CAIN-42 CAIN Studio

Privacy

Privacy notice

What we collect, what we never collect, where it goes and how to have it deleted.

Last reviewed 31 August 2026

In short. We process the account, billing and decision-record data needed to run the service, never your agents' prompts, model outputs or training data. There is no third-party analytics and no advertising tracker on these sites. The detailed processor terms are in the data processing addendum.

What we process and how

What we process

Account identifiers and billing contact details; the decision records your agents generate, including the service, path, verdict and stage results; usage counts for metering; and API key fingerprints. We do not require or store your agents' prompts, model outputs or training data.

What we never store in the clear

API keys. They are held as SHA-256 fingerprints, so a database disclosure does not hand anyone a working credential. Card numbers never reach our servers at all -- they are entered on Stripe's own hosted page.

Where it is processed

United States, on infrastructure operated by the hosting provider named in the sub-processor list. The hosted deployment is single-region. If your data may not leave a jurisdiction, the self-hosted deployment processes nothing on our side.

How long we keep it

Decision records and evidence are retained for the life of the account so they remain available for an incident review, which is their entire purpose. Usage counters are retained for billing and reconciliation. Deletion on request is covered below.

Deletion

Write to the privacy address and we will delete your account data, including decision records and evidence, and confirm when it is done. Billing records are retained where tax and accounting law requires it, which we will identify specifically rather than citing a blanket exemption.

Isolation between customers

Every fabric store is tenant-scoped and the tenant is resolved from billing on the server -- never taken from a header the caller controls. Cross-tenant reads return a 404, not a 403, so an identifier cannot be probed for existence.

Sub-processors

Four, listed in full with what reaches each of them. There is no third-party LLM provider, no third-party analytics and no advertising tracker on either site.

Breach notification

We will notify affected customers without undue delay and in any case within 72 hours of becoming aware of a personal data breach, with what we know at the time rather than waiting for a complete picture.

Who else touches your data

Every third party that processes data for the hosted deployment is on the sub-processors page, with what reaches each of them. We publish a new one there before we use it.

Questions and requests

Access, correction and deletion requests, and any privacy question: privacy@cainstudio.online. Security reports go to the disclosure policy.

DPA · Sub-processors · Security · Terms