Privacy
If you self-host Dexby, we never receive your data. If you use Dexby Cloud, we hold encrypted credentials and execution metadata on your behalf and nothing else. This page explains both cases.
Who we are
Dexby Inc. provides the Dexby runtime, the connector catalog, and Dexby Cloud. Questions about this policy go to privacy@dexby.ai. Security reports go to security@dexby.ai.
Self-hosted deployments
When you run Dexby on your own infrastructure, you are the controller of every credential, log, and end-user record stored in your PostgreSQL or DynamoDB deployment. That data stays inside your network. Dexby Inc. does not receive it, and the self-hosted runtime sends no telemetry to us.
Your own obligations to your users, including erasure and disclosure requests, remain yours. The runtime supports them: credentials, connection bindings, and execution traces can be purged for a single subject.
Dexby Cloud
Where we operate the runtime for you, we process:
- Account data for the people who administer your workspace: email address, name, and authentication records.
- Third-party credentials your users connect, held under envelope encryption and never in plaintext at rest.
- Execution metadata: which tool ran, for which user identifier, when, how long it took, and whether it succeeded.
Tool payloads carrying a PII or PHI classification are redacted, masked, or hashed before any log, trace, or metric is written. We do not use your data, your prompts, or your tool results to train models.
This website
When you submit the access request form we store the email address you provide, along with the optional name, company, role, deployment preference, and connector requests you choose to share. We use it to contact you about access and to decide which connectors to build next.
We do not sell it, we do not enrich it through third-party data brokers, and we do not add you to a newsletter. Ask us to delete it at any time by writing to privacy@dexby.ai.
Retention and deletion
Access request records are kept until you ask us to remove them or until the beta programme closes. Cloud account data is kept for the life of the account. Encrypted credentials are destroyed when a connection is revoked, using cryptographic erasure of the key material rather than a row delete alone.
Your rights
Depending on where you live, you may have the right to access, correct, export, or delete the personal data we hold about you, and to object to certain processing. Write to privacy@dexby.ai and we will respond. If you are an end user of a product built on self-hosted Dexby, direct your request to that operator instead, because we hold nothing about you.
Changes
Dexby Cloud is in private beta and this policy will change as the service reaches general availability. Material changes will be sent to account administrators by email before they take effect. See Governance for the current state of our compliance programmes.
Last updated 19 September 2026