legal

Privacy Policy

Last updated June 15, 2026

This policy covers the Cinder website and the Cinder platform. It is written in plain language on purpose. Where a plain-language summary and a legal obligation could diverge, we have chosen the plain language and narrowed our own rights to match.

This is demo content shipped with a website template. It is not legal advice and it has not been reviewed by a lawyer. Replace it with a policy written for your own company before you launch.

Who we are

Cinder Systems, Inc., 2 Kearny Street, Floor 4, San Francisco, CA 94108, USA, is the controller of the personal data described here. You can reach our privacy team at privacy@cinder.dev.

What we collect

From visitors to this website

Page views, referrer, approximate country, and device class, collected by our own analytics running on our own infrastructure. We do not set advertising cookies, we do not use third-party analytics, and there is no cross-site tracking. A single first-party cookie stores your light or dark theme preference; it contains the word light or dark and nothing else.

From account holders

Name, work email address, organisation name, and — if you are on a paid plan — billing details, which are held by our payment processor and not by us. We record authentication events (time, IP address, user agent) and keep them for 90 days for security purposes.

From your telemetry

Whatever your instrumentation sends us. This is the important paragraph, so it is worth being precise about it:

  • Span structure and timing is always sent. Names, durations, parent-child relationships, status codes, token counts, model identifiers.
  • Payload content is opt-in, per attribute. Prompts, responses and tool arguments are captured only where you have explicitly enabled capture for that attribute.
  • Redaction runs in your process, before transmission. The SDK’s redaction hook executes on your infrastructure. Data you redact never reaches us.

We do not read your telemetry. Access by our engineers requires a support ticket from you authorising it, is scoped to the specific traces named in that ticket, expires after 72 hours, and is recorded in an audit log you can request.

We do not train models on your telemetry. There is no exception to this and no setting that changes it.

Why we process it

Purpose Lawful basis (UK/EU GDPR)
Providing the platform you signed up for Performance of a contract
Billing and invoicing Performance of a contract
Security monitoring and fraud prevention Legitimate interests
First-party website analytics Legitimate interests
Product and service emails Performance of a contract
Marketing emails Consent, withdrawable at any time

How long we keep it

Telemetry is deleted at the end of your plan’s retention window — 7 days on Developer, 30 days on Team, 90 days on Scale, configurable on Enterprise. This is automatic and we cannot extend it retroactively.

Account records are kept while your account is open and for 30 days after closure. Authentication events are kept for 90 days. Invoices are kept for seven years because tax law requires it.

Deletion propagates to backups within a further 35 days, which is the maximum age of any backup we hold.

Who we share it with

Sub-processors only, listed here with what each one handles:

  • Amazon Web Services (us-east-1, eu-west-1) — infrastructure and storage
  • Stripe — payment processing and invoicing
  • Postmark — transactional email
  • Anthropic — powers the optional trace-summarisation feature; disabled by default and never fed opted-out payload content

We do not sell personal data, and we do not share it with advertisers. If we are ever acquired, this policy travels with the data, and you will be told before anything about it changes.

Where it goes

Data is processed in the United States and the European Union. You choose your ingest region at project creation and telemetry does not leave it. Transfers between our own regions rely on Standard Contractual Clauses.

Your rights

You can request access, correction, deletion, restriction, portability, or object to processing based on legitimate interests. Email privacy@cinder.dev and we will respond within 30 days. Most of these are also self-service in account settings, which is faster.

If you are in the UK or EU and we have not resolved something to your satisfaction, you may complain to your national supervisory authority.

Security

TLS 1.3 in transit, AES-256 at rest, SSO and enforced MFA available on all paid plans, least-privilege internal access with quarterly review. We publish a SOC 2 Type II report under NDA — email security@cinder.dev.

If you believe you have found a vulnerability, security@cinder.dev is monitored by a human and we will acknowledge within one business day.

Changes

Material changes are announced by email to account holders at least 30 days before they take effect. The date at the top of this page is the last revision.