Privacy Policy
Last updated 19 August 2026
This policy explains what Webority Technologies Private Limited collects when you use Ensemble, why, and what we do not do. It is written to be read, not to be survived.
The short version
- Your AI vendor credentials never reach us. They stay on your machine, held by the runner. That is architectural, not a policy promise.
- We do not sell your data, and we do not use your content to train models.
- We collect what is needed to run the service and to bill you, and not much else.
What we collect
- Account data - your email address, display name, account name and role. Sign-in is passwordless, so we never hold a password.
- Service data - the agents, runners, machines, rooms and sessions you create, and the transcripts of agent runs you route through the Console.
- Billing data - subscription state, invoices and payment records. Card details are handled by our payment gateway and are never stored by us; we keep the gateway's identifiers and, where it provides them, the card brand and last four digits.
- Operational telemetry - error reports, request logs and usage metrics used to keep the service working. Product-usage metrics are counts and outcomes; they deliberately carry no message bodies, prompts or labels.
What we do not collect
- Your Claude, ChatGPT, Grok or other AI vendor credentials. The runner holds them locally and the Console has no mechanism to receive them.
- Your source code, except where it appears inside a transcript you route through the Console.
- Card numbers.
Why we process it
- To provide the service - the contract between us.
- To take payment - a legal and contractual necessity.
- To keep it running and secure - our legitimate interest in a working, non-abused service.
- To email you about your account, sign-in codes and material changes. We do not send marketing email without asking first.
Who else sees it
We use a small number of processors, each for one job:
- Microsoft Azure - hosting and database, in the Central India region.
- Razorpay - payment processing.
- SendGrid - transactional email, including sign-in codes.
- Azure Notification Hubs, APNs and FCM - mobile push notifications, where you enable them.
We do not sell or rent personal data to anyone, for any purpose.
Where it lives
Data is stored in Microsoft Azure's Central India region. Some processors above may handle data outside India in the course of delivering their service.
How long we keep it
- Account and service data: while your account exists, and for a short period after deletion so a mistake can be undone.
- Invoices and payment records: as long as tax and accounting law requires, which is longer than the account itself.
- Logs and telemetry: a rolling window, typically 90 days.
A lapsed subscription deletes nothing. Non-payment makes an account read-only, not erased.
Your rights
You can ask us to access, correct, export or delete your personal data, and to stop processing it. Write to us and we will respond within 30 days. Deleting your account removes your service data; invoices are retained where the law requires.
Security
Traffic is encrypted in transit. Sign-in is passwordless with short-lived tokens and rotating refresh tokens. Every account's data is isolated at the database query layer, not merely in application code. No system is perfectly secure, and we will tell affected users promptly if a breach puts their data at risk.
Children
Ensemble is not intended for anyone under 18, and we do not knowingly collect their data.
Changes
We will notify you by email or in the Console before a material change takes effect.
Contact
Privacy questions or a rights request: contact us.