upstream provider's terms once forwarded, after redaction has run.

8. Contact

Privacy questions: privacy@redactcloud.com.