Last updated September 2026
Privacy Policy
What this website collects, and how attest_tag handles data when you run it. The binding version of the product half is the data processing agreement, which we countersign before you sign anything.
What we collect
Details you give us. If you fill in the form on /contact we receive the fields you typed — your name, work email, company, workspace size, role and message — and email them to ourselves so we can reply. They are not stored in a database on this site, because there is no database on this site. For customers we also hold the ordinary account and billing details: who the admins are, their work email addresses, and the company’s billing contact.
Content the product processes. The threads attest_tag is mentioned in, the channels its tools are asked about, the documents you upload, and the responses that come back from services you connect. Whatever is in that content is in it — including personal data about your people and whoever they are writing about.
Operational records. Sessions, turns, tool calls, proxied requests, token counts and cost, the memories you asked it to keep, the routines you created, and the artifacts it produced. This is what makes the audit trail an audit trail. Web servers also keep ordinary request logs, which include IP addresses, for a short period; a submitting IP is held in memory for ten minutes to rate-limit the contact form.
Your workspace’s data is yours
You own the content that goes through attest_tag. We process it to run the service for you and for nothing else — not to build a product, not to profile anyone, not to sell or share with anyone.
Deployments are isolated from one another: one workspace’s data is never mixed with another’s, and attest_tag is built to run on infrastructure you control, which is the strongest form of that isolation there is. Everything is encrypted in transit with TLS and at rest by the storage layer.
Threads are rebuilt from Slack on every turn rather than mirrored into a separate copy of your workspace. Credentials for connected services are sealed with AES-256-GCM under a master key held in your environment, injected by the proxy at call time; they are never placed in a prompt and never returned to a Slack thread.
No training on your data
Your threads, documents, tool results and artifacts are never used to develop, train, fine-tune or evaluate a model — by us or by any provider we route through. Model calls go out with deny-training routing on by default, so a turn only reaches providers contractually barred from training on the prompt. If you point the product at your own endpoint instead, that endpoint’s terms apply and the choice is yours.
Where data goes, and who else is involved
The one thing that necessarily leaves your infrastructure is the model call, to the endpoint you configured. Calls to services you have connected go to those services, at the hosts you allow-listed and nowhere else.
For this website: our hosting provider, and Resend for delivering contact-form email. For a hosted deployment, the current list is on the subprocessors page — every one of them under written terms as protective as these, and none of them permitted to train on your data. If you run it yourself, the list is yours rather than ours: the model endpoint and the services you chose to connect.
We may disclose data if the law compels us to. Where we are allowed to tell you first, we will.
Retention and deletion
Operational records are kept for as long as your account is active, because that is what makes them auditable. You can delete documents, sessions, memories and artifacts from the console at any time, and deletion means deletion rather than a hidden flag.
Contact-form email sits in our inbox for as long as the conversation is live, and we clear out leads that went nowhere once a year. Server request logs age out within thirty days.
On termination, customer data is deleted within thirty days — or returned first if you ask inside that window. Backups age out on their own schedule and are gone within ninety days. We keep billing records for as long as tax law requires and nothing else.
Security
Encryption in transit and at rest; sealed credentials the model never sees; outbound calls limited to hosts you allow-list; per-deployment isolation; and an audit ledger of every tool call, proxied request and confirmed write.
Actions that change something in a connected system wait for a person, and the confirmation is recorded against the human who gave it. Access to a deployment for support is on request and on the record — we do not read your threads as a matter of routine, and there is no internal dashboard that shows them.
If a breach affects your data we will tell you without undue delay and within seventy-two hours, with what we know and what you need for your own notifications. More on the guardrails is on the guardrails page.
Your choices and your rights
Email [email protected] to ask what we hold about you, to correct it, to get a copy of it, to object to how it is used, or to have it deleted. We will answer within thirty days, and we will not charge you for a reasonable request or treat you differently for making one.
For data inside a deployment you run, you already hold it: it is your database file and your documents, and the console can export or delete it without asking us. If you are an employee of a customer asking about data in your employer’s workspace, they are the controller — ask them, and we will help them answer.
Cookies and tracking
This site has no analytics script, no advertising pixel, no session cookie and no tracker on any page. That is not a setting you have to find; it is the absence of code, which is why there is no consent banner to dismiss. The admin console sets one cookie, for your sign-in session, and nothing else.
Children
attest_tag is a product for workplaces. It is not directed at children, and we do not knowingly collect data from anyone under sixteen. If you think we have, tell us and we will delete it.
Changes
We may update this policy as the product and the law change. If a change materially affects how we handle your data we will say so before it takes effect, by email or in the product. The date at the top of this page is the version in force.
Contact
Attest Tag is the company behind attest_tag. Privacy questions, deletion requests and security questionnaires: [email protected]. See also the subprocessors page and the data processing agreement.