Privacy Policy
Last updated July 17, 2026
Caddi is operated by Ethan Rogers (the “Operator”). We take your data seriously. This policy says what we collect, why, and what we will never do with it. It also explains how long we keep it and what you can do about it.
What we collect
When you create an account, we collect:
- Your email and password hash (or magic-link identifier).
- Metadata about the services you connect: which provider, when, and what scopes were granted. Your actual keys and tokens are end-to-end encrypted to your account’s vault; our servers only ever store ciphertext, as described in our security model.
- Records of what your agents do through Caddi: which tool ran, from which project, and on which device, stored in an audit log. We record names, never argument values.
If you join the email list instead of creating an account, we collect:
- Your email address and where you signed up from. We use it to invite you to Caddi and send you a welcome email, and for nothing else. Ask us to remove it any time.
How we use it
We use this data only to operate Caddi: running the service, sending you transactional emails, and answering support requests. We don’t sell data and we don’t share it with advertisers.
Subprocessors
Caddi runs on Vercel (hosting), Supabase (database, auth, storage), Cloudflare (R2 object storage and DNS), Resend (transactional email), Sentry (error tracking), Axiom (logs), and Better Stack (uptime). Each sees only the data needed to perform its function.
Security
All connections use TLS. Provider tokens and keys you connect (GitHub, Vercel, Cloudflare, Resend) are end-to-end encrypted to your account’s vault, sealed before they reach our servers where possible, and never stored in a form we can read. Row-Level Security is enforced on every table.
Retention
Audit logs are kept for two years. If you cancel your account, we delete your data within 30 days unless you’ve exported it first.
Your rights
Email [email protected] and we’ll send you an export of everything we hold about you. You can request deletion the same way. We honor GDPR access, rectification, and erasure requests.
Cookies
We use first-party cookies for authentication. We use Plausible for marketing-site analytics, which is cookie-free. No third-party tracking cookies on the marketing site or the app.
Changes
We’ll update this page when our practices change and notify you by email for material changes.
Contact
Questions? Email [email protected].