Privacy
Last updated: 9 September 2026
This page says what we hold about you, what we hold on behalf of your agents, and what has no storage at all. It covers sallyport.cloud, the console and the API.
- 01
Account data
Your name, email address, organisation and the identifiers of the sessions you sign in with. Sessions are opaque random tokens looked up in our database, and they carry no personal data in themselves. We use this to run your account and to write to you about the service.
- 02
Credentials
Credential values are encrypted with a per-record key derived under a per-tenant key, and there is no route that reads a value back: not for you, not for our staff, not over the API. The only unwrap happens inside the engine for a call already on its way to an upstream. What is visible anywhere in the product is a credential's name, its version and where it is used.
- 03
Call records
Each call produces journal rows: the agent, the workspace, the binding, the class, the method, the host, the path, the decision, who took it and the result. The sensitive parts of a record are sealed to a recipient your tenant holds, which means the process that writes the journal cannot read it back.
- 04
Bodies
Request and response bodies are kept only when you turn capture on for a binding, and they are stored encrypted and referenced from the journal. Notifications never carry a body: a Telegram card or an email holds the target of a call and a link, never its content.
- 05
Website analytics
This site loads Google Analytics for aggregate traffic figures. The contact form is protected by Cloudflare Turnstile, which sees the interaction that proves you are a person. Neither one has access to your account or to anything inside the product.
- 06
Where it lives
The shared service runs in Kazakhstan. A dedicated deployment runs on the hardware and in the region you choose, with the same binary and the same pipeline, which is how teams with a residency requirement use the product.
- 07
How long we keep it
Journal retention follows your plan. Captured bodies follow the quota on your plan and their own time to live. Deleting a tenant destroys the keys that decrypt its records, which makes every one of them unreadable, including by us.
- 08
Sub-processors
Infrastructure providers for hosting and object storage, an email provider for transactional mail, Telegram for approval cards you have linked, and the analytics and captcha services named above. The current list is available on request and changes are announced to account owners.
- 09
Your rights
Ask for a copy of your data, ask for corrections, or ask for deletion, and write to [email protected]. Your journal is exportable from the console at any time without asking anyone.
- 10
Changes
Changes appear on this page with a new date, and material changes are announced to account owners by email before they take effect.