Caddi
Sign inGet started

Privacy Policy

Last updated July 17, 2026

Caddi is operated by Ethan Rogers (the “Operator”). We take your data seriously. This policy says what we collect, why, and what we will never do with it. It also explains how long we keep it and what you can do about it.

What we collect

When you create an account, we collect:

  • Your email and password hash (or magic-link identifier).
  • Metadata about the services you connect: which provider, when, and what scopes were granted. Your actual keys and tokens are end-to-end encrypted to your account’s vault; our servers only ever store ciphertext, as described in our security model.
  • Records of what your agents do through Caddi: which tool ran, from which project, and on which device, stored in an audit log. We record names, never argument values.

If you join the email list instead of creating an account, we collect:

  • Your email address and where you signed up from. We use it to invite you to Caddi and send you a welcome email, and for nothing else. Ask us to remove it any time.

How we use it

We use this data only to operate Caddi: running the service, sending you transactional emails, and answering support requests. We don’t sell data and we don’t share it with advertisers.

Subprocessors

Caddi runs on Vercel (hosting), Supabase (database, auth, storage), Cloudflare (R2 object storage and DNS), Resend (transactional email), Sentry (error tracking), Axiom (logs), and Better Stack (uptime). Each sees only the data needed to perform its function.

Security

All connections use TLS. Provider tokens and keys you connect (GitHub, Vercel, Cloudflare, Resend) are end-to-end encrypted to your account’s vault, sealed before they reach our servers where possible, and never stored in a form we can read. Row-Level Security is enforced on every table.

Retention

Audit logs are kept for two years. If you cancel your account, we delete your data within 30 days unless you’ve exported it first.

Your rights

Email [email protected] and we’ll send you an export of everything we hold about you. You can request deletion the same way. We honor GDPR access, rectification, and erasure requests.

Cookies

We use first-party cookies for authentication. We use Plausible for marketing-site analytics, which is cookie-free. No third-party tracking cookies on the marketing site or the app.

Changes

We’ll update this page when our practices change and notify you by email for material changes.

Contact

Questions? Email [email protected].