Legal

Privacy

This summary describes how Noodle Seed handles data during the public beta, including the no-card Free start and self-service paid plans. It will be expanded into a full policy before general availability.

What we collect

On this public website, Statsig collects page views, clicks, device and browser context, performance data, a pseudonymous per-device identifier, and session replay data so we can understand and improve the experience. Form inputs are masked and lead forms are blocked from session replay; named analytics events do not contain submitted contact details or assistant prompt text. If you choose a Console signup link, the browser uses the per-device identifier transiently to create a separate pseudonymous acquisition identifier and sends a short-lived signed handoff directly to the Console. The raw website identifier is not placed in the URL or persisted in our CRM notes. The public site assistant processes your messages and keeps the recent conversation context needed to answer. If you choose its workflow-consultation form, we collect the contact details, company information, workflow brief, and contact consent you review before submission. When you sign in with Google to the separate console, we receive your account identity (your email and a stable subject identifier) to create your workspace. We also store the deployment metadata and operational records needed to run and secure the service and administer subscriptions, such as which apps you deployed and safety-control counters.

Secrets and tokens are protected by design

Service credentials and secrets are stored through the credential broker, never in manifests, widget payloads, or logs. Our logging is structurally redacted: no code path logs a request header, request body, bearer token, secret value, or continuation token. Tool-call payloads and the contents your server processes are not retained as logs.

How we use data

We use the data above to operate, secure, debug, and improve the hosted service; administer subscriptions, pooled usage limits, and safety controls; and respond when you explicitly submit a contact or workflow-consultation form. Contact fields entered in the assistant’s private form go through a confirmation-gated app action to our CRM and are not added to the ordinary model conversation. We do not sell personal data.

Subprocessors

The hosted service runs on Google Cloud, which processes data on our behalf to provide compute, storage, and key management. Statsig processes website analytics, session replay data, pseudonymous Console interactions, and pseudonymous service-verified product-usage facts. Those product facts exclude prompts, responses, tool arguments and results, URLs, tokens, configuration values, logs, errors, and raw account or deployment identifiers. The configured model provider processes site-assistant messages so it can answer, and our Twenty CRM service processes contact-form and confirmed workflow-consultation submissions. We will publish a full subprocessor list as the service matures.

Your choices

You can delete the apps you deploy at any time. To request access to or deletion of your account data, contact us and we will help.

Contact

Privacy questions? Email hello@noodleseed.com.