Last updated: August 2026

Privacy at Iyctt.

We collect the minimum data required to run the service and are explicit about how we use it. This page summarizes what we collect, what we do with it, and your controls.

Scope

This policy covers iyctt.com, our dashboard, APIs, CLIs, and SDKs. It does not cover third-party services you integrate with your workflows — those are governed by their own policies.

What we collect

  • Account data: name, email address, and the organization you belong to.
  • Usage data: API request metadata, workflow names, run counts, and error rates, used for billing and operations.
  • Support data: the content of tickets or contact form submissions you send us.
  • Telemetry: minimal, aggregated, opt-out CLI telemetry (command name, exit code).

We do not sell personal data. We do not run third-party ad trackers on this site.

How we use your email address

Your email is treated as a service-critical identifier and used for three specific purposes:

1. Account verification. When you sign up or change your account email, we send a one-time verification link to confirm you control the address. Without verification, we cannot authenticate sensitive requests.
2. API notifications. If you subscribe to notifications for a workflow — for example, a failed run, a webhook signature failure, or a rate-limit event — we email the address on file. These notifications are configurable per workflow.
3. Service alerts. We send infrequent operational messages: incidents affecting your projects, mandatory security advisories, planned maintenance windows, and legally required policy updates. These cannot be disabled while your account is active because they are required to run the service safely.

Marketing email is opt-in only. If you receive it, every message contains a working unsubscribe link, and unsubscribing does not affect account or service messages.

Storage and retention

  • Account data is retained while your account is active and deleted within 30 days of account closure.
  • Logs are retained per your plan (7, 30, or 90 days) and then permanently deleted.
  • Support tickets are retained for 24 months, or until you request deletion, whichever comes first.

Security

  • All traffic is encrypted with TLS 1.3.
  • Data at rest is encrypted with AES-256.
  • Secrets are stored in an isolated vault and never returned in plaintext outside the runtime.
  • We follow SOC 2 Type II controls and undergo annual third-party audits.

Sub-processors

We use a small set of trusted vendors for infrastructure, email delivery, and payments. A current list is available on request from privacy@iyctt.com.

Your rights

You can access, correct, export, or delete your account data at any time from the dashboard, or by emailing privacy@iyctt.com. We honor requests under GDPR and CCPA and reply within 30 days.

Contact

Privacy questions: privacy@iyctt.com
Security disclosures: security@iyctt.com