Constal — Privacy Policy

This Privacy Policy explains how Constal, Inc. ("Constal," "we," "us," or "our") collects, uses, discloses, and retains personal information in connection with Constal and related websites, software, APIs, SDKs, cloud services, agents, support, billing, and communications.

Constal provides a managed runtime for production AI agents. It may process agent code and definitions, prompts, messages, durable state, Resource invocations, logs, traces, outputs, artifacts, sandbox data, and related operational information to provide the Service.


1. Scope

This Policy applies to personal information we collect or process in connection with account management, billing, support, security, analytics, communications, service administration, agent execution, and product improvement.

Unless Constal agrees in a separate signed writing, Constal does not undertake special regulated-data, industry-specific compliance, or customer-specific data-handling obligations beyond this Policy and the Terms. You are responsible for having all rights, permissions, notices, consents, and authority needed to submit personal information or Customer Content.

2. Geographic Availability and EU/EEA Restrictions

Constal is not currently offered for use in the European Union or European Economic Area. Constal does not currently provide EU AI Act compliance, EU/EEA data-protection compliance, EU representative services, EU-specific transfer mechanisms, or EU-specific compliance terms.

You may not access or use Constal if you are located in, ordinarily resident in, or organized under the laws of the EU or EEA. You may not submit personal information of individuals located there, or use Constal in a way requiring EU or EEA compliance, unless Constal expressly agrees in writing.

3. Personal Information We Collect

We may collect the following categories:

Account and Profile Information. Name, email, display name, organization, role, settings, authentication method, OAuth identity, SSO issuer or domain, organization membership, invitations, and profile details.

Authentication and Security Information. API-key metadata, key prefixes or hints, session identifiers, cookies, bearer-token metadata, tenant and organization IDs, login events, IP addresses, device information, security logs, and access records. We do not intentionally retain full plaintext API keys after issuance unless needed for a specific feature.

Agent and Deployment Information. Agent code, definitions, bundle and artifact references, manifests, versions, deployment revisions, Resource bindings, Policy configuration, Channel configuration, Driver metadata, build output, runtime logs, and related operational context.

Run and Session Information. Inputs, prompts, messages, planning notes, user instructions, durable state, checkpoints, journal and ledger events, approvals, steering events, control operations, outputs, status transitions, and outcomes.

AI and Tool Interaction Data. Model messages, tool and Resource calls, shell output, file operations, assistant responses, subtask results, summaries, traces, model identifiers, token usage, costs, and related metadata.

Cloud Execution Information. Sandbox and worker identifiers, session and run IDs, heartbeat data, errors, artifacts, execution time, queues, streams, callbacks, completion data, and cleanup information.

Billing and Commercial Information. Purchases, balances, subscriptions, usage, invoices, billing contacts, payment status, payment-provider identifiers, token and Resource consumption, execution records, and cost estimates. Payment-card details are processed by our payment provider and are not stored directly by Constal except for limited metadata.

Communications and Support Information. Messages, support requests, bug reports, Feedback, survey responses, sales communications, and administrative communications.

External Tool Information. If enabled or requested, web queries, fetched URLs, API responses, package information, code-hosting metadata, MCP messages, identity-provider data, and other information needed for connected Resources.

Sensitive Information. Sensitive information may appear in Customer Content, logs, prompts, tool output, or configuration, including secrets, Credentials, private keys, environment variables, certificates, regulated personal information, vulnerabilities, and confidential business information. Avoid providing it unless necessary and authorized.

4. Sources of Personal Information

We collect information from:

5. How We Use Personal Information

We use personal information to:

6. AI Processing, Model Training, and Aggregated De-Identified Data

Constal sends Customer Content, including prompts, code, messages, logs, tool outputs, traces, and agent outputs, to AI inference and infrastructure providers as needed to provide the Service.

Customer Content and foundation model training. Constal will not use raw Customer Content to train Constal or third-party foundation models except with explicit opt-in or separate written agreement. Providers may retain limited content or metadata for abuse monitoring, security, debugging, application state, or legal compliance under their commercial terms and configurations. Constal does not authorize raw Customer Content for foundation-model training except as enabled by you or agreed in writing.

Aggregated De-Identified Data. This means data submitted to, collected by, or generated by the Service only in aggregate, de-identified form that cannot reasonably be linked to you or your organization. Constal may use, retain, and make it available to improve, test, operate, secure, promote, and market the Service and other products. Constal will maintain it in aggregate or de-identified form and require recipients not to attempt reidentification.

Limited human review. Constal may review limited Customer Content for support, debugging, abuse prevention, security investigation, legal compliance, or with your authorization.

Feature-specific terms. Different terms will be disclosed in an applicable agreement, notice, or configuration where a provider or feature handles data differently.

7. How We Disclose Personal Information

Vendors and Infrastructure Providers. We may disclose information to contractors and providers supporting hosting, storage, compute, databases, queues, payment processing, AI inference, analytics, logging, observability, security, support, email, identity, and operations. These may include payment processors, Google or other identity providers, cloud platforms, AI providers, and web-search providers.

