Account and authentication information
When you register we collect your email address, a hashed password credential, your company name, and any App IDs issued to your account. We do not store your password in plain text.
Billing information
We collect the billing details you enter — legal or trading name, billing address, country, and where applicable a tax identification number such as a GSTIN. Card details are collected and stored by our payment processor; we do not receive or store full card numbers. We retain payment references, invoice records, amounts, and payment status.
Usage telemetry
The Operate container reports metering events to us so we can bill accurately. Each event contains an App ID, token counts, the model name, the agent type, and a duration. It does not contain your logs, your database records, your source code, or the content of an investigation.
Infrastructure and integration credentials
Credentials for your own systems and connected services are configured in your deployment and are held in your infrastructure. Where you explicitly authorise a hosted integration from your account (for example connecting a code host so Operate can open a draft pull request), we store the resulting installation identifier and a hashed installation secret needed to operate that integration.
Customer-provided data
Data you or your users submit directly into our website or dashboard — support messages, form content, correspondence — is collected as submitted.
Website and technical metadata
Our hosting and infrastructure providers process standard request metadata, including IP address, user agent, timestamps, and requested paths, for delivery, availability, and abuse prevention.