Subak
Legal

Privacy Policy

Last updated: 2026-04-19

This is a placeholder document. A counsel-reviewed final policy will replace it before public launch.

Data we collect

  • Account identity: your email, Stripe customer ID, billing status.
  • Artifacts you author: stored content-addressed in AWS S3 under per-tier KMS encryption.
  • Usage events: one record per validation run (bucket, count, timestamp), used to produce invoices and power subak status.
  • Logs: request metadata (IP, user-agent, endpoint, latency) retained for operational debugging.

What we don't do

  • We do not train machine-learning models on your artifacts.
  • We do not sell your data to third parties.
  • We do not share artifacts across licenses. Every API call is scoped by the authenticated license ID; isolation is enforced server-side.

Third parties

We rely on Stripe (payments) and AWS (infrastructure). Their privacy policies apply to data they handle on our behalf.

Retention

Artifact content is retained indefinitely while your license is active; deleted artifacts are removed from the current manifest but historical manifests remain resolvable (per content-addressed storage design). Billing records are retained per applicable tax law (typically 7 years).

Your rights

You may request export of your data, deletion of your license, or rectification of stored details by writing to privacy@subak.ai.