Privacy policy
Effective 4 September 2026
AstroFabric ("AstroFabric", "we", "us") provides Agentic AI for Business Intelligence: an API, MCP server and console at www.astrofabric.ai through which autonomous agents build lists, enrich and verify company and person data, monitor business signals and stage audiences on behalf of customer workspaces. This policy explains what data we collect, why, who processes it, and the choices you have. Questions and requests: hello@astrofabric.ai.
What we collect
- Account data. Your email address and optional name. You can sign in with a password, Google, or an emailed link. Supabase handles authentication, including password hashing; our application does not store plaintext passwords.
- Workspace data. Workspace names, member roles, the ICP, brands and domains you configure, your suppression lists, and the standing workspace memory you or the agent save (for example your sender identity or value proposition).
- Mission and usage data. The objectives you give the agent, conversation threads and their tool-call traces, agent run records, the lists, audiences and signals produced for your workspace, generated deliverables (including downloadable files, which expire automatically after 30 days), API request metadata, and usage meters.
- Connected-account data. When you connect an integration (for example a CRM, an outreach tool, Slack, a sheet or an ad account), we access that service on your instruction, under the scopes you granted. OAuth tokens are held by our integration brokers rather than stored in our own database; our database keeps a mirror of connection status and account labels.
- Billing data. Subscription and invoice records. Card details go directly to our payment processor and never touch our servers.
- Technical data. Server logs, IP addresses and authentication cookies needed to run the service securely. The marketing site sets no advertising or cross-site tracking cookies.
How we use it
- To run the service: executing the missions, tools, agents, list builds, signal watches and audience pushes you invoke.
- To operate AI features: mission content is processed by our AI model provider to plan and execute the work you requested. Our provider does not use this content to train its models.
- To meter usage, enforce credit ceilings, and bill accurately.
- To secure the platform: rate limiting, abuse prevention, audit trails.
- To communicate service matters: sign-in links, invites, delivery failures.
We do not sell personal information, and we do not use your workspace data to build cross-customer profiles. Data fetched from your connected accounts is used inside your workspace, for your missions.
Business contact data we process for customers
The lists our customers build contain business contact data: company records and the names, titles, business emails and business phone numbers of people who work there. For that data the customer is the controller (or the business under the CCPA) and AstroFabric acts as their processor (service provider), on their documented instructions.
- Where it comes from. Company and person data is sourced from licensed business-data providers under contract with us, each of which receives the specific query needed to serve the request and never the customer's account identity. We do not scrape member networks or social platforms, we do not log in to any service as the customer, and we do not send messages to anyone on the customer's behalf.
- What it is used for. Building and refreshing lists, enriching and verifying records, scoring fit, monitoring business signals, preparing audiences and personalizing outreach data, each for the customer's own business-to-business go-to-market use. Every field keeps its source and the time it was retrieved.
- How long it is kept. List rows are retained for as long as the list they belong to exists, within the customer's plan limits and the retention period set in the workspace settings; by default a row is removed when its list is deleted, and everything is removed when the workspace is deleted. Customers can delete a row, a list or the workspace from the console or the API at any time.
- Suppression. Each workspace holds a suppression list. A person or company on it is excluded from every future list, audience and export in that workspace, and a request not to be contacted that reaches us is added to the relevant workspace's suppression list.
- Audiences. When a customer pushes an audience to an advertising platform, identifiers are hashed (SHA-256) before they leave the platform. Raw emails and phone numbers are never uploaded to an ad platform, and the customer approves every push before it happens.
- Your rights as a data subject. If you believe your business contact details appear in a customer workspace, write to hello@astrofabric.ai. We will identify the workspaces that hold the record, route your request to the responsible customer, and act on access, correction, deletion, restriction and objection requests within the statutory window under the GDPR, the UK GDPR, the CCPA/CPRA and comparable laws, regardless of which one applies to you.
Who processes it
We build on a small set of infrastructure processors, each bound by its own data processing terms: Vercel (hosting), Supabase (database and authentication), Stripe (payments), Anthropic (AI model inference), Composio (integration broker holding OAuth credentials for connected apps), Inngest (background job execution) and Resend (transactional email). Business data (firmographics, technographics, hiring, funding, news, buying intent, contact discovery and verification) comes from licensed business-data providers who receive the specific query needed to serve your request, never your account identity. Audiences reach the advertising platforms you connect only after hashing and only on your approval.
Tenant isolation and security
Every read and write in the platform is bound to a single workspace at the database layer, with row-level security as a second line of defence. API keys are stored as hashes and shown once; webhook deliveries are signed; connections to third parties are pinned to the workspace that created them. Data moves over TLS everywhere.
Retention and deletion
- Generated download files expire and become inaccessible after 30 days.
- Mission threads keep a bounded transcript; the oldest turns roll off as a thread grows.
- Workspace retention settings cover conversation threads, finished runs and inactive lists. Audience records and signal-watch records remain until removed with the workspace. Detected signal events are purged after 90 days; staged audience member payloads are purged after a successful push. Deleting a list removes its rows, including the signals attached to those rows.
- Revoking an integration removes our access and deactivates its mirror row.
- Deleting a workspace removes its data from the live database; residual copies in encrypted backups age out on the backup cycle.
- Billing records are retained as long as tax and accounting law requires.
Your rights
Depending on where you live (including under GDPR and CCPA), you may have the right to access, correct, export or delete your personal information, to object to or restrict certain processing, and to complain to a supervisory authority. Write to hello@astrofabric.ai and we will act on verified requests within the statutory window. We respond the same way regardless of which privacy law applies to you.
International transfers
Our infrastructure runs primarily in the United States. Where data of EU, EEA, UK or Swiss residents is transferred, we rely on our processors' standard contractual clauses and equivalent safeguards.
Children
The service is for businesses and is not directed at children under 16; we do not knowingly collect their data.
Changes
When this policy changes in substance we will update the effective date above and note the change on this page. Continued use after a change means the updated policy applies.