Your Organization and Authorized Users. Administrators and authorized users may access organization-associated users, agents, sessions, runs, Resources, logs, traces, usage, billing, and security settings.

Integrations You Authorize. We may disclose information to systems, APIs, tools, code hosts, package registries, databases, models, MCP servers, and other Resources you connect, configure, or instruct Constal to use.

Aggregated De-Identified Data. We may use, retain, and make it available as described above.

Legal, Safety, and Compliance Recipients. We may disclose information where reasonably necessary to comply with law, process, sanctions, export rules, tax or security requirements; protect rights, safety, or property; or enforce agreements.

Business Transactions. We may disclose information in a merger, acquisition, financing, reorganization, bankruptcy, asset sale, or similar transaction, subject to appropriate confidentiality protections.

8. Cookies and Similar Technologies

We may use cookies, local storage, session tokens, and similar technologies to operate the Service, authenticate users, remember settings, secure accounts, measure usage, and improve performance. Where required, we obtain consent for non-essential cookies. Browser controls may disable cookies, but parts of the Service may stop functioning.

9. Retention

We retain personal information as reasonably necessary to provide the Service, comply with law, resolve disputes, enforce agreements, maintain security, and support legitimate business purposes. Criteria include the information's type and sensitivity, feature and account context, relationship duration, operational needs for runs and support, security needs, legal and accounting requirements, backup cycles, and protection of rights and safety.

We may retain billing, tax, accounting, security, incident, and abuse-prevention records as required or appropriate. Aggregated De-Identified Data may be retained indefinitely.

10. Deletion and Account Controls

The Constal UI or API may provide controls to delete agents, sessions, runs, artifacts, or other records. For account-level deletion or formal privacy requests, email legal@constal.ai. We respond within legally required timeframes.

Deletion may not be immediate in all systems. We may retain information to provide the Service, complete transactions, comply with law, maintain security, prevent abuse, resolve disputes, enforce agreements, complete backup cycles, retain billing or legal records, and retain Aggregated De-Identified Data. Organization users may need to direct requests to their administrator.

11. Security

We use reasonable technical and organizational safeguards designed to protect personal information. Safeguards vary based on the information, feature, environment, and operational need. No security measure is perfect. You are responsible for least privilege, code and dependency hygiene, Credential management, account security, and review of agent permissions and Policies.

12. International Processing

We may process and transfer personal information in the United States and other countries where we or our vendors operate. Their laws may differ from yours. Constal is not currently offered in the EU or EEA and does not provide EU/EEA-specific transfer mechanisms unless expressly agreed in writing.

13. Your Privacy Rights

Depending on your location and law, you may have rights to access, correct, delete, or receive a copy of personal information; opt out of certain sale, sharing, targeted advertising, or profiling; limit uses of sensitive information; or appeal a denied request.

Contact legal@constal.ai to exercise a right. We may verify your identity and authority before responding.

14. California Privacy Notice

This section applies to California residents where the California Consumer Privacy Act, as amended, applies.

Categories Collected. In the preceding 12 months, we may have collected identifiers; commercial information; internet or network activity; professional or employment information; inferences and usage analytics; and sensitive personal information if included in Customer Content, configuration, logs, or instructions.

Purposes. We use these categories to provide and secure the Service, process agent workloads, bill customers, provide support, meet compliance obligations, improve products, and generate Aggregated De-Identified Data.

Disclosure. We may disclose them to vendors and infrastructure providers, your organization, integrations you authorize, legal recipients, and business-transaction recipients as described above.

Sale or Sharing. Constal does not sell personal information or share it for cross-context behavioral advertising unless we provide specific notice and an opt-out. Aggregated De-Identified Data is maintained in de-identified or aggregate form, and recipients are required not to reidentify it.

Sensitive Personal Information. We do not use sensitive personal information to infer characteristics about you. It may be processed where you or your organization includes it in Customer Content or uses a feature requiring it.

California Rights. California residents may have rights to know, access, correct, delete, receive disclosure information, limit certain sensitive-data uses, opt out of applicable sale or sharing, and avoid discrimination for exercising rights. Submit requests to legal@constal.ai. Authorized agents may submit requests subject to verification.

15. Children

Constal is not directed to children or minors under eighteen (18), and users must be at least eighteen or the age of majority. We do not knowingly collect personal information from children under 13. If you believe a child or minor provided information, contact legal@constal.ai.

16. Separate Written Agreements

A separate signed agreement may include additional or different confidentiality, retention, security, support, data-handling, billing, or deletion terms. If it conflicts with this Policy, the signed agreement controls to the extent of conflict.

17. Changes to this Privacy Policy

We may update this Policy. If changes are material, we will provide notice as required by law or the applicable agreement. The updated Policy is effective as of the date stated above.

18. Contact

Constal, Inc.
2261 Market Street STE 68771
San Francisco, CA 94114
Email: legal@constal.ai