Privacy policy
This page explains the account details, encrypted credentials and request data Dexby Cloud processes, along with the choices you control.
Last updated 4 October 2026Who we are
Dexby Inc. provides the Dexby runtime, the connector catalog and Dexby Cloud. Questions about this policy go to privacy@dexby.ai. Security reports go to security@dexby.ai.
What we process in Dexby Cloud
- Account data for the people who administer your workspace: email address, name and sign-in records.
- Third-party credentials your customers connect, under envelope encryption and never in plaintext at rest.
- Execution metadata: which tool ran, for which user identifier, when, how long it took and whether it succeeded.
- Optional request payloads, subject to your project’s request logging settings.
This website
When you submit the contact form we store the email address you provide, along with the optional name, company, role, deployment preference and message you choose to share. We use it to reply to you and to decide which connectors to build next. We do not sell it, we do not enrich it through third-party data brokers, and we do not add you to a newsletter.
What we never do
We do not use your data, prompts or tool results to train models, and we do not sell personal data. Payloads from health-data actions are never retained. Storing payloads from personal-data actions requires an explicit project setting.
Request logs
Each project can turn request logging off, keep request metadata for 30 days, or also keep payloads for 7 days. Payloads include request bodies, query strings and responses. Personal data requires a separate opt-in. Projects handling health data cannot keep payloads. Turning logging off deletes stored request logs and payloads; audit records and usage totals remain.
Retention
Cloud account data is kept for the life of the account. Request logs are kept for 30 days. Request payloads, when a project keeps them, are kept for 7 days. Usage counts per user ID are kept for 13 months. Audit records are kept for 6 years. Credentials are deleted from our database when a connection is revoked; encrypted copies in database backups expire with those backups. Contact form records are kept until you ask us to remove them or until the beta closes.
Your rights
Depending on where you live, you may have the right to access, correct, export or delete your personal data, and to object to some processing. Write to privacy@dexby.ai. If you are an end user of a product built on Dexby, you can also ask that product’s operator.
Changes
Dexby Cloud is in beta and this policy will change as it reaches general availability. We email account administrators before material changes take effect.