Scope
This policy covers iyctt.com, our dashboard, APIs, CLIs, and SDKs. It does not cover third-party services you integrate with your workflows — those are governed by their own policies.
What we collect
- Account data: name, email address, and the organization you belong to.
- Usage data: API request metadata, workflow names, run counts, and error rates, used for billing and operations.
- Support data: the content of tickets or contact form submissions you send us.
- Telemetry: minimal, aggregated, opt-out CLI telemetry (command name, exit code).
We do not sell personal data. We do not run third-party ad trackers on this site.
How we use your email address
Your email is treated as a service-critical identifier and used for three specific purposes:
Marketing email is opt-in only. If you receive it, every message contains a working unsubscribe link, and unsubscribing does not affect account or service messages.
Storage and retention
- Account data is retained while your account is active and deleted within 30 days of account closure.
- Logs are retained per your plan (7, 30, or 90 days) and then permanently deleted.
- Support tickets are retained for 24 months, or until you request deletion, whichever comes first.
Security
- All traffic is encrypted with TLS 1.3.
- Data at rest is encrypted with AES-256.
- Secrets are stored in an isolated vault and never returned in plaintext outside the runtime.
- We follow SOC 2 Type II controls and undergo annual third-party audits.
Sub-processors
We use a small set of trusted vendors for infrastructure, email delivery, and payments. A current list is available on request from privacy@iyctt.com.
Your rights
You can access, correct, export, or delete your account data at any time from the dashboard, or by emailing privacy@iyctt.com. We honor requests under GDPR and CCPA and reply within 30 days.
Contact
Privacy questions: privacy@iyctt.com
Security disclosures: security@iyctt.com