Privacy Policy

Last updated: July 24, 2026

Early-access draft, written to be read: this is the plain truth of how we handle data, and counsel will formalize it before commercial launch.

What we collect

Your account details (name, email), the business data you put in (contacts, projects, documents, messages), and basic usage logs (what happened when — the same audit trail you can see in the product).

Your clients' information reaches us because YOU add it. For that data we act as a processor on your behalf: you decide what's stored and when it's deleted.

What we never do

We don't sell your data or your clients' data. We don't use your business data to advertise to anyone. We don't train AI models on your data.

AI features

AI features run only when you or your workspace enables and deliberately uses them. They may use a clearly identified Cygnetree allowance or the provider and key your workspace selected. Only the material needed for the requested task is sent; the provider, purpose, and approval step remain visible.

Who else touches data

A short list of processors runs the service: Vercel (hosting), Neon (database), Stripe (payments — money goes directly between you and your clients), Resend (email delivery), Inngest (background jobs), Sentry (error monitoring). Each sees only what's needed for its job.

Security

Data is encrypted in transit (TLS) and at rest. Especially sensitive values — connected-account tokens, API credentials — are additionally encrypted at the application level. Sign-in links and portal links are signed and time-limited. Staff access to customer workspaces is time-boxed, banner-visible, and logged.

Your controls

Export your contacts anytime; download any document. Close your account and we delete your data within 30 days (excluding records we must keep by law). Email hello@cygnetree.com for any privacy request and a human will handle it.

See also our Terms of Service.