Legal

Privacy Policy

Last updated: July 16, 2026

01Overview

Armature, Inc. ("Armature", "we", "us") provides product analytics for AI agent sessions. This policy explains what information we collect on armature.tech and in the Armature product, how we use it and the choices you have.

When our customers send us session data from their own products, we process that data on their behalf as a processor. If you are an end user of a customer's product, that customer's privacy policy applies to you and you should contact them first.

02What we collect

Account data. Name, email address and workspace details when you create an account.

Billing data. Payments are processed by Stripe. We receive billing status and invoices, and we never store card numbers.

Session data. Customers instrument their MCP servers, Claude Connectors or ChatGPT Apps with our SDK, which sends us agent session data such as tool calls, user intents and agent output. Detection models scan this data and redact personal information and secrets by default, before anything reaches storage.

Usage data. How you use the Armature dashboard, collected with privacy-preserving product analytics.

Communications. Emails and support messages you send us.

03How we use it

  • To provide and operate the service, including running AI models that rebuild, classify and score sessions.
  • To bill customers and manage accounts.
  • To answer support requests.
  • To secure the service and prevent abuse.
  • To improve the product.

We do not sell personal data and we do not run advertising.

05Subprocessors

We share data only with providers we need to run the service:

Amazon Web Services
Cloud infrastructure and storage, EU and US regions.
Supabase
Databases and authentication, EU and US regions.
Vercel
Hosts the site and dashboard front end.
Anthropic, OpenAI, Google
AI models used to classify and score sessions.
Stripe
Payment processing.
PostHog
Product analytics for the dashboard.
Slack
Delivers alerts to customer workspaces when configured.

We may also disclose information when the law requires it.

06Hosting and transfers

Armature runs in two regions: an EU-based hosting region and a US-based hosting region. Customers choose where their workspace lives when they sign up. Data in an EU workspace is stored and processed in the EU.

Where personal data is transferred outside the EEA or UK, we rely on Standard Contractual Clauses or equivalent safeguards.

07Retention

Account data is kept while your account is active. Session data is kept for the retention period of your plan, 7 days on the free plan and a custom period on custom plans. When you delete your account or ask us to delete data, we remove it from production promptly and from backups within 90 days.

08Security

  • Encryption in transit and at rest.
  • PII and secret redaction on by default, before storage.
  • Access controls with multi-factor authentication and audit logging.
  • Secrets kept in a managed secret store.
  • Separate environments for development and production.

No system is perfectly secure. If you find a vulnerability, report it to [email protected] and we will work with you in good faith.

09Your rights

Depending on where you live, you can ask to access, correct, export or delete your personal data, and object to or restrict some processing. Email [email protected] and we will respond within 30 days. You can also complain to your local supervisory authority.

If you are an end user of a customer's product, contact that customer first and we will support their response.

10Cookies

The marketing site uses no tracking cookies, and visits are anonymous. The Armature dashboard uses essential cookies for authentication only.

11Children

Armature is a business tool and is not directed at children under 16. We do not knowingly collect their data.

12Changes and contact

We will update this policy when our practices change and revise the date at the top. For material changes we will notify customers by email or in the product.

Entity
Armature, Inc.