Privacy policy

This page explains the account details, encrypted credentials and request data Dexby Cloud processes, along with the choices you control.

Last updated 4 October 2026

Who we are

Dexby Inc. provides the Dexby runtime, the connector catalog and Dexby Cloud. Questions about this policy go to privacy@dexby.ai. Security reports go to security@dexby.ai.

What we process in Dexby Cloud

  • Account data for the people who administer your workspace: email address, name and sign-in records.
  • Third-party credentials your customers connect, under envelope encryption and never in plaintext at rest.
  • Execution metadata: which tool ran, for which user identifier, when, how long it took and whether it succeeded.
  • Optional request payloads, subject to your project’s request logging settings.

This website

When you submit the contact form we store the email address you provide, along with the optional name, company, role, deployment preference and message you choose to share. We use it to reply to you and to decide which connectors to build next. We do not sell it, we do not enrich it through third-party data brokers, and we do not add you to a newsletter.

What we never do

We do not use your data, prompts or tool results to train models, and we do not sell personal data. Payloads from health-data actions are never retained. Storing payloads from personal-data actions requires an explicit project setting.

Request logs

Each project can turn request logging off, keep request metadata for 30 days, or also keep payloads for 7 days. Payloads include request bodies, query strings and responses. Personal data requires a separate opt-in. Projects handling health data cannot keep payloads. Turning logging off deletes stored request logs and payloads; audit records and usage totals remain.

Retention

Cloud account data is kept for the life of the account. Request logs are kept for 30 days. Request payloads, when a project keeps them, are kept for 7 days. Usage counts per user ID are kept for 13 months. Audit records are kept for 6 years. Credentials are deleted from our database when a connection is revoked; encrypted copies in database backups expire with those backups. Contact form records are kept until you ask us to remove them or until the beta closes.

Your rights

Depending on where you live, you may have the right to access, correct, export or delete your personal data, and to object to some processing. Write to privacy@dexby.ai. If you are an end user of a product built on Dexby, you can also ask that product’s operator.

Changes

Dexby Cloud is in beta and this policy will change as it reaches general availability. We email account administrators before material changes take effect.