Privacy Policy
Effective July 19, 2026
What we collect
When you create an account, we collect your email address and the organization name you provide. We use Supabase Auth for passwordless sign-in; your authentication session is stored in your browser and transmitted to our servers to verify your identity on each request.
When you start a paid subscription, Stripe collects and processes your payment information. We do not receive, store, or have access to your full credit card number, CVC, or bank details. Stripe provides us with a customer identifier, subscription status, and billing period dates so we can manage your entitlement.
What we do not collect
Ummi is an approval and audit layer for agent actions. The exact actions your agents perform, the credentials they use, the content of approval decisions, and the resulting audit receipts stay inside your isolated Ummi Core deployment. We do not ingest, store, or have access to your action payloads, database credentials, internal tool configurations, or audit records.
Our servers do not log the content of your agent requests, your approval decisions, or the results of executed actions. We do not use your operational data to train models.
How we use your information
Your email is used solely to authenticate you and to send you transactional messages related to your account (sign-in links, billing notices, service announcements). Your organization name is displayed within your workspace dashboard. We do not sell, rent, or share your personal information with third parties for their own marketing purposes.
Service providers
We use the following service providers to operate Ummi:
- Supabase — authentication, organization membership, and entitlement records. Supabase hosts our control-plane database in the US West (Oregon) region.
- Stripe — payment processing. Stripe processes your payment information and provides us with subscription status updates via webhooks. Stripe's privacy policy applies to payment data they process.
- Cloudflare — application hosting and content delivery. Cloudflare serves the Ummi web application from its global edge network and may process your IP address and request metadata for security and performance purposes.
Data retention
We retain your account information (email, organization, membership, and entitlement records) for as long as your account is active. If you cancel your account, your control-plane records are deleted within 30 days. Action payloads, credentials, and audit records in your isolated Ummi Core deployment are never stored on our servers and are governed by your own retention practices.
Your rights
You may request a copy of the personal data we hold about you, ask us to correct inaccurate data, or request deletion of your account and associated data by contacting us at privacy@ummi.app. We will respond within 30 days.
Changes to this policy
If we make material changes to this policy, we will notify you by email and update the effective date above. Your continued use of Ummi after a change constitutes acceptance of the updated policy.
Contact
For questions about this privacy policy, contact us at privacy@ummi.app.