Table of Contents
Data We Collect
How We Use Your Data
Data Sharing & Disclosure
Data Retention
Your Rights
Security
Cookies & Tracking
Children's Privacy
International Transfers
Changes to This Policy
Contact Us
1. Data We Collect
1.1 Account & Profile Data
When you create an account, we collect:
Email address (verified)
Name (optional, for display)
Password hash (bcrypt, never stored in plaintext)
Organization/team name (optional)
1.2 License & Usage Data
To provide the CWAI service, we collect:
License keys (hashed for authentication)
Token usage counts (input/output tokens per request)
Model used, latency, success/failure status
Timestamp and tenant ID for each request
Daily aggregated usage summaries
Important: We never store your prompts, completions, or code. CWAI acts as a proxy — data flows from your editor → CWAI gateway → model provider → back to you. We only log metadata: token counts, latency, model used, and success/failure status for your analytics dashboard.
1.3 Billing Data
Processed by Stripe (our payment processor):
Payment method details (card, bank account) — handled entirely by Stripe
Billing address
Invoice history
Subscription status
We never see full card numbers. See Stripe's Privacy Policy .
1.4 Analytics & Telemetry
Page views, referrers, time on page (via privacy-friendly analytics)
Feature usage in dashboard (opt-in)
VS Code extension telemetry (opt-in, anonymous)
2. How We Use Your Data
Purpose Legal Basis Data Categories
Provide CWAI service (auth, routing, budgets) Contract performance Account, license, usage
Billing & subscription management Contract performance Account, billing
Analytics dashboard for you Legitimate interest Usage metadata
Security & abuse detection Legitimate interest Usage, license
Product improvement Legitimate interest / Consent Analytics, telemetry
Communications (updates, security) Legitimate interest / Consent Account
Legal compliance Legal obligation All categories
3. Data Sharing & Disclosure
3.1 Model Providers
When you make a request, we forward it to the selected model provider (OpenAI, Anthropic, Google, etc.). We send:
Your prompt/completion content (required for the model to respond)
Model parameters (temperature, max tokens, etc.)
Each provider's privacy policy applies to data they receive. We have DPAs with major providers.
3.2 Subprocessors
Subprocessor Purpose Location
Stripe Payment processing USA (EU SCCs)
AWS / GCP Cloud hosting USA, EU
Postmark / SendGrid Transactional email USA
Sentry Error tracking USA
3.3 We Do Not
Sell your data
Share with advertisers
Use data for training models
Disclose to governments without valid legal process
4. Data Retention
Data Category Retention Period Deletion Trigger
Account & profile Active + 2 years Account deletion request
License keys (hashed) Active + 2 years Key revocation + 2 years
Usage metadata 13 months Rolling window
Daily usage summaries 3 years Rolling window
Billing records 7 years Legal requirement
Audit logs 2 years Rolling window
Analytics (opt-in) 13 months Consent withdrawal
5. Your Rights
Depending on your jurisdiction (GDPR, CCPA, etc.), you may have:
Access: Request a copy of your data
Rectification: Correct inaccurate data
Erasure: Delete your data ("right to be forgotten")
Portability: Export your data in machine-readable format
Restriction: Limit processing
Objection: Object to legitimate-interest processing
Withdraw consent: For consent-based processing
To exercise rights: email privacy@cwai.dev or use the dashboard's "Export Data" / "Delete Account" features.
6. Security
Encryption: TLS 1.3 in transit; AES-256 at rest
Authentication: License-key auth (Ed25519), optional SSO
Access control: Least-privilege, MFA for staff, regular access reviews
Monitoring: 24/7 SIEM, intrusion detection, vulnerability scanning
7. Cookies & Tracking
Category Purpose Duration
Essential Session, auth, CSRF protection Session / 1 year
Preferences Theme, language, dashboard config 1 year
Analytics (opt-in) Usage stats, feature adoption 13 months
Marketing None — we don't use marketing cookies N/A
Manage preferences in dashboard settings or browser. Essential cookies cannot be disabled.
8. Children's Privacy
CWAI is not directed at children under 16. We don't knowingly collect data from children. If you believe we have, contact privacy@cwai.dev .
9. International Transfers
CWAI is hosted in the US. If you're in the EU/UK, your data transfers rely on:
Standard Contractual Clauses (SCCs) with subprocessors
Adequacy decisions where applicable
Supplementary measures (encryption, access controls)
10. Changes to This Policy
We may modify this policy. Material changes: 30 days' notice via email and dashboard banner. Continued use after effective date = acceptance. Version history on GitHub .
Questions about this policy?
Email: privacy@cwai.dev
Postal: CWAI Inc., 123 Mission St, San Francisco, CA 94105