Legal

Privacy Policy

Effective: September 8, 2026  ·  Last updated: September 8, 2026

1. Who we are

cpum.ai ("cpum.ai", "we", "us", or "our") operates an observability and incident-response platform consisting of a hosted dashboard, a host-installed collector agent, a mobile application, a desktop tray application, and a browser extension. This Privacy Policy describes how we collect, use, disclose, and protect information across all of these surfaces.

For privacy questions, data subject requests, or to exercise any right described below, contact privacy@cpum.ai.

2. Information we collect

2.1 Account information

When you sign up, we collect your email address, display name, authentication identifiers from our identity provider (Clerk), and (for paid plans) billing information processed by Stripe. We do not store full payment card numbers — Stripe handles card data directly under PCI-DSS.

2.2 Operational telemetry from your hosts

When you install the cpum.ai agent on a server, the agent sends us system metrics (CPU, memory, disk, network), running process metadata (PID, command name, user, parent PID), container metadata, and — only when you explicitly enable them — OpenTelemetry traces, logs, and eBPF-derived stack samples. This telemetry is scoped to the workspace you create it under and is never used to train shared machine-learning models.

2.3 AI investigation context

When you trigger an AI investigation, we send the relevant slice of your operational telemetry — the metrics, recent logs, recent deploys, and incident timeline pertinent to that investigation — to our configured LLM provider. Depending on the feature and routing configuration, that provider may be Anthropic or OpenAI. These providers process the submitted context under their applicable enterprise/API data-processing terms and it is not used to train shared models. You can disable AI investigations entirely from the workspace settings page.

2.4 Third-party integration credentials

If you connect cpum.ai to GitHub, Slack, PagerDuty, Datadog, CloudWatch, or another integration, we store the access tokens you provide. Sensitive secrets are encrypted at rest with AES-256-GCM (see lib/secret-cipher.ts in our open integration documentation).

2.5 Product analytics and logs

We collect first-party product analytics events (page views, feature interactions, signup → activation funnel steps) and server-side logs containing IP addresses, user-agent strings, and request metadata. Analytics data is retained for up to 24 months; request logs are rotated after 30 days.

3. How we use your information

  • To operate and maintain the cpum.ai platform and the agent.
  • To compute incidents, SLO breaches, anomaly detection, and AI investigations on your data.
  • To send transactional notifications (incidents, budget warnings, billing) via email, push, and webhook.
  • To detect, prevent, and respond to security incidents, abuse, and fraud.
  • To meet legal, tax, and accounting obligations.
  • With your explicit opt-in, to send product update emails. You can unsubscribe at any time.

We do not sell personal information. We do not use your operational telemetry to train shared models or to benchmark you against other customers without explicit opt-in.

4. How we share information

We share data only with these categories of processors:

  • Identity / auth: Clerk (account & session management).
  • Payments: Stripe (subscription billing, card processing).
  • Hosting: our cloud infrastructure provider (data stored in the United States; EU region available on Enterprise plans).
  • AI providers: Anthropic and OpenAI, only for the AI features and translation-review workflows that use them, under their applicable API data-processing terms.
  • Email delivery: Resend for transactional and notification email.
  • Error monitoring: our internal error-tracking system.

We may also disclose information when required by law, in response to a valid legal process, to protect the rights or safety of cpum.ai or others, or in connection with a merger, acquisition, or sale of assets (subject to your continued rights under this policy).

5. Your rights

Depending on your jurisdiction (GDPR, UK GDPR, CCPA/CPRA, LGPD, and equivalents) you have the right to access, correct, port, restrict, or delete personal information we hold about you, and to object to certain processing. To exercise any of these rights, email privacy@cpum.ai. We respond within 30 days. You may also lodge a complaint with your local data protection authority.

Workspace owners can delete their workspace at any time from account settings; deletion permanently removes all telemetry, incidents, investigations, and integration credentials within 30 days, except where we are required to retain records (billing for tax purposes, security audit logs).

6. Data retention

  • Operational metrics: 30 days on Free, 90 days on Pro, 1 year on Team, configurable on Enterprise.
  • Incidents & investigations: retained for the lifetime of the workspace, deleted on workspace deletion.
  • Logs & traces: 7 days on Free, 30 days on Pro+, configurable on Enterprise.
  • Account & billing records: retained for 7 years after account closure for tax compliance.
  • Security audit logs: 1 year minimum.

7. Security

All data in transit is encrypted with TLS 1.2 or higher. Secrets (integration tokens, webhook keys) are encrypted at rest with AES-256-GCM under a key managed in our environment. We enforce SSRF protection on all outbound webhook destinations, scoped tenant isolation on every authenticated route, and constant-time comparison on all secret-bearing inputs. Our agent collector is open-source (Apache-2.0) and verifiable.

No security control is perfect. If you believe you have found a vulnerability, please email security@cpum.ai. We do not pursue legal action against good-faith security researchers.

8. International transfers

cpum.ai is operated from the United States. If you access cpum.ai from outside the United States, your information will be transferred to and processed in the United States. We rely on Standard Contractual Clauses (SCCs) for transfers from the European Economic Area, the United Kingdom, and Switzerland.

9. Children

cpum.ai is not directed to children under 16, and we do not knowingly collect personal information from children. If you believe a child has provided us with personal information, email us and we will delete it.

10. Cookies

We use strictly necessary cookies for authentication and session management, and a small number of first-party cookies to remember your locale and UI preferences. We do not use third-party advertising cookies.

11. Changes to this policy

We will post material changes to this Privacy Policy at this URL and notify active users by email at least 30 days before any material change takes effect. The "Last updated" date at the top reflects the most recent revision.

12. Contact

cpum.ai  ·  privacy@cpum.ai for privacy  ·  security@cpum.ai for security  ·  support@cpum.ai for everything else.

See also our Terms of Service.

Privacy Policy — cpum.ai | cpum.ai