Privacy Policy
Last updated: 2026-05-17 · Plain-language v1
What we collect
- Account: email, display name, hashed password (argon2id), workspace name.
- Usage: conversations you and your visitors have with your agents, message tokens, usage events.
- Knowledge: any text, URLs, or files you upload to a knowledge source.
- Operational: IP + user-agent on session creation and audited admin actions (retained for incident response).
What we do with it
- Run the service for you: store agents, retrieve knowledge, route chat to your LLM provider.
- We do not train models on your data. Model calls go through your own provider keys, against your account.
- We do not sell or share your data with third parties for advertising.
Where it lives
Postgres on infrastructure we operate. LLM credentials, webhook signing secrets, and MCP auth headers are encrypted at rest with AES-256-GCM. Self-hosting is on the roadmap for customers who want full residency control today.
Your rights
- Export your data on request.
- Delete your account at any time via
DELETE /api/v1/me(UI coming). - Ask for an audit of what we've recorded about an admin action — see the audit log.
Contact
hello@fyrasoft.com for anything privacy-related.