This Privacy Policy explains how Sigil Labs, Inc. ("Sigil", "we", "us") collects, uses and shares personal information when you visit our website, create an account, or use the Sigil platform (the "Service"). If you use Sigil on behalf of an organization, that organization's agreement with us, including our Data Processing Agreement, governs how we process the data you send through the Service.
Information we collect
Information you give us. Your name, work email, company, role and password when you sign up; billing details when you subscribe (card data is handled by our payment processor and never stored by Sigil); and anything you send us through support, sales or careers forms.
Information collected automatically. Log and device data such as IP address, browser type, pages visited and timestamps; product usage such as features used, API request counts and error rates; and cookies or similar technologies described below.
Customer Data. Prompts, completions, tool calls, traces, audit log entries and other content your agents send through the Service. We process Customer Data only on your instructions, as a processor, under our Data Processing Agreement. Customer Data is never used to train models, and it is never sold.
How we use information
To provide, operate, secure and maintain the Service, including routing, fallbacks, budgets and audit logging.
To authenticate users, prevent abuse and investigate security incidents.
To process payments and send transactional messages such as invoices, receipts and service notices.
To understand aggregate usage and improve the product, using de-identified or aggregated data where possible.
To send product updates and marketing emails, which you can unsubscribe from at any time.
To comply with legal obligations and enforce our Terms of Service.
Legal bases (EEA, UK and Switzerland)
We rely on performance of a contract (to provide the Service), legitimate interests (to secure and improve the Service and to market to business contacts), consent (for non-essential cookies and certain marketing), and legal obligation (for tax, accounting and law-enforcement requests).
How we share information
Subprocessors and vendors that host infrastructure, process payments, send email or provide analytics, under contracts that limit their use of the data.
Model providers you choose. When your agents call a third-party model through Sigil, the request is forwarded to that provider on your behalf and is governed by your agreement with them.
Legal and safety when required by law, or to protect the rights, property or safety of Sigil, our customers or others.
Business transfers as part of a merger, acquisition or sale of assets, subject to this Policy.
We do not sell personal information and do not share it for cross-context behavioral advertising.
Cookies
We use strictly necessary cookies to keep you signed in and secure the Service, and, with your consent where required, analytics cookies to understand how the website is used. You can control cookies through your browser settings and our cookie banner.
Retention
Account data is kept for as long as your account is active and for a limited period afterwards to meet legal and accounting obligations. Customer Data is retained according to the retention settings in your workspace and is deleted within 30 days of account termination, unless the law requires otherwise. Self-hosted deployments keep Customer Data in your own infrastructure.
Security
We use encryption in transit (TLS 1.2+) and at rest (AES-256), role-based access controls, single sign-on, audit logging and regular third-party penetration tests. No system is perfectly secure, but we work to protect your information and will notify you of a breach as required by law.
International transfers
Sigil is based in the United States and uses providers in other countries. Where we transfer personal information out of the EEA, UK or Switzerland, we rely on the European Commission's Standard Contractual Clauses and the UK Addendum, or another lawful transfer mechanism.
Your rights
Depending on where you live, you may have the right to access, correct, delete or export your personal information, to object to or restrict certain processing, and to withdraw consent. California residents have the rights described in the CCPA/CPRA, and we will not discriminate against you for exercising them. To make a request, email privacy@sigil.dev. If we process your data on behalf of a customer, we will forward your request to that customer. You may also lodge a complaint with your local data protection authority.
Children
The Service is built for businesses and is not directed to children under 16. We do not knowingly collect their personal information.
Changes to this Policy
We may update this Policy from time to time. We will post the new version here with a new "Last updated" date and, for material changes, notify account owners by email or in the product.
Contact
Sigil Labs, Inc. · privacy@sigil.dev