Privacy Policy
Last updated: July 7, 2026
This policy explains what Cactal collects, how we use it, which providers help us run the service, and the rights and choices available to users, customers, and website visitors.
Who we are
Cactal, Inc., a Delaware corporation ("Cactal", "we"), is the controller for personal information we collect to run our marketing site, product app, API, billing, authentication, support, and account operations. This policy covers cactal.ai, app.cactal.ai, api.cactal.ai, and related Cactal services. When customers use Cactal to publish websites and collect first-party visitor analytics, the customer is responsible for their site and we process that visitor data on their behalf.
Information we collect
- Account and authentication data. Name, email address, profile image, password credentials, email verification state, session identifiers, IP address, user agent, and authentication events.
- Organization and access data. Organization names, slugs, logos, roles, memberships, invitations, website-scoped collaborator access, API key metadata, credential hashes, and audit history.
- Website and customer content. Website names, source files, custom code, CMS schemas, CMS fields and items, redirects, metadata, domains, deployments, generated artifacts, screenshots, images, files, and other assets you upload or publish.
- Billing and usage data. Plan, subscription state, invoices, checkout and portal activity, live-site capacity, usage meters, prepaid balance activity, payment method setup status, provider customer identifiers, and billing events. We do not store full card numbers.
- Product usage and diagnostics. Pages and features used, API and MCP activity, operation outcomes, error categories, rate-limit events, device and browser information, log data, telemetry, and product analytics events.
- Communications. Demo requests, support messages, notification preferences, transactional email delivery status, bounce or complaint data, and suppression records.
Hosted-site analytics
Customer websites may include first-party Cactal analytics. Those analytics can include pageviews, referrers, UTM campaign values, devices, countries, realtime activity, and related traffic statistics. Analytics are measured through same-origin Cactal collection paths rather than third-party advertising trackers, and our systems also process the technical serving logs needed to deliver customer sites. For this visitor data, the site owner is the responsible party: the owner must tell visitors how their site uses analytics, and visitor questions or requests about a customer website should go to that site's owner. We act on owner instructions consistent with our agreements.
How we collect information
We collect information directly from you when you create an account, configure an organization, publish a site, upload assets, use the API or MCP server, start billing flows, or contact us. We collect some information automatically through cookies, local storage, logs, analytics events, and service telemetry. We also receive information from service providers that help us process billing, send email, run analytics, host infrastructure, store assets, and secure the service.
How we use information
- provide, authenticate, authorize, publish, host, analyze, maintain, and support the service
- process subscriptions, usage charges, prepaid balances, invoices, payment setup, cancellations, and billing support
- secure accounts, detect abuse, enforce rate limits, debug errors, preserve audit history, and investigate incidents
- send transactional emails, invitations, OTP codes, billing notices, security notices, service updates, and support responses
- understand product usage, improve features and reliability, and measure the effectiveness of the service
- comply with legal obligations and enforce our Terms, policies, rights, and agreements
Legal bases
Where laws such as the GDPR or UK GDPR apply, we process personal information to perform our contract with you, pursue legitimate interests such as security, support, product improvement, billing administration, and abuse prevention, comply with legal obligations, and rely on consent where the law requires consent, such as for optional communications or non-essential tracking.
How we share information
We share information only as needed to operate Cactal, comply with law, protect rights and safety, or complete a business transaction. We do not sell personal information or share it for cross-context behavioral advertising.
- Infrastructure and hosting. Railway, Postgres infrastructure, S3-compatible object storage, Cloudflare R2/CDN services, and related providers process account, content, asset, and operational data.
- Billing. Autumn and connected payment processors process subscription, checkout, invoice, usage, customer, and payment-method data.
- Email. Resend processes recipient, template, delivery, bounce, complaint, and suppression data for transactional email.
- Analytics and observability. PostHog processes product analytics events. Hosted-site analytics run on Umami infrastructure we operate, and OpenTelemetry-compatible observability services such as OpenObserve may process diagnostics, traces, and metrics.
- Rendering and screenshots. Cloudflare Browser Run and sandbox infrastructure may process public URLs, rendered pages, screenshots, and generated artifacts.
- AI infrastructure. Where AI generation features run, prompts, website source, and related content may be processed by the model and inference providers we use to deliver those features.
- Legal, safety, and corporate events. We may disclose information to comply with law or valid legal process, to protect rights, safety, and the integrity of the service, or in connection with a merger, acquisition, financing, reorganization, or sale of assets, with notice where required.
- Public websites. Content you publish is served publicly to visitors and may be indexed, cached, linked, archived, or copied by third parties.
Cookies and local storage
We use essential cookies for authentication and security. We use local storage for preferences such as theme and for product analytics identifiers when product analytics is enabled. We use session storage for short-lived product analytics flow state, such as sign-in completion. We do not use third-party advertising cookies on the marketing site or product app.
Retention
- Account, organization, website, CMS, source, asset, and billing records are kept while needed to provide the service and for legitimate business, security, tax, accounting, legal, and compliance purposes.
- Organization deletion starts a 30-day support restore window before permanent purge eligibility. Websites deleted by that organization action are taken offline and may be restored with the organization during that window.
- Website deletion starts a 30-day restore window. After that window, the website and its dependent content, source, asset records, and backing objects become eligible for permanent deletion.
- Website assets and generated artifacts use soft-delete and retention sweeps. Deleted asset rows and backing objects are physically cleaned up after the configured retention window, which is currently seven days by default.
- Invitations, sessions, verification records, API keys, logs, audit events, notification events, provider records, and backups follow their configured expiration, retention, or legal hold periods.
Security
We use safeguards intended to protect personal information, including authentication, authorization, scoped API keys, tenant-aware database constraints, rate limits, audit logging, reviewed telemetry allowlists, and encryption in transit where applicable. No method of transmission or storage is completely secure, and you are responsible for protecting your own credentials, exports, and endpoint environments.
International transfers
We and our service providers may process information in the United States and other countries. Where transfer safeguards are required, we use appropriate measures such as contractual protections, standard contractual clauses, or other lawful transfer mechanisms.
Your choices and rights
You may request access, correction, deletion, portability, or restriction of your personal information, object to certain processing, withdraw consent where processing is based on consent, or opt out of optional communications. Email [email protected] or use our contact page to exercise these rights. We may need to verify your identity and authority before acting on a request, and where the law allows, an authorized agent may submit a request for you if we can verify the agent's authority. If we decline a request, we will explain why, and you may appeal by replying to our response.
Regional notices
Depending on where you live, you may have rights under the GDPR, UK GDPR, CCPA/CPRA, LGPD, or similar laws. Those rights may include the right to know categories of personal information collected, sources, purposes, recipients, retention periods, correction, deletion, portability, objection, restriction, non-discrimination for exercising rights, and complaint to a supervisory authority.
For California residents: in the last 12 months we collected the categories of personal information described in this policy, from the sources, for the purposes, and with the recipients described in this policy. We do not sell personal information or share it for cross-context behavioral advertising, so there is no sale or sharing to opt out of, and we treat legally recognized opt-out preference signals such as Global Privacy Control accordingly. We do not use sensitive personal information to infer characteristics or for purposes requiring a separate "limit use" link, and we will not discriminate against you for exercising your rights.
Children's privacy
Cactal is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child provided personal information to us, contact [email protected] and we will take appropriate steps to delete it.
Changes
We may update this Privacy Policy as our service, providers, data practices, or legal obligations change. We will post the updated version here and revise the date above. For material changes, we will provide reasonable notice by email, in-product notice, or another appropriate method.
Contact
Questions or privacy requests? Email [email protected] or use our contact page.