1. Introduction
At BeforeWire, we take privacy and enterprise data boundaries seriously. This Privacy Policy explains, at a general level, how we may collect, use, retain, and protect information when you visit our website or use our software, documentation, APIs, examples, local components, hosted services, or enterprise features (the “Service”).
2. Minimal Data Approach
We aim to collect and process only the information needed to operate, secure, support, and improve the Service. Depending on how the Service is configured, many agent runs, checkpoints, artifacts, credentials, logs, and customer systems may remain local or under customer control.
3. Information We May Process
Depending on how you use the Service, we may process:
- account and contact information, such as name, email address, company, role, workspace, preferences, and communication history;
- technical and usage information, such as device information, browser information, IP address, logs, product events, diagnostics, performance data, and anti-abuse signals;
- service configuration information, such as policy settings, workspace settings, integration metadata, access settings, and deployment preferences;
- agent-run related metadata, such as run identifiers, policy hashes, checkpoint identifiers, decision records, approval metadata, action identifiers, receipt hashes, error records, and restore coverage summaries;
- support information that you choose to share with us, such as screenshots, logs, examples, or troubleshooting context.
We do not intend to collect production secrets, full databases, sensitive business records, raw source code, or checkpoint artifacts through the public website. If an enterprise deployment or support workflow requires additional processing, it should be governed by the applicable configuration or written agreement.
4. How We Use Information
We may use information to:
- provide, operate, maintain, and secure the Service;
- authenticate users, manage sessions, and support accounts or workspaces;
- process requests, demos, subscriptions, enterprise evaluations, and support interactions;
- debug issues, improve reliability, understand product usage, and prevent fraud or abuse;
- generate or display receipts, audit summaries, policy summaries, or operational metadata when configured;
- comply with legal obligations and enforce our terms.
5. AI Training
We do not use Customer Content, production data, credentials, private code, run artifacts, receipts, or support materials to train general-purpose AI models unless you expressly authorize that use or a separate written agreement says otherwise.
6. Sharing Information
We may share limited information with service providers that help us operate the Service, such as providers for hosting, analytics, authentication, security, email delivery, support, billing, or infrastructure. We do not sell Customer Content. We may also disclose information if required by law, to protect rights and safety, or in connection with a corporate transaction.
7. Third-Party Integrations
The Service may connect to third-party products, models, repositories, databases, workflow systems, cloud platforms, or enterprise tools. Those third parties may process information according to their own terms and privacy policies. You control which third-party integrations you enable and what permissions they receive.
8. Data Retention
We retain information for as long as reasonably needed to provide the Service, maintain security, support users, comply with legal obligations, resolve disputes, and enforce agreements. Retention may vary by deployment mode, account status, product configuration, enterprise agreement, and the type of information involved.
9. Security
We use reasonable technical and organizational measures designed to protect information from unauthorized access, alteration, disclosure, or destruction. No system is perfectly secure. Customers remain responsible for managing their own credentials, integrations, approval flows, policy configuration, and access permissions.
10. Your Choices and Rights
Depending on applicable law and your relationship with us, you may request access, correction, deletion, export, or restriction of certain personal information. Some information may need to be retained for security, fraud prevention, accounting, legal compliance, dispute resolution, or service integrity.
11. International Processing
The Service may be operated from, or use providers located in, different jurisdictions. Enterprise customers with data residency or cross-border transfer requirements should address those requirements through deployment configuration or a separate written agreement.
12. Children
The Service is intended for business and professional use. It is not intended for children, and we do not knowingly collect personal information from children.
13. Changes to This Policy
We may update this Privacy Policy from time to time. If changes are material, we will make reasonable efforts to provide notice, such as by posting the updated Privacy Policy on this page.
14. Contact
If you have questions about this Privacy Policy or want to make a privacy request, contact us at [email protected]. For security-sensitive reports, contact [email protected].