Legal
Privacy Policy
Last updated 25 July 2026
This policy explains how Fystash (“we”, “us”) handles personal and account data when you use fystash.ai, the control-plane API, and related services.
Who we are
Fystash operates the Fystash multi-agent sandbox platform at fystash.ai and api.fystash.ai. Contact: support@fystash.ai.
What we collect
- Account identity — email and authentication identifiers via our auth provider (InsForge), plus the mapping from your user to a Fystash organisation.
- Billing — payment method and subscription status processed by Stripe. We store Stripe customer / subscription IDs and credit balances; we do not store full card numbers.
- Usage and product data — organisation IDs, API key metadata (names, prefixes, creation times — not secrets after issue), rooms, sandboxes, quotas, credit burns, and audit events needed to run the service.
- Technical logs — request metadata, error logs, and capped command/exec summaries where you use those features.
- Communications — messages you send to support@fystash.ai or through access-request forms.
How we use data
- Provide, secure, and improve the platform
- Authenticate you and authorise API access
- Meter credits, enforce quotas, and process subscriptions
- Respond to support and security incidents
- Comply with law and enforce our Terms
Processors
We use trusted processors, including:
- InsForge — authentication and user–org mapping
- Stripe — payments and billing
- Cloud infrastructure providers hosting the control plane and VMs
- Vercel — hosting the web application
Retention
We keep account, billing, and audit data while your organisation is active and for a reasonable period afterward for security, dispute resolution, and legal compliance. You may request deletion of account data by emailing support@fystash.ai; some records may be retained where required by law or legitimate security needs.
Your choices
- Update or close your account via the product or by contacting us
- Rotate or revoke API keys from Account
- Manage payment methods through Stripe Checkout / billing flows
Security
We use industry-standard practices to protect data in transit and at rest. API keys are shown once at creation or rotation; store them securely. No method of transmission or storage is perfectly secure.
International transfers
Infrastructure and processors may process data in regions outside your own. We take steps appropriate to the service to protect that data.
Children
The service is not directed at children under 16. Do not use Fystash if you are under that age.
Changes
We may update this policy. Material changes will be reflected by the “Last updated” date on this page.
Contact
Privacy questions: support@fystash.ai.