Caldyr ("we") operates caldyr.ai and the Caldyr control plane. This page explains what we collect, what we don't, and how to ask us to delete it.
What we collect
Account email and company name. Billing details (handled by our payment processor). Anonymous, cookieless usage stats via Plausible. Your personal vault notes are BYOK end-to-end encrypted before they reach our servers, so we cannot read them. Your secrets, team knowledge, saved session transcripts, and session metadata are encrypted at rest under per-team keys held by our custody service so they can be indexed, searched, and streamed — meaning those classes can be decrypted by the service that operates them. Live terminal sessions streamed to the control plane are processed server-side for real-time watching and replay; they are encrypted at rest (storage-level), tenant-isolated, access-controlled, and kept only for your configured retention window.
What we share
Nothing with advertisers. Payment processor (Stripe) receives card details. Cloud provider (Hetzner) hosts encrypted blobs. That's it.
Your rights
GDPR + CCPA both apply. Email privacy@caldyr.ai to delete, export, or correct your data within 30 days.