Legal

Privacy policy.

Last updated: January 2026. We collect the minimum we need, store it securely, and never sell it.

1. What we collect

  • Account data — email, name, OAuth provider IDs.
  • Usage data — agent invocations, tool calls, approval decisions, audit log entries.
  • Connector data — tokens you authorize Pantheon to use on your behalf (encrypted at rest).
  • Telemetry — anonymized error reports, latency, feature usage.

2. Why we collect it

To run the product, generate audit trails you actually need, debug issues, and improve features. We do not sell, rent, or trade personal data.

3. Sub-processors

  • Supabase — managed Postgres + Auth (data stored in EU/US per workspace setting)
  • Stripe — billing
  • Anthropic / OpenAI / Google — model providers (only when you route requests to them)
  • Vercel / Fly.io — hosting

4. Your rights (GDPR / CCPA)

You can export, correct, or delete your data at any time. Email us and we'll process within 30 days.

5. Contact

Questions? Email me@nikhilbindal.com.