Skip to content

Legal

Privacy Policy

Last updated August 2026

What we hold

We store the data your organization brings to the platform: your users and roles, the agents and skills you configure, the runs they perform, the credentials you connect (held encrypted), and the audit trail of consequential actions. We store what is needed to run the service and to let you prove what happened.

Isolation between organizations

Every record is scoped to the organization that owns it and that scoping is enforced in the database with row-level security, not left to application code to remember. There is no legitimate path by which one organization's agents or people can reach another's data.

How agents use data

Retrieved documents and tool output are treated as untrusted reference data, never as instructions. Provider credentials are held only by the isolated runtime that needs them and never exposed to the browser. Tokens, keys, and secrets are kept out of logs.

Retention and deletion

Your plan defines how long run history is retained. You can delete data your organization owns; deletions are recorded in the audit trail. Some records required for billing and security may be retained for as long as the law requires.

Subprocessors

chAIn relies on infrastructure and model providers to deliver the service. We share only what is necessary for them to perform their function, and provider details are never surfaced to your end users.

Contact

Data requests can be raised through your organization's support channel.