Scope of this policy
This policy covers the Fact6 product - the interface where agents are built, tested, and monitored - and the runtime that executes those agents against your connected tools.
It does not cover the data that continues to live in your own tools (your CRM, your mailbox, your billing provider). Those tools remain the source of record and are governed by their own terms.
What we collect
- Account information you provide when signing up - name, work email, company, and role.
- Task descriptions and agent configuration you author inside the product.
- Tool connection metadata - which integrations you enable, scopes granted, connection health.
- Activity logs generated by your agents as they run.
- Product usage data - features used, errors encountered, performance signals.
How we use it
Only for purposes that keep the product running for you:
- Provisioning and operating your account and agents.
- Executing the actions your agents are configured to take, on the tools you connect.
- Producing the activity log and reasoning trace that make each action explainable.
- Product safety - detecting abuse, preventing account compromise, keeping the runtime honest.
- Support you request from us.
We do not sell personal data. We do not use content from your connected tools to train third-party general-purpose models.
Data from your connected tools
When an agent runs, it reads and writes data in the tools you connect. Fact6 only accesses the scopes you explicitly grant, and only when the agent's configured actions require it.
The product stores enough of this data to make each action reviewable - the inputs the agent saw, the decision it made, and the outcome reported by the tool. Sensitive fields can be redacted from the log view without affecting the runtime.
Retention
- Account data is retained while your account is active.
- Activity logs default to 90 days, and are configurable on Growth and Scale plans.
- On account closure, data is deleted from active systems within 30 days and from backups within a further 60 days.
Security measures
- TLS 1.2+ for all in-transit data, HSTS on the product surface.
- Encryption at rest for persistent data, with per-tenant keys.
- Credentials for connected tools stored encrypted, never returned in plaintext through the product.
- Least-privilege access to production systems, with audit trails.
Your rights
- Access - request a copy of the account data we hold about you.
- Correction - update inaccurate account information at any time.
- Deletion - request removal of your account and associated data.
- Portability - request an export of the configuration you authored.
- Objection - object to specific processing where lawful grounds allow.
Changes to this policy
If we change this policy in a way that materially affects how your data is handled, we will let you know inside the product before the change takes effect. Non-material clarifications may be made without notice.