Privacy Policy
Draft for prototype purposes · Last updated: [date to be set at launch]
This is placeholder legal copy for a product prototype. It is not legal advice and has not been reviewed by counsel. Replace every section with attorney-approved language before launch.
1. What we collect
- Account data: name, email address, and workspace name you provide at sign-up.
- Billing data: handled by our payment processor; we never store full card numbers.
- Operational data: standard infrastructure logs — container health, resource usage, and access timestamps.
2. What we deliberately do not collect
Your prompts, code, sessions, and model responses travel directly between your workspace container and the LLM provider you configured. We do not proxy, inspect, or log that traffic. Your provider API keys are stored encrypted in your workspace's secret store and are never readable by us in plaintext.
3. How we use your data
- To provision and operate your workspace.
- To bill your subscription and send service notices.
- To diagnose infrastructure problems using operational logs.
We do not sell your data or use your workspace contents to train models.
4. Third parties
Your use of any LLM provider (OpenAI, Anthropic, Google, or others) is governed by that provider's own privacy policy. We share account data only with the subprocessors needed to run the service — hosting and payment infrastructure — under data-processing agreements.
5. Retention and deletion
Workspace volumes persist while your subscription is active. When you cancel, your workspace and its volume are deleted after a 30-day grace period. You can export your recipes, extensions, and provider configuration to a local Goose install at any time before deletion.
6. Your rights
You may request a copy of your account data, correct it, or ask for deletion at any time. [Jurisdiction-specific rights language — GDPR, CCPA — to be supplied by counsel.]
7. Contact
[Privacy contact email and legal entity details to be added at launch.]