Privacy

Five privacy promises.
The rest is detail.

Most privacy pages are 4,000 words you can't audit. Ours opens with the five commitments that don't change between plans, regions, or quarters — and links to the long version for everything else.

The Privacy Promise

Five things we won't change on you

01 irrevocable

No sale of personal data

Permanent. Encoded in our DPA. There is no plan, business model, or pricing tier where this changes.

02 opt-in only

No model training on your queries

Off for every account. Anonymized samples are only ever used after explicit opt-in inside the dashboard.

03 24h SLA

24-hour delete on request

Hard delete fans out across primaries, replicas, and backups within 24 hours of confirmation.

04 self-serve

Full export, in one click

A signed JSON archive of every query, account record, and audit event. No tickets, no waiting period.

05 30d notice

30-day notice on subprocessor changes

New vendors, new regions, ownership changes — all announced before they take effect, never after.

+ When you sign up

Account → Settings → Privacy gives you toggles for telemetry, retention, and email — plus a one-click export and audit log.

See account settings →
Subprocessors

The full vendor list

AWS
Cloud hosting
us-east-1, us-west-2
Cloudflare
Edge / WAF
Global
Stripe
Payments
US
Postmark
Transactional email
US
Sentry
Error monitoring
US
Auth0
Authentication
US

Changes to this list are announced 30 days before they take effect.