Introduction
Welcome to Calypso ("we," "our," or "us"). We provide a platform ("Calypso Platform", the "Platform") that enables registered individuals or teams ("Users," "you," "your") to build, deploy, and manage artificial intelligence agents ("AI Agents") and automated workflows. Users may belong to projects or teams within the Platform.
This Privacy Policy explains how we collect, use, disclose, and protect information, including Personal Data, in connection with the Platform. It specifically addresses the data processed when Users use our Platform and the resulting storage of messages and data exchanged through AI Agents and workflows.
This policy applies to Users of our Platform. It also outlines our role concerning the data of end-users interacting with AI Agents and workflows built on our Platform.
Definitions
- Platform
- Our website, APIs, tools, and services operated by Calypso 1, Inc. that allow Users to build and manage AI Agents and automated workflows.
- User
- An individual or entity registered to use our Platform, potentially as part of a project or team.
- AI Agent
- An artificial intelligence application built by a User on our Platform designed to interact and perform automated tasks.
- End-User
- An individual interacting with an AI Agent or workflow built on our Platform.
- Personal Data
- Any information relating to an identified or identifiable natural person.
- User Data
- Information provided by Users when they register for or use our Platform (e.g., name, email, company info, team/project associations, usage data).
- End-User Data
- Messages, interactions, and data processed and stored by our Platform on behalf of the User through AI Agents and workflows.
Information We Collect
Account information
When you register, we collect:
- Name, email address, password, company name (if applicable)
- Billing information and payment details
- Information regarding your association with specific projects or teams
Usage information
- Features accessed, AI Agent configurations, performance metrics
- API calls, IP addresses, browser type, operating system, log data
- Team member activities and project interactions
Communication information
Content of communications when you contact us for support via privacy@calypso.day or other channels.
End-User Data (processed on behalf of Users)
When an End-User interacts with an AI Agent or workflow built on our Platform by a User, we receive and process:
- Messages and interactions exchanged through AI Agents
- Conversation content, sender/recipient identifiers, and timestamps
- Workflow execution data and results
- Integration data from connected third-party services
Important: We store this data on our systems to enable AI Agent functionality and provide conversation history access to authorized Users within a project/team.
Third-party information
We may receive information from third-party services when you connect them to our Service:
- Social media profile information (Facebook, Instagram, etc.)
- Authentication data from identity providers
- Integration data from connected applications and APIs
- Webhook data from external services
Our Role as Data Controller and Processor
User as Controller (End-User Data)
For messages and interactions exchanged through AI Agents built by Users on our Platform, the User (or organization/team the User represents) is the Data Controller.
- User determines purposes and means of processing
- User responsible for legal basis (e.g., consent)
- User must provide privacy notices to End-Users
Calypso as Processor (End-User Data)
We act as a Data Processor on behalf of the User for End-User interactions and data.
- Process data based on User's instructions
- Enable AI Agent operation and store conversation history
- Provide data access to authorized team members
- Processing limited to Platform functionality
Note: We are the Data Controller for User Data we collect directly from Users (account information, usage data, billing information, etc.).
Information Sharing and Disclosure
We do not sell your Personal Data. We may share information in the following circumstances:
Within User teams/projects
Information associated with a specific project, including stored messages and data related to AI Agents within that project, is accessible to all authorized User members belonging to that project or team on the Platform, as managed by the project/account administrators.
Authorized external sharing
- Service Providers: Third-party vendors who perform services on our behalf (hosting providers, payment processors, analytics providers, customer support tools)
- Legal Requirements: When required by law, subpoena, court order, or government request
- Business Transfers: In connection with mergers, acquisitions, financing, or asset sales
- Protection: To protect our rights, privacy, safety, or property, or that of users and the public
- Aggregated Data: Anonymized information that does not directly identify individuals
Data Storage, Security, and Retention
Data storage location
Your information, including User Data and stored End-User interactions, is primarily processed and stored on infrastructure provided by industry-leading cloud providers, which may involve servers located in various regions, including the United States and Europe.
- Hosting: AWS, Google Cloud, Vercel
- Databases: PostgreSQL, MongoDB
- Regions: US, EU, Asia-Pacific
Security measures
We implement appropriate technical and organizational security measures designed to protect the information we process against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access.
