Full privacy policy is being finalized for v3.1. Until then: we store the minimum needed to operate (tenant data, user identities, AI usage events you choose to ingest), encrypt vendor API keys at rest with AES-GCM, retain ledger data per your plan, and never sell, share, or use your data to train models. Contact [email protected] with questions.