Legal
Privacy Policy
Scope
This Privacy Policy describes how Candler (“we”) handles information when you use the Service. It should be read with the Terms of Service. It is not a claim of zero collection or zero logging.
Information we handle
We handle the following categories, depending on how you use the Service:
- Account and profile information, such as name, email address, and authentication identifiers.
- Authentication data, including password hashes managed by Supabase Auth, session cookies, MFA factor metadata, and hashed or encrypted recovery-code material as applicable. We do not store your account password in plaintext.
- Billing metadata from Stripe, such as customer and subscription identifiers, plan, status, and period dates. We do not store full payment-card numbers on Candler servers.
- Project and workspace metadata, including names, environments, services, and similar organizational records.
- Encrypted Vault, Authenticator, and Recovery payloads (ciphertext, initialization vectors, authentication tags, and key version). Plaintext secret values are not stored as a Vault column. They may exist briefly in memory on a server during encrypt, decrypt, or authorized reveal.
- Cloud file bytes and Cloud metadata (filename, size, path, checksums, status). Files are stored in private object storage.
- Agent conversation text and tool metadata after secret-pattern sanitization. Agent is designed not to be given raw Vault secret values. Sanitization can miss secrets that do not match known patterns.
- Security and product logs, including audit events such as copies of secrets, authenticator codes, or recovery material, legal acceptance versions, and operational errors. Audit metadata is redacted for obvious secret fields and is not a transcript of secret values.
- Cookies and similar storage for authentication sessions.
- Browser localStorage and cookies for appearance preferences such as workspace mode and shade. Those preferences are not used as a substitute for legal consent.
Purpose of processing
We process information to create and authenticate accounts, provide Vault, Authenticator, Recovery, Cloud, Agent, billing, and workspace features, enforce quotas and access control, secure the Service, debug incidents, comply with law, and communicate with you about the account you asked us to operate.
Service providers
We use processors who handle information on our instructions, including:
- Supabase, for authentication, Postgres, and row-level security.
- Cloudflare R2, for private Cloud object storage and signed access.
- Stripe, for checkout, subscriptions, customer portal, and invoices.
- OpenAI, when Candler Agent is enabled, for model inference on sanitized conversation content.
- Vercel, for application hosting, logs, and related infrastructure where the product is deployed there.
Retention and deletion
We retain account and workspace data while the account is active and for a limited period afterward as needed for backups, billing disputes, security investigations, and legal obligations. You may request deletion via the contact below. Some records, such as billing and security logs, may be retained longer where required.
Legal consent records are kept to show which Terms and Privacy versions you accepted. They are not a marketing profile.
Security practices
Candler uses TLS in transit on supported deployments, AES-256-GCM for Vault/Authenticator/Recovery payloads, tenant isolation via Postgres row-level security, private Cloud storage, server-side quota checks, and step-up authentication for sensitive reveals. These measures reduce risk. They do not make processing risk-free.
International processing
The Service and its processors may process information in the United States and other countries. Those countries may have different data-protection laws than your own. By using the Service you understand that your information may be transferred internationally as needed to operate Candler.
Your rights
Depending on your location, you may have rights to access, correct, delete, or export personal information, or to object to or restrict certain processing. Requests can be sent to the privacy contact below. We may need to verify the account making the request.
You can control appearance preferences in your browser. Clearing site data removes local appearance settings; it does not delete your account or legal consent records.
Children
Candler is not directed to children under 16, or under the higher digital-consent age in your country. We do not knowingly collect personal information from children below that age.
Changes
We may update this Policy. The version and dates on this page will change. We will require a fresh in-product acknowledgement when we decide a change is material to that effect. Not every edit will block the workspace.
Contact
Privacy questions: privacy@candler.dev. General contact: hello@candler.dev.