Privacy Policy

Effective Date: March 29, 2026 | Last Updated: September 10, 2026

1. Information We Collect

Account Data: Email address, display name, hashed password, subscription tier.

Usage Data: Queries submitted, council sessions, agent interactions, API usage metrics.

API Credentials: Third-party API keys you provide (Anthropic, OpenAI, Google, Mistral) — stored encrypted.

Payment Data: Processed by our payment provider (Stripe). We do not store credit card numbers.

Marketplace Data: Agent listings, reviews, purchase history.

Site Analytics Data: Pages you visit — including pages viewed without signing in — the website that referred you, your browser's user-agent string, and a hashed form of your IP address. We use this to see which pages are useful and where visitors arrive from.

Newsletter Data: When you subscribe to the AI Engineering Brief, we keep your email address, the page and campaign that brought you to the form, the consent wording you accepted, and the time you subscribed. The newsletter includes weekly AI engineering material and occasional Meta-Council product updates. Every message includes an unsubscribe link.

Enquiry Data: When you use the contact form or email us, we keep your name, email address, company, message, the page you wrote from, and the time of the enquiry so that we can reply and keep track of the conversation. Emails sent to our sales addresses are handled the same way. We only send you marketing updates if you tick the box on the form and then confirm from the email we send you; every such email carries an unsubscribe link.

2. How We Use Your Data

3. What We Do NOT Do

4. Data Storage and Security

Passwords: bcrypt hashed (never stored in plaintext).

API keys (yours): SHA-256 hashed. The full key is shown once at creation and never again.

Third-party API keys: Stored with encryption at rest.

Session data: Stored in our database. Signed-in runs are private by default and restricted to the owning account and authorized administrators. Guest runs and sessions an owner explicitly publishes are accessible without signing in and may appear in search results, so do not submit confidential or regulated information in guest mode or publish it.

5. Data Retention

Account data: Retained while your account is active. Deleted within 30 days of account deletion.

Query history: Retained for 90 days, then automatically purged.

API logs: Retained for 30 days for debugging and abuse detection.

Site analytics: Individual page-visit records are retained for 24 months, then automatically purged. Aggregate totals derived from them (such as monthly page-view and visitor counts), which contain no IP-derived or account-identifying values, may be retained indefinitely.

Newsletter records: Kept while you are subscribed. If you unsubscribe, we stop newsletter delivery and retain the minimum suppression record needed to honor that choice.

6. Your Rights

You may: access your data, request deletion, export your data, update your information, and withdraw consent for optional processing. Contact [email protected].

7. Third-Party Services

When you use third-party models (Anthropic, OpenAI, etc.), your query content is sent to those providers subject to their privacy policies. The platform default currently routes to Anthropic's Claude, so by default your query content is sent to Anthropic under their privacy policy. When a query is instead served by our self-hosted open-weight models, it is processed on our own infrastructure.

The contact form may use Cloudflare Turnstile to tell people from automated submissions. Turnstile runs in your browser and sends a token and connection metadata to Cloudflare under Cloudflare's privacy policy; it does not receive the contents of your message.

8. Cookies

We use minimal cookies: a JWT authentication token stored in localStorage (not a cookie). No third-party tracking cookies.

9. Contact

Privacy inquiries: [email protected]

Back to Meta Council