substructure.ai
DocsPricingllms.txtGitHub

Privacy policy

Last updated 6 August 2026

This policy covers substructure.ai and the hosted dashboard at app.substructure.ai. It describes the hosted service. Running the open-source engine yourself puts your data on your own infrastructure, and none of this applies to it.

What we collect

  • Account details. Your email address, and the name and avatar your identity provider returns if you sign in with Google or GitHub. Email addresses of people you invite to an organization.
  • Billing details. Payments run through Stripe on Stripe-hosted pages. Card numbers never reach our servers. We store the Stripe customer and subscription identifiers, which plan an organization is on, and when the current period ends.
  • What you build. Project and agent configuration, the manifest you apply, and the log of every change to it.
  • What your agents do. A durable event log for every session: the messages in and out, tool calls and their results, sub-agent runs, approval steps, and per-turn token counts. Records of calls to your model provider and of webhook deliveries to your worker, including request and response bodies.
  • Content from services you connect. If you connect Slack, that includes messages in the channels an agent is present in, and the mentions and direct messages sent to it. If you connect MCP servers, it includes what those tools return.
  • Credentials. Your model provider API keys, Slack bot tokens, and MCP OAuth tokens. These are encrypted with AES-256-GCM before they are written, and are only decrypted in memory to make the call you configured.
  • Analytics. Google Analytics 4 sets _ga cookies on substructure.ai and app.substructure.ai to count visits and to tell whether a signup began on the marketing site. When a subscription is purchased, our server reports the sale to Google Analytics with the amount Stripe charged.
  • Operational logs. Ordinary server logs — request paths, timings, status codes, IP addresses — kept for debugging and abuse investigation.

Why we collect it

To run the service you asked for: executing agent turns, keeping sessions durable across restarts, delivering webhooks, enforcing the limits your plan sets, and billing you. To keep accounts secure and investigate abuse. To understand which parts of the site lead to signups.

We do not sell personal information, and we do not use the content of your agent sessions to train models.

Who else sees it

We use a small number of providers to run the service. Each receives only what its job needs.

  • Fly.io — hosting and compute. The application and its database run here.
  • Cloudflare — the marketing site, encrypted database backups, and delivery of sign-in emails.
  • Stripe — payments, subscriptions, and invoices. Stripe receives your payment details directly and handles them under its own privacy policy.
  • Google Analytics — website and dashboard usage measurement.

Separately, your agents call the model provider whose API key you supply, and any MCP servers and webhook workers you point them at. Those are your integrations, not our subprocessors: what you send them is governed by your agreement with them. Because you bring your own key, we never act as an intermediary for your model spend.

We may disclose information if the law requires it, or if a company acquires the service — in which case this policy travels with the data until it is replaced by one you are told about.

How long we keep it

Session history is a plan entitlement: depending on the plan, sessions and their event logs are retained for 14 to 365 days, then removed. See pricing for the window each plan carries.

Account, organization, and billing records are kept while the account is open, and afterwards only as long as we need them for tax and accounting. Encrypted database backups are retained on a rolling basis, so deleted data can persist in a backup for a short period after it is gone from the live system. Deleting a project purges its data and leaves only the append-only record that it existed and was deleted.

Security

Traffic is served over TLS. Credentials that the system must read back — model provider keys, Slack tokens, MCP tokens — are encrypted at rest under a key held outside the database. Database backups are encrypted in transit and at rest. Data is stored in the United States.

No system is perfectly secure, and we do not claim otherwise. If you believe you have found a vulnerability, write to support@substructure.ai before disclosing it publicly.

Your choices

  • Analytics. Blocking cookies or using a tracker blocker stops the_ga cookies. The service works normally without them.
  • Access and deletion. Write to support@substructure.ai to get a copy of what we hold about you, correct it, or have your account and its data deleted.
  • Disconnecting a service. Removing a Slack install or an MCP connection revokes the stored token and stops any further collection through it.

Children

The service is not directed at children, and is not intended for anyone under 16.

Changes

We will update this page when what we collect changes, and move the date at the top. Continuing to use the service after a change means the updated policy applies.

Contact

Questions about this policy, or about the data we hold on you: support@substructure.ai.

DocsPricingTermsGitHub