← Back

Privacy Policy

Last updated: August 20, 2026

Sigil ("we", "our") provides a semantic context layer for AI agents. This policy explains what data we collect, why, and how we protect it.

1. Data We Collect

Data typePurposeStorage
Email addressAccount login, billingStored in database
Context definitionsCore service functionalityStored in database
Embedding vectorsSemantic searchStored in database (pgvector)
Organization nameMulti-tenant isolationStored in database

2. How We Use Your Data

We use your data solely to provide the context layer service:

  • Store and retrieve your business context definitions
  • Provide semantic search over your context records
  • Send transactional emails (login links)

We do not sell, share, or use your data for advertising or any purpose other than providing the Service.

3. No CRM Data Access

Sigil does not connect to your CRM (HubSpot, Salesforce, etc.) and never accesses your CRM data. Your AI agent uses its own CRM connector separately. We only store the business definitions you create.

4. Subprocessors

ServicePurposeLocation
RailwayApplication hostingUS/EU
NeonDatabase (PostgreSQL)US
OpenAIText embeddingsUS
PaddlePayment processingUK
ResendTransactional emailUS
CloudflareDNS, CDNGlobal

5. Data Retention

  • Active accounts: Data retained while your subscription is active
  • Cancelled accounts: Data retained for 30 days, then permanently deleted

6. Data Security

  • All connections over HTTPS/TLS
  • Signed session cookies with expiry
  • Row-level tenant isolation in database
  • Structured logging with correlation IDs for audit

7. Your Rights (GDPR)

If you are in the EU/EEA, you have the right to access, rectify, delete, export, and object to processing of your personal data. Email lucas.fatas@gmail.com to exercise these rights.

8. Cookies

We use a single signed session cookie for authentication. No tracking or third-party cookies.

9. Contact

Privacy questions: lucas.fatas@gmail.com