Privacy Policy
Last updated August 21, 2026
This policy explains what Visceral collects when you use visceralai.dev, the dashboard, the APIs, the SDK, and the capture proxy (together, the “Service”), how that data is stored and protected, and the choices you have. Our use of your data is also governed by the Terms of Service.
What we collect
- Account information. Your email address and a password. Authentication is handled by Amazon Cognito; your password never lands in our own database.
- Call metadata. For every LLM call the Service observes we record metadata: model names, token counts, costs, latencies, and content hashes. This stream contains no prompt or response text.
- Captured payloads. Some features, such as caching and replay, need the content of LLM requests and responses. When we capture that content it is stored encrypted at rest with AES-256-GCM under a key unique to your workspace.
- API keys. We do not store your LLM provider API keys in our database. When you route calls through the capture proxy, your provider key passes through to the provider with each request and is not persisted. The workspace API keys we issue to you are stored as hashes.
- Contact and support. The name, email address, and message you submit through the contact form.
- Operational logs. Standard server logs (IP addresses, user agents, timestamps) used to run and secure the Service.
How we use it
We use this data to operate the Service: to compute and validate optimizations for your own workspaces, to meter usage and enforce plan limits, to respond when you contact us, and to keep the Service secure. We do not sell your data. We do not train machine learning models on your captured content, and we do not use one customer’s content to serve another.
Where your data lives and how it is protected
The Service runs on Amazon Web Services in the us-east-1 region (United States). Data is encrypted in transit with TLS. Captured payloads are encrypted at rest with AES-256-GCM under per-workspace keys, and workspace isolation is enforced at the database layer with row-level security.
Subprocessors
We rely on these providers to run the Service:
- Amazon Web Services (us-east-1, United States): hosting, storage, and account authentication.
- Temporal Cloud (United States): schedules and coordinates our background processing jobs.
We will update this policy when our subprocessors change.
Retention
On the free plan, captured payloads and call records are retained for 30 days and then removed by a scheduled sweep. Account information is retained while your account is active.
Your choices and deletion
To access, correct, or delete data we hold about you or your workspaces, including deleting your account, contact us through the contact form. We will verify the request, act on it, and confirm with you when it is complete.
Children
The Service is built for business use and is not directed to children.
Changes to this policy
We may update this policy from time to time; when we do, we will change the “Last updated” date above, and for material changes we will give reasonable notice.
Contact
Questions about privacy at Visceral? Reach us through the contact form.