⟨ LEGAL ⟩

Privacy policy

Effective 6 August 2026


AstroFabric ("AstroFabric", "we", "us") provides agentic marketing infrastructure: an API, MCP server and console at www.astrofabric.ai through which autonomous agents run marketing missions on behalf of customer workspaces. This policy explains what data we collect, why, who processes it, and the choices you have. Questions and requests: hello@astrofabric.ai.

What we collect

  • Account data. Your email address and optional name, collected when you sign in with a magic link. We use passwordless authentication, so we never hold a password for you.
  • Workspace data. Workspace names, member roles, the brands, domains and competitors you configure, and the standing workspace memory you or the agent save (for example your ICP, sender identity or value proposition).
  • Mission and usage data. The objectives you give the agent, conversation threads and their tool-call traces, agent run records, generated deliverables (including downloadable files, which expire automatically after 30 days), API request metadata, and usage meters.
  • Connected-account data. When you connect an integration (for example Google Search Console, a CRM, Slack or an ad account), we access that service on your instruction, under the scopes you granted. OAuth tokens are held by our integration brokers rather than stored in our own database; our database keeps a mirror of connection status and account labels.
  • Billing data. Subscription and invoice records. Card details go directly to our payment processor and never touch our servers.
  • Technical data. Server logs, IP addresses and authentication cookies needed to run the service securely. The marketing site sets no advertising or cross-site tracking cookies.

How we use it

  • To run the service: executing missions, tools and autopilots you invoke.
  • To operate AI features: mission content is processed by our AI model provider to plan and execute the work you requested. Our provider does not use this content to train its models.
  • To meter usage, enforce plan budgets, and bill accurately.
  • To secure the platform: rate limiting, abuse prevention, audit trails.
  • To communicate service matters: sign-in links, invites, delivery failures.

We do not sell personal information, and we do not use your workspace data to build cross-customer profiles. Data fetched from your connected accounts is used inside your workspace, for your missions.

Who processes it

We build on a small set of infrastructure processors, each bound by its own data processing terms: Vercel (hosting), Supabase (database and authentication), Stripe (payments), Anthropic (AI model inference), Composio (integration broker holding OAuth credentials for connected apps), Inngest (background job execution) and Resend (transactional email). Marketing intelligence (search results, keyword data, advertising libraries, buyer signals, technographics, email verification) comes from licensed data providers who receive the specific query needed to serve your request, never your account identity.

Tenant isolation and security

Every read and write in the platform is bound to a single workspace at the database layer, with row-level security as a second line of defence. API keys are stored as hashes and shown once; webhook deliveries are signed; connections to third parties are pinned to the workspace that created them. Data moves over TLS everywhere.

Retention and deletion

  • Generated download files expire and become inaccessible after 30 days.
  • Mission threads keep a bounded transcript; the oldest turns roll off as a thread grows.
  • Revoking an integration removes our access and deactivates its mirror row.
  • Deleting a workspace removes its data from the live database; residual copies in encrypted backups age out on the backup cycle.
  • Billing records are retained as long as tax and accounting law requires.

Your rights

Depending on where you live (including under GDPR and CCPA), you may have the right to access, correct, export or delete your personal information, to object to or restrict certain processing, and to complain to a supervisory authority. Write to hello@astrofabric.ai and we will act on verified requests within the statutory window. We respond the same way regardless of which privacy law applies to you.

International transfers

Our infrastructure runs primarily in the United States. Where data of EU or UK residents is transferred, we rely on our processors' standard contractual clauses and equivalent safeguards.

Children

The service is for businesses and is not directed at children under 16; we do not knowingly collect their data.

Changes

When this policy changes in substance we will update the effective date above and note the change on this page. Continued use after a change means the updated policy applies.