Legal Privacy Policy
Last updated: 2026-04-19
This is a placeholder document. A counsel-reviewed final policy will replace it before public launch.
Data we collect
- Account identity: your email, Stripe customer ID, billing status.
- Artifacts you author: stored content-addressed in AWS S3 under per-tier KMS encryption.
- Usage events: one record per validation run (bucket, count, timestamp), used to produce invoices and power
subak status. - Logs: request metadata (IP, user-agent, endpoint, latency) retained for operational debugging.
What we don't do
- We do not train machine-learning models on your artifacts.
- We do not sell your data to third parties.
- We do not share artifacts across licenses. Every API call is scoped by the authenticated license ID; isolation is enforced server-side.
Third parties
We rely on Stripe (payments) and AWS (infrastructure). Their privacy policies apply to data they handle on our behalf.
Retention
Artifact content is retained indefinitely while your license is active; deleted artifacts are removed from the current manifest but historical manifests remain resolvable (per content-addressed storage design). Billing records are retained per applicable tax law (typically 7 years).
Your rights
You may request export of your data, deletion of your license, or rectification of stored details by writing to privacy@subak.ai.