法務
取得する情報、その取得目的、および保管期間について。
This document describes how we operate and is published so you can review it early. It has not yet completed external legal review and is not a binding agreement in this form. If you need executed terms before that review completes, contact us and we will handle it directly.
Translations of this page may be provided for convenience. Where a translation conflicts with the English text, the English text controls.
This policy covers personal information we handle as a controller — account data, billing data, and product analytics. Content you upload into your workspace is handled as a processor on your instructions and is governed by our Data Processing Addendum instead.
| Category | What it includes | Where it comes from |
|---|---|---|
| Identity | Name, email address, profile picture, identity provider subject identifier | Your identity provider at sign-in |
| Organization | Workspace name, verified domains, role assignments, invitation records | You and your administrators |
| Billing | Plan, seat counts, invoices, billing contact | You. Card details go directly to our payment processor — we never receive them |
| Usage | Feature usage, credit consumption, error reports, approximate location from IP | Automatically, as you use the product |
| Audit | Who did what and when, including IP address and user agent | Automatically. Retained per your plan |
We do not store passwords. Authentication happens at your identity provider, so there is no credential database here.
We do not use your data to train machine learning models, and we do not sell personal information or share it for cross-context behavioral advertising.
Where GDPR or similar law applies, we rely on:
We share personal information with the subprocessors listed in our subprocessor list, each bound by contract to process it only on our instructions.
Data you bring in from a connected tool (GitHub, Google, Microsoft 365, Slack, Notion, Atlassian, Linear, Figma) is covered by section 13, which sets out what we access, what we store, and how Google user data is handled.
We may also disclose information when required by law, to protect our rights or someone's safety, or as part of a merger or acquisition — in which case we will give notice before your information becomes subject to a different policy.
| Data | Retention |
|---|---|
| Account and profile | While your account is active, then deleted within 30 days |
| Workspace content | Until you delete it, or 30 days after account closure |
| Audit logs | Per your plan — 90 days, 1 year, or 3 years |
| Billing records | Seven years, as required for tax and accounting |
| Support correspondence | Three years |
Depending on where you live, you may have the right to access, correct, delete, or port your personal information, to object to or restrict processing, and to complain to a supervisory authority.
Most of this is available directly in the product: you can export your data at any time and delete your account from workspace settings. For anything else, write to [email protected] and we will respond within 30 days. We do not charge for these requests and we will not treat you differently for making one.
If you are a member of a workspace your employer administers, direct requests about workspace content to them — they control that data, and we act on their instructions.
We operate from the United States and our infrastructure providers operate globally. Where we transfer personal information out of the European Economic Area, the United Kingdom, or Switzerland, we rely on the European Commission's Standard Contractual Clauses together with additional technical measures including encryption in transit and at rest.
Enterprise customers can request regional data residency.
We use the minimum set of cookies needed to run the product:
| Cookie | Purpose | Duration |
|---|---|---|
| Session | Keeps you signed in | Session or up to 30 days |
| CSRF token | Prevents cross-site request forgery | Session |
| Preferences | Language and interface settings | 1 year |
We do not use advertising or cross-site tracking cookies.
The service is for organizations and is not directed to anyone under 16. We do not knowingly collect information from children. If you believe we have, write to [email protected] and we will delete it.
We will post changes here and update the date at the top. For material changes we will notify account administrators by email at least 30 days before they take effect.
Privacy questions or requests:
[email protected]
Security matters:
[email protected]
A registered business address and, where required, an EU/UK representative will be published here before general availability.
untactit connects to the tools you already use — GitHub, Google, Microsoft 365, Slack, Notion, Atlassian (Jira and Confluence), Linear, and Figma — so the agent assets living in those tools can be inventoried, reviewed, and deployed from one place. You start every connection yourself by signing in to that vendor. We never ask for, receive, or store your password for a connected service.
What we access. Only what the connection needs: the files, pages, issues, and documents your own account can already see in the workspace you connect, plus the account or workspace identifier that tells us which connection a token belongs to. We request read-only scopes wherever the vendor offers them, and we ask for write access only where you have asked us to publish assets back.
What we store. Access and refresh tokens, encrypted at rest and scoped to your organization; the content you choose to import as an asset; and a synchronization log recording what moved and when. Tokens are never shared with other customers, and we do not sell data obtained from connected services.
Google user data — Limited Use. untactit's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. We use Google user data only to provide and improve the features you connected it for; we do not transfer it except as necessary to provide those features, to comply with applicable law, or as part of a merger with prior notice; we do not use it for advertising; we do not sell it; and we do not use it to develop, improve, or train generalized artificial intelligence or machine learning models. Human access is limited to what you explicitly permit, to what security or law requires, and to aggregated or anonymized data used to operate the service.
Disconnecting. You can disconnect any service at any time from Settings → Connectors, or revoke untactit's access from the vendor's own security settings. Disconnecting deletes the stored tokens for that service immediately. Assets you already imported stay in your workspace until you delete them.