Legal
Privacy Policy
Last updated: July 1, 2026
This Privacy Policy describes how Cayu Technologies, Inc. ("Cayu," "we," "us," or "our") collects, uses, and protects information when you use our websites, platform software, documentation, and related professional services (collectively, the "Services").
The Services are primarily offered to businesses. If you use the Services on behalf of a company, "you" may refer to that organization, and we process business contact and customer data as described here and in any applicable order form, statement of work, or data processing terms.
By using the Services, you agree to this Privacy Policy. If you do not agree, please do not use the Services.
Changes to this Privacy Policy
We may update this Privacy Policy from time to time. When we make changes, we will update the "Last updated" date. For material updates, we will notify you through the Services or via email at least thirty (30) days before the effective date where practical.
Collection and Use of Your Information
We collect information to operate, improve, and secure the Services. This includes information you provide, information collected automatically, and information from third-party sources.
Information You Provide to Us
Account and business contact information may include:
- Name and work email address
- Company name, role, and professional information
- Password or authentication credentials
- Credentials you supply to connect third-party systems (for example GitHub, databases, or cloud providers), stored and used only to provide the connection you request
- Billing and invoicing details for paid engagements
Customer Content and operational data may include content you create, upload, or authorize us to process when delivering the Services, such as:
- Code, projects, files, and configuration
- Commands, workflows, and agent interactions or prompts
- Deployment artifacts, runtime logs, and operational telemetry needed to run or support a system
- Database queries, schemas, and metadata you connect or provide
- Business process materials needed for an engagement
Communications may include:
- Customer support messages
- Feedback and survey responses
- Bug reports and feature requests
- Sales and partnership correspondence
Information Collected Automatically
Device and technical information may include:
- Device type and identifiers
- Operating system and environment details
- IP address and approximate geolocation (country or region level)
- Browser type and application or client version information
Usage information may include:
- Features used and actions taken in the Services
- Performance metrics and resource utilization
- Error logs and debugging data
- Build, run, deployment, and session events
Analytics. We may use analytics tools (such as PostHog, Google Analytics, or similar services) to understand how visitors and users interact with the Services, including feature adoption, error patterns, flows, and performance. Where required, we honor applicable consent preferences. Analytics on our marketing site may be more limited than analytics inside an authenticated product environment.
Information From Other Sources
- Analytics providers
- Information you choose to share when connecting third-party platforms
- Publicly available business information or data provided by partners in connection with an engagement
How We Use Your Information
We use the information we collect to:
Provide and improve the Services
- Authenticate users and maintain accounts
- Deliver professional services, deployments, and ongoing operations
- Execute builds, runs, and integrations you request
- Connect to third-party services at your request
- Process invoices, subscriptions, and transactions
- Improve product quality, reliability, and operator workflows
- Fix bugs and develop new capabilities
Communications
- Respond to support and sales requests
- Notify you about system, security, or account events
- Provide product or service updates related to your engagement
- Send marketing communications where permitted (you may opt out of marketing emails)
Security and compliance
- Detect and prevent fraud, abuse, or unauthorized access
- Secure execution of workloads
- Comply with legal obligations
- Enforce our Terms of Service
Analytics and internal research
- Understand aggregated usage patterns
- Improve workflow efficiency and service quality
- Conduct internal research and development that does not train public or third-party foundation models on your Customer Content without your explicit consent
Your Data Belongs to You
Customer Content remains yours. We do not claim ownership of your projects, code, or business data. We do not use Customer Content to train foundation models for unrelated customers or public model providers without your explicit written consent. Customer Content is processed to provide, secure, and support the Services for you, and remains isolated according to our access controls and any engagement- specific commitments.
Cookies and Tracking Technologies
We use cookies, pixels, and similar technologies to:
- Maintain sessions
- Understand usage patterns
- Improve performance
- Support analytics and, where applicable, marketing measurement
You can disable cookies in your browser settings, although some features may not function properly.
Disclosure of Your Information
We do not sell personal information. We may share information in the following scenarios:
Service providers
We work with trusted vendors for functions such as:
- Cloud hosting (regions as applicable to the engagement)
- Data storage
- Payment and invoicing processing
- Analytics
- Customer support tooling
- Model and AI infrastructure providers acting on our instructions
- Security and monitoring
These providers are permitted to process information only to perform services for us and under appropriate confidentiality and security obligations.
Connected services
When you or your organization link third-party tools, we share only what is necessary to enable those connections, such as access tokens (stored securely), repository metadata, or connection information you authorize.
Legal requirements
We may disclose information:
- To comply with laws or regulations
- In response to lawful requests such as court orders or subpoenas
- To protect our rights, users, or the security of the Services
Business transfers
If we undergo a merger, acquisition, financing, or similar transaction, information may be transferred as part of that deal. We will provide notice before personal information is transferred in a manner that becomes subject to a different privacy policy, where required.
With your consent
We will share information when you explicitly authorize it.
Third-Party Links and Integrations
The Services may include integrations with or links to third-party platforms. Information you share through those features is subject to the third party's own policies.
Children's Privacy
The Services are directed to businesses and are not intended for children under 13 (or the equivalent minimum age in your jurisdiction). We do not knowingly collect personal information from children. If we learn that we have collected such data, we will delete it promptly.
Data Security and Retention
We apply industry-standard measures intended to protect data, which may include:
- Encryption in transit and at rest where appropriate
- Secure development and deployment practices
- Multi-factor authentication and access controls
- Monitoring for security events
No method of transmission or storage is completely secure. We retain information as long as needed to provide the Services, meet contractual commitments, resolve disputes, and comply with legal obligations. When no longer needed, data is deleted or anonymized according to our retention practices and any applicable Order.
International Transfers
We may process information in the United States and other countries where we or our providers operate. Where required, we use appropriate transfer mechanisms and contractual protections.
Your Rights and Choices
Depending on your jurisdiction, you may have rights to:
- Access your personal data
- Correct inaccurate data
- Request deletion of your data
- Restrict or object to certain processing
- Withdraw consent where processing is consent-based
- Request data portability
To exercise these rights, contact contact@cayu.ai. We aim to respond within seven (7) business days, or sooner if required by law. If you are an end user of a Customer organization, we may refer your request to that Customer where they are the controller of the data.
You may opt out of marketing emails using the unsubscribe link in those messages or by emailing us.
Complaints
If you have concerns about how your information is handled, contact contact@cayu.ai. You may also contact your local data protection authority.
How to Contact Us
For questions about this Privacy Policy or our practices:
Cayu Technologies, Inc.
Email:
contact@cayu.ai
For urgent privacy matters, include "PRIVACY URGENT" in the subject line.