Your data is yours. Only yours.
SchemaBounce runs AI agents on your business data. That data belongs to you and nobody else. We don't sell it, we don't train AI models on it, and we don't use it to show you ads. We charge for subscriptions and usage, so your data is never the product.
This page lists every promise we make about your data, how we keep it, and where it goes. If any of it changes, this page changes first.
Our promises
We never sell your data. Not to advertisers, not to data brokers, not to anyone.
We never train AI models on your data. Your records, files, and agent conversations are not a training set for us.
We never use your data for ads. We don't show ads, we don't build ad profiles, and we don't share your data with ad networks.
Your data stays in your workspace. Every workspace gets its own database. One customer's agents can't read another customer's records.
You can leave with it and delete it. Export your pipeline setup as code at any time. Delete your workspace from settings, and its encrypted backups expire within 30 days.
How this is different
Many free apps pay for themselves with what they learn about you. That is a fair trade for some people. It is the wrong trade for a company's customer records, contracts, and internal decisions.
| SchemaBounce | Consumer AI chat apps | Ad-funded social networks | |
|---|---|---|---|
| How the company makes money | Subscriptions and usage | Subscriptions, with free tiers | Advertising |
| Trains its own AI on what you share | Never | ChatGPT may, unless you turn off "Improve the model for everyone" (OpenAI) | Meta explains how it trains its AI on its generative AI privacy page |
| Uses what you share for ads | Never | Not in paid business plans | Meta uses interactions with its AI to personalize ads (Meta) |
| Sells your data | Never | No | Doesn't sell it; uses it to target ads for advertisers |
The comparison uses each company's own published policies, linked in the table. Business plans from OpenAI, such as the API, ChatGPT Team, and Enterprise, don't train on your data by default. That is the standard we hold everything to.
What we control, and what we don't
Everything above covers what SchemaBounce controls: our servers, our databases, our staff, and our business. Your agents also call AI models, and each model's provider sets its own rules for the prompts it receives. We tell you what those rules are so you can choose.
When we run the model for you, we call the provider's business API, not a consumer app. Each provider's terms decide what it may do with those prompts:
- Anthropic: "Anthropic may not train models on Customer Content from Services." (Anthropic commercial terms)
- OpenAI: business and API data is not used for training by default. (OpenAI)
- Google: on the paid Gemini API, "Google doesn't use your prompts ... or responses to improve our products." (Gemini API terms)
- Moonshot (Kimi): its terms allow content it receives to be used to develop and improve its services, and they offer no self-serve opt-out. (Moonshot terms)
If a provider's terms don't fit your data, choose a different model for that agent, or bring your own key.
When you bring your own key, the call runs under your own agreement with that provider. We store your key encrypted and use it only for your workspace.
How we keep it
Encrypted in transit and at rest. Traffic uses TLS. Stored data uses AES-256 envelope encryption. Paid workspaces get their own encryption key in AWS Key Management Service.
Walled off by workspace. Every workspace has its own database on every plan. Team and higher plans also get a dedicated runtime, cache, and network boundary. See data safety for the details.
Staff access is locked down. Only a small operations team can reach production systems, over a private network, with every action recorded. Our policy bans anyone from reading your records or agent conversations outside the product itself, and we treat any break of that rule as a top-severity security incident.
Hosted in the United States. Your workspace runs in US data centers.
Compliance. SOC 2 Type II and PCI DSS are in progress.
Who else touches your data
We use a small set of vendors to run the service. Each one gets only what its job needs.
| Vendor | What it handles | Why |
|---|---|---|
| Vultr | Workspace compute and storage | Hosting |
| Amazon Web Services | Encryption keys, stored credentials, sign-in | Security and login |
| Cloudflare | Website delivery, bot protection, encrypted backups | Delivery and backups |
| Stripe | Billing details (never full card numbers on our side) | Payments |
| Sentry | Error reports | Keeping the service up |
| AI model providers (for example Anthropic, OpenAI, Google) | Prompts and responses when we run a model for you | Running your agents |
| Composio | Access tokens for tools you connect | Tool connections |
| Email delivery provider | Your email address and account notices | Account email |
The full, current list is in our privacy policy.
Common questions
Does SchemaBounce train AI on my data?
No. We don't train any model on your records, files, or agent conversations. The AI model providers your agents call follow their own terms, and some, such as Moonshot's Kimi, may use prompts to improve their models. The section on what we control lists what each one says.
Does SchemaBounce sell my data?
No. We don't sell it, rent it, or share it with advertisers or data brokers. We make money from subscriptions and usage.
Can SchemaBounce employees read my data?
Our policy bans it. Only a small operations team can reach production systems, over a private network, with every action recorded, and reading customer records or conversations outside the product is treated as a top-severity security incident.
Where is my data stored?
In US data centers, in a database that belongs to your workspace alone. Paid workspaces also get their own encryption key.
What happens when I delete my workspace?
Your workspace and its data are removed from service. Encrypted backups of it expire within 30 days.
Can I use my own AI provider key?
Yes. Your prompts then run under your own agreement with that provider, and we use your key only for your workspace.
How is this different from ChatGPT or Facebook?
Consumer ChatGPT may use your conversations to train models unless you opt out, and Meta uses interactions with its AI to personalize ads. SchemaBounce does neither, for any plan, with no setting to find.