Privacy Policy
This notice explains what Observyze processes, why it is processed, and the controls available to customers.
1. Data Collection & Sovereignty
Account data can include your name, email address, organization membership, authentication records, billing identifiers, support messages, and security events. Telemetry can include prompts, completions, span metadata, model and provider identifiers, token usage, latency, costs, user/session identifiers, and errors, depending on how you configure capture. Observyze does not use customer inference payloads to train its own models.
2. Security Infrastructure
Provider credentials and supported organization secrets are stored in AES-256-GCM envelopes. Network encryption, database and object-storage encryption, backups, logging, and key management depend on the deployed infrastructure and its configuration. Tenant-scoped authorization checks are applied in the application. No SOC 2 report, ISO certification, HIPAA compliance status, or other independent attestation is claimed by this notice.
3. Regional Compliance
Observyze provides technical controls that can support customer privacy programs, including metadata-only SDK capture, deterministic local and server-side redaction, configurable retention, exports, and deletion workflows. These controls do not make every deployment legally compliant; customers remain responsible for lawful use, notices, consent, data minimization, and sector-specific obligations.
4. Purposes and Service Providers
Data is processed to provide and secure the service, authenticate users, route configured model requests, calculate usage and cost estimates, run requested evaluations, deliver alerts, support customers, process billing, and meet legal obligations. Depending on enabled features, data may be sent to hosting, database, object-storage, authentication, payment, email, alert, and model providers. Customers should review and approve the providers enabled in their deployment.
5. Retention and Deletion
Trace retention is configurable by organization and may include S3-compatible cold storage. Account, billing, security, backup, and audit records may follow separate retention schedules. Object-lock or legal-hold configurations can prevent immediate deletion. Contact us to request account access, correction, export, or deletion; applicable law and contractual obligations may limit a request.
6. International Processing
The service and its configured providers may process data outside your country. The customer is responsible for selecting deployment regions and contractual transfer mechanisms appropriate to its users and data.
7. Security and Incident Reporting
No system is completely secure. Use metadata-only capture for sensitive workloads, avoid sending regulated data unless your deployment and contracts permit it, restrict roles and API keys, and rotate secrets. Report suspected security issues through the contact channel below without including live credentials or sensitive customer payloads.
8. Children and Changes
Observyze is a business service and is not directed to children. We may update this notice as the service or legal requirements change; the effective date above identifies the current version.
9. Contact
Privacy questions and data requests can be submitted through the Observyze contact page. Before a request is fulfilled, we may need to verify the requester and their authority over the organization. This notice should be reviewed by qualified counsel before production launch.