Technical measures
- Encryption of data in transit (HTTPS/TLS)
- Encryption of database data at rest
- Authentication mechanisms for User access control
- Regular software updates and security patching
- Logical separation of data where applicable
- API rate limiting and DDoS protection
Organizational measures
- Employee training and awareness programs
- Robust physical and network security (via hosting partners)
- Access controls and monitoring systems
- Incident response procedures
- Regular security audits and assessments
- Data processing agreements with vendors
Important: No security system is impenetrable, and we cannot guarantee the absolute security of data transmitted to or stored on the Platform.
Data retention policies
- End-User interactions and User project data: We store End-User interactions processed through the Platform and associated User project data indefinitely for as long as the User's account is active, to provide ongoing service and historical context.
- Account termination: If a User terminates their account, we will initiate deletion of their associated User Data and stored End-User interactions linked to their account and projects. Data will be permanently deleted within 30-90 days, unless legally required to retain information longer.
Specific retention periods
- Account information: Duration of account + 30 days
- AI Agent configurations: Duration of account
- End-User interactions: Duration of account
- Usage analytics: 2 years from collection
- Support communications: 3 years
- Financial records: 7 years (legal requirement)
- Security logs: 1 year
- API access logs: 90 days
Data Subject Rights (Your Rights as a User)
Depending on your location (e.g., GDPR in Europe, CCPA in California), you may have certain rights regarding your Personal Data that we hold as a Controller (i.e., your User Data):
Access and control
- Access your personal information
- Correct inaccurate data
- Update your preferences
- Request data portability (structured format)
Deletion and restriction
- Delete your personal information
- Restrict processing activities
- Object to processing based on legitimate interests
- Withdraw consent
End-User data rights
For End-Users: If you are an End-User who has interacted with an AI Agent or workflow, and wish to exercise your data subject rights concerning those interactions, please direct your requests to the User (or organization/team) who built and operates that AI Agent, as they are the Data Controller for that data.
We will reasonably assist Users in responding to such requests as required by law and our contractual agreements.
To exercise your rights regarding User Data: Contact us at privacy@calypso.day or visit our Data Deletion page. We may need to verify your identity before processing your request.
Third-Party Services
Our Service may contain links to third-party websites or integrate with external services. This Privacy Policy does not apply to third-party services, and we encourage you to review their privacy policies.
Common third-party integrations
- Social media platforms (Facebook, Instagram, Twitter, WhatsApp)
- Analytics services (Google Analytics, Mixpanel)
- Payment processors (Stripe, PayPal)
- Cloud service providers (AWS, Google Cloud, Vercel)
- Customer support tools (Intercom, Zendesk)
- AI and ML services (OpenAI, Anthropic, Google AI)
- Communication APIs (Twilio, SendGrid)
International Data Transfers
Your information, including Personal Data and stored End-User interactions, will be transferred to, stored, and processed in countries other than your own, primarily where our service providers operate data centers, including potentially the United States and locations within the European Union.
These countries may have data protection laws that differ from those in your country. Calypso takes steps designed to ensure that your Personal Data receives an adequate level of protection in the jurisdictions in which we process it.
Safeguards we use
- Standard Contractual Clauses (SCCs) where applicable
- EU-U.S. Data Privacy Framework compliance where required
- Adequacy decisions from relevant authorities
- Binding corporate rules and data processing agreements
Children's Privacy
Our Platform is not intended for or directed at children under the age of 16 (or a higher relevant age threshold). We do not knowingly collect Personal Data from children via our Platform registration.
If we become aware that we have inadvertently collected such data, we will take steps to remove it. Users are responsible for ensuring their AI Agents comply with all applicable laws regarding interactions with children, including obtaining verifiable parental consent where required.
Social Media Platform Compliance
This data processing complies with Meta's data handling requirements and other social media platform policies for applications integrated with Facebook, Instagram, WhatsApp, and other platforms. When you request data deletion or exercise your rights:
- All data obtained from social media platforms will be handled according to their requirements
- Any stored access tokens will be managed securely and invalidated when requested
- Integration with social media services will be terminated upon account deletion
- Cached social media content will be removed according to our retention policies
- End-User interactions via social platforms will be processed according to controller/processor agreements
Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or for other operational, legal, or regulatory reasons. We will notify you of any material changes by posting the new Privacy Policy on the Platform and updating the "Effective Date" at the top.
We may also notify you via email or through the Platform interface. We encourage you to review this Privacy Policy periodically. Your continued use of the Platform after any changes constitutes your acceptance of the revised policy.
Contact Us
If you have any questions about this Privacy Policy or our data practices, please contact Calypso 1, Inc. at:
- privacy@calypso.day
- Company
- Calypso 1, Inc.
- Office
- Data Protection Office