Privacy Policy

Last updated: September 9, 2026

On this page

On this page

  1. 1. Information We Collect
  2. 2. How We Use Your Information
  3. 3. Data Isolation
  4. 4. Data Security
  5. 5. Data Retention
  6. 6. Data Sharing
  7. 7. Cookies and Website Analytics
  8. 8. Your Rights
  9. 9. Children's Privacy
  10. 10. Changes to This Policy

This Privacy Policy describes how Aegara AI ("we", "us", or "our") collects, uses, and protects your information when you use our platform, APIs, and related services (the "Service").

1. Information We Collect

Account Information: When you register, we collect your company name, email address, and a hashed version of your password. We never store passwords in plain text.

Observability Data: When you integrate the Service, your AI systems send event data (AI Action Events) to our platform. This data includes action primitives (READ, WRITE, TRANSFORM, CALL, STORE, ROUTE), metadata, and trace information as defined by your integration. AI Action Events carry behavioral metadata only: the content of your AI interactions (prompts, responses, file contents, data values) is not part of the event schema, and our ingestion validation rejects events that appear to contain such content.

Edge Value Inspection: Aegara checks structured values in your AI tool calls for sensitive data. The checking runs inside your own environment, on your own systems. Only the verdict reaches us: a field's name path, the identifier of the pattern that matched, a sensitivity level, a category, and counts. The values themselves, and any fragment or hash of them, are never transmitted or stored. Free-form text is not inspected; only structured tool arguments and tool results are.

Usage Data: We automatically collect information about how you use the Service, including API call volume, timestamps, and feature usage.

2. How We Use Your Information

Data TypePurpose
Account infoAuthentication, account management, service communications
Observability dataProviding the core Service - dashboards, traces, analytics
Usage dataImproving the Service, capacity planning, abuse prevention

3. Data Isolation

Each customer's data is strictly isolated by organization ID. Your observability data is not accessible by other customers. API keys are scoped to your organization and cannot access data belonging to other organizations.

4. Data Security

We implement industry-standard security measures to protect your data:

  • Passwords are hashed using scrypt with random salts
  • Authentication tokens are signed with HMAC-SHA256
  • API keys are securely generated and can be revoked at any time
  • All connections in production use HTTPS/TLS encryption
  • Rate limiting protects against brute-force attacks

5. Data Retention

We retain your account information for as long as your account is active. Observability event data is retained according to your plan's retention period. You may request deletion of your account and associated data by contacting us.

6. Data Sharing

We do not sell, rent, or share your personal information or Customer Data with third parties for marketing purposes. We may share data only in the following circumstances:

  • Service providers: With trusted providers who help us operate the Service (e.g., hosting, email delivery), bound by confidentiality obligations
  • Legal requirements: When required by law, regulation, or valid legal process
  • Safety: To protect the rights, property, or safety of Aegara AI, our users, or the public

7. Cookies and Website Analytics

Essential cookies. We set HttpOnly authentication cookies that are required for secure session management when you sign in to the portal or admin panel. These cookies do not leave your browser and are not shared with any third party.

Website visitor analytics. We use Google Analytics 4 on the public aegara.ai website to understand visitor traffic (pageviews, referrers, country, device class). GA4 sets first-party cookies in your browser (the _ga family) for this purpose. You can opt out of GA4 at any time using Google's opt-out browser add-on.

What we do NOT do. We do not use advertising cookies, retargeting pixels, or cross-site tracking. We do not combine website visitor analytics with Customer Data (the AI Action Events you send through our SDK, LangChain handler, or Direct API). Visitor analytics is purely for understanding aegara.ai traffic; Customer Data lives in your organization's isolated tenant and is never analyzed for marketing.

8. Your Rights

Whatever privacy law applies to you, you can do all of the following, and you can do most of them yourself.

  • See the account information we hold about you, on your Profile page
  • Correct it there
  • Export your observability data through the API, on any plan
  • Revoke and rotate API keys from the Trace Portal at any time
  • Ask us to delete your account and everything associated with it, by getting in touch

We are the processor for the observability data you send us and you are the controller of it: you decide what your systems record, and we hold it on your instruction. We are the controller of your account information, which is your company name, your email address and a hashed password.

If you need a data processing agreement, get in touch and we will put one in place before you send us anything.

9. Children's Privacy

The Service is not directed to individuals under the age of 16, and we do not knowingly collect or sell the personal information of children under 16. If you believe we have inadvertently collected such information, contact us and we will delete it.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email or through the Service. The "Last updated" date at the top of this page indicates when this policy was last revised.

If you have questions about this Privacy Policy or our data practices, get in touch.

Terms of Service · Back to home