Short version. RustGrid uses account and operational data to provide and secure the Service. Customer workflow, repository, and mission data is processed on the customer’s instructions. Optional analytics stays off until consent. Payment credentials go to Stripe’s embedded components, not RustGrid’s own forms. RustGrid does not sell personal data.
01
Scope, responsible operator, and roles
This policy applies to RustGrid websites, hosted applications, APIs, agent-control-plane features, billing, support, and related hosted services (the “Service”). “RustGrid” means the service operator identified on the applicable checkout, invoice, order form, or enterprise agreement. Contact: hello@rustgrid.com.
RustGrid is a controller for data used to run its own business, including website analytics, account administration, security, support, and billing. RustGrid generally acts as a processor or service provider for customer-submitted workflow, repository, attachment, and mission data. The customer decides what is submitted, who can access it, which integrations and model providers are enabled, and how long it is needed.
A signed order, data-processing agreement, or other written contract controls if it conflicts with this policy for covered processing.
02
Personal data and Customer Data we handle
| Category | Examples |
|---|---|
| Account and identity | Name, email, password hash, verification state, OAuth identifiers, avatar URL, active status, memberships, roles, and permissions. |
| Workspace and workflow | Tenants, projects, tickets or missions, descriptions, comments, labels, sprints, custom fields, attachments, watchers, invitations, links, and activity history. |
| Repository and integration | GitHub account, installation, and repository identifiers; permissions; branches, commits, pull requests, reviews, workflow state, webhook events, delivery outcomes, and configuration. |
| Agent execution | Prompts, manifests and policies, worker identity and health, run and step state, bounded command and quality-gate output, file paths, tool and model-call telemetry, token usage, timing, failures, and pull-request links. |
| Security and diagnostics | Session and device state, API-key metadata and scopes, token hashes, request IDs, IP or anonymized IP, user agent, timestamps, rate limits, security events, and logs. Plaintext API keys are returned only at creation. |
| Billing | Billing contact, plan, entitlements, usage, Stripe customer, price, Checkout, invoice, subscription, tax, refund, dispute, payment, and cancellation status. RustGrid does not store full card or bank credentials. |
| Website and communications | Pages, clicks, consent choice, browser and device information, referrer, approximate region, support messages, and email delivery events. |
Free-form tickets, comments, repositories, files, prompts, and output can contain personal or confidential data selected by a customer. Do not submit special-category or highly regulated data unless a written agreement permits it and the deployment is configured for it.
03
Where data comes from
- You and your organization when you register, configure a workspace, create records, connect integrations, run agents, subscribe, or contact us.
- Authorized users when teammates invite, assign, mention, or add information about you.
- Connected services including GitHub, Google or GitHub OAuth, Stripe, webhooks, and customer-selected model or tool providers.
- Browsers, devices, APIs, and workers through requests, security controls, storage, telemetry, logs, heartbeats, and execution events.
04
Purposes and legal bases
Where the GDPR or similar law applies, RustGrid relies on:
- Contract to administer accounts and provide authentication, tenant-scoped APIs, workflows, integrations, agent execution, support, usage measurement, and paid plans.
- Legitimate interests to secure the Service, prevent abuse, diagnose failures, maintain reliability, improve usability, protect rights, and establish or defend claims, after considering individual rights.
- Consent for optional website analytics and any processing where consent is specifically requested. Consent can be withdrawn at any time.
- Legal obligation for tax and accounting records, valid legal process, sanctions, and other compliance duties.
RustGrid does not use customer repository or mission content to train a RustGrid foundation model. Aggregate or de-identified measurements may be used for capacity, reliability, and product improvement when they no longer identify an individual or customer.
05
AI agents, source code, and model providers
Agent runs can read mission instructions, comments, attachments, source, dependencies, and prior state; generate code and text; run commands and quality gates; create branches; and publish pull requests under configured manifests, permissions, and approval gates.
Run content may be sent to customer-selected model and tool providers. For the RustGrid agent this may include OpenAI Codex under the customer’s configured OpenAI or ChatGPT relationship. Provider terms govern their independent processing. Provider credentials are intended to stay outside customer-visible records, but prompts, outputs, usage, model identity, and run events may be operational data.
Worker output is normally bounded, but failure excerpts and quality-gate records may contain tenant-sensitive text. Failed or interrupted workspaces may temporarily retain proprietary source and local audit output for recovery.
08
Retention, deactivation, and deletion
RustGrid keeps data only as reasonably needed for the stated purpose, the customer’s plan or contract, security and recovery, and legal duties. Exact periods depend on data type, configuration, and deployment:
- Account, workspace, workflow, billing, and integration records generally remain during the relationship and afterward as needed for contractual, legal, security, or dispute purposes.
- Plan-based audit availability differs by plan and is not necessarily the same as deletion from backups or legally required records.
- Current software defaults include 30 days for agent events, 30 days for webhook outbox and attempts, and 90 days for webhook deliveries. Deployments or contracts may differ.
- The RustGrid agent defaults to retaining failed local workspaces for 72 hours, configurable up to 30 days. Successful workspaces are cleaned by the worker lifecycle. Self-hosted operators control actual storage, access, backup, and cleanup.
- Security, tax, invoice, payment, abuse-prevention, and legal-claim records may be kept longer. Backups expire on their normal protection cycle.
Account deactivation blocks normal access but is not erasure. Request deletion or export at hello@rustgrid.com. RustGrid will verify the requester and consider customer instructions, other users’ rights, security, and legal retention.
09
International transfers
RustGrid and providers may process data outside the user’s country. Where required, RustGrid uses an appropriate safeguard such as an adequacy decision, standard contractual clauses, or another lawful mechanism. Residency is not guaranteed unless a signed contract says so.
10
Security and deployment boundaries
Controls include tenant-derived authorization, explicit roles and API-key scopes, one-time API-key display, signed GitHub webhooks, short-lived run credentials, request tracing, bounded telemetry, secret redaction, and isolated production execution. No system is completely secure, and worker hosts, storage, encryption, networking, secrets, backups, and cleanup remain deployment responsibilities. Read RustGrid Security or report vulnerabilities privately to security@rustgrid.com.
11
Your privacy rights
Depending on law, you may have rights to information, access, correction, deletion, restriction, objection, portability, withdrawal of consent, and a complaint to a supervisory authority. Some rights are limited by law or others’ rights. Email hello@rustgrid.com with the account email and request, but never a password, API key, or model credential. If RustGrid processes data only for a customer, it may refer the request to that customer. EEA residents can find authority information in the European Commission’s guidance.
12
Customer responsibilities
Customers must have a lawful basis for submitted data; give required notices; configure permissions, webhooks, model providers, retention, and workers; respond to requests for customer-controlled data; and avoid unnecessary personal data or secrets in prompts, tickets, repositories, logs, and output.
13
Children
The Service is a business and developer platform, not directed to children. Users must be at least 18 or the age of legal majority. RustGrid does not knowingly collect children’s data through the Service.
14
Changes
RustGrid may update this policy as the Service, providers, or law changes. The date above will be revised, and material changes will be communicated through the Service, by email, or another reasonable method when required.
15
Contact
Privacy requests, data-processing questions, and DPA requests: hello@rustgrid.com. Security reports: security@rustgrid.com.