Privacy policy
Last updated September 2026. Public policy for hosted cloud.
You are the controller for chat your users send through your app. We store what the Worker needs to run rooms: messages, presence, Yjs documents, attachments if you upload them, and account/billing fields. Dashboard login may use Clerk.
Export and delete for a signed-in operator: console /privacy (JWT required). DPA: /dpa. Processors: /subprocessors.
Default retention
- Messages. 365 days by default; soft-deleted rows are purged on schedule
- Audit events. 90 days
- Agent runs. 180 days
- Usage records. 730 days (24 months) for billing reconciliation
- Webhook deliveries. 30 days
Processors (summary)
- Cloudflare. Hosts the Worker, D1, R2, and Durable Objects when you deploy on Cloudflare
- Clerk. Hosted sign-in for the dashboard (optional; only if NEXT_PUBLIC_CLERK_PUBLISHABLE_KEY is set)
- Stripe. Subscription billing when payments are enabled on your Worker
- OpenAI / Anthropic (or your gateway). LLM inference when in-room agents are configured to call them