Collect less by default.
Prompt content, model output and tool arguments are disabled by default. Customers choose what evidence fields may leave the private runner.
Last updated 3 October 2026
Conseqa is operated by Devraj Jhala in India. For support, privacy requests, or security reports, contact jhaladevrajsinh11@gmail.com. These notices describe the current early-access service. They do not claim an independent legal review, regulatory certification, or a negotiated enterprise agreement.
Data processed
The hosted service processes account identity, organization and project configuration, redacted OpenTelemetry metadata, action lifecycle events, evaluated outcomes, runner health, issue and alert state, and contract manifests and schemas.
Why we process this data
We use account and workspace data to authenticate users, enforce access boundaries, operate the dashboard, verify recorded outcomes, deliver configured alerts, respond to support requests, and investigate reliability or security problems. Do not submit payment-card data, health records, provider passwords, or other sensitive personal information to the hosted service.
Data not intended for the cloud
Provider credentials, database credentials, encrypted spool files and executable contract callbacks remain local. Prompt or response content is excluded unless an authorized customer explicitly enables capture and configures redaction.
Retention and deletion
Trace retention is shown per environment in Settings. Action evidence and audit data have separate retention from traces and currently remain until environment-data deletion. Workspace members can export authorized data; organization owners can request environment-data deletion in Settings. The displayed status shows completion, not merely receipt of the request. Environment deletion does not itself delete a Neon Auth account. Contact us to request account closure, correction, or access to your personal data.
Providers, storage and cookies
Vercel hosts the web service; Neon provides the hosted PostgreSQL database and authentication. Those providers process service data and technical request information. The current database is in Singapore; hosting, authentication, operational logs, and support messages may be processed outside India. Gmail handles messages sent to our published contact address. No India-only residency or enterprise data-processing agreement is offered by this early-access release.
Essential authentication cookies maintain your signed-in session. A local browser preference remembers the selected colour theme. We do not add advertising cookies or third-party advertising trackers. Optional alert email uses Resend only when a sender has been configured and explicitly enabled; webhook delivery sends the configured redacted issue metadata to the HTTPS endpoint selected by your administrator.
Requests and backup limitations
Email jhaladevrajsinh11@gmail.com for privacy questions or a complaint. We may need to confirm your account ownership before releasing or changing data. Do not email passwords, API keys, or raw customer records. An environment-data deletion request does not remove operator-held encrypted recovery archives immediately. Recovery copies currently require operator-managed expiry, and no automatic off-site backup schedule or maximum backup retention is promised. Ask us to confirm archive expiry before submitting production personal data. Material changes to this notice will be published here with an updated date.