PretzelGraph

  • Home
  • How it works
  • Build
  • Pricing
Try for free

Privacy Policy

Effective date: [DATE] Last updated: [DATE]

This policy explains what personal data PretzelGraph collects when you use the hosted service at pretzelgraph.ai (the "Service"), why, and what rights you have. It is written to meet the EU General Data Protection Regulation (GDPR).

Who is responsible: Teslaru Roland Persoană Fizică Autorizată (PFA), [REGISTERED ADDRESS], Romania ("we", "us"). We are the data controller for the account and billing data described below. Contact: [email protected].

The self-hosted software is different. If you run PretzelGraph on your own infrastructure under its source-available licence, nothing is sent to us: no telemetry, no account check, no usage reporting. This policy covers only the hosted Service.

1. What we collect

1.1 Account data

When you sign up we store your email address, a display name, a username, and an avatar if you set one. If you sign in through a third-party identity provider (for example Google or GitHub), we receive the profile fields that provider shares and store only those listed above.

1.2 Workspace content

Everything you create inside a workspace: workflows and their configuration, folders, publications, execution history (inputs, outputs, and logs of runs, retained for the period of your plan), chats, and uploaded attachments. This content may contain personal data about other people — for example if a workflow processes customer records. For that data you are the controller and we are your processor: we process it only to run the Service on your instructions. A data processing agreement is available on request (see section 9).

1.3 Credentials you store

API keys, passwords, and connection strings you save in a workspace's vault. These are encrypted at rest with a key unique to your workspace and decrypted only inside your workspace's own infrastructure when a workflow needs them. They are never displayed back to you or to us in plain text, and we do not use them for any purpose other than running your workflows.

1.4 Payment data

If you subscribe to a paid plan, payment is handled by Stripe. We do not receive or store your card number. We receive and keep: your billing name and address, the last four digits and brand of your card, invoices, and your subscription status, as required for billing and tax law.

1.5 Technical data

When you use the Service we automatically record: IP address, browser and device information, the pages and API endpoints you use, timestamps, and error reports. Each workspace also records when it was last active, which we use to pause idle workspaces (see section 3).

1.6 Communications

If you email us or use an in-app support channel, we keep the correspondence.

2. What we do not collect

We do not run third-party advertising, tracking, or analytics. We do not sell personal data.

3. Why we process it, and on what legal basis

PurposeDataLegal basis (GDPR Art. 6)
Creating and operating your account and workspacesAccount data, workspace content, credentialsContract (6(1)(b))
Running your workflows, including calling the third-party services you configureWorkspace content, credentialsContract (6(1)(b))
Billing, invoicing, and tax compliancePayment dataContract (6(1)(b)); legal obligation (6(1)(c))
Keeping the Service secure, preventing abuse, debuggingTechnical dataLegitimate interest (6(1)(f)) — protecting the Service and other users
Pausing idle workspaces to manage capacityLast-activity timestampsLegitimate interest (6(1)(f))
Answering your messagesCommunicationsLegitimate interest (6(1)(f))
Product announcements by emailEmail addressConsent (6(1)(a)) — you can unsubscribe at any time

4. Third-party services your workflows use

Workflows connect to services you choose — language-model providers, databases, APIs — using your own credentials. When a workflow runs, data flows from our infrastructure to those services under their terms and privacy policies, not ours. Check the policies of any provider you connect, particularly for where they store data and how they use it.

5. Who we share data with (sub-processors)

We use a small number of providers to run the Service. Each processes data only on our instructions and under a written agreement.

ProviderPurposeLocation
Cloud infrastructure providerCompute and databases for workspacesUnited States
CloudflareDNS, TLS, and traffic routingEU / global edge
StripePayments and invoicingEU / US
[EMAIL PROVIDER]Transactional email (sign-in links, password resets, receipts)[LOCATION]

The current list is published at https://pretzelgraph.ai/legal/notice and we will update it before adding a provider that processes customer content.

6. International transfers

Your workspace data is currently stored in the United States, with our cloud infrastructure provider. For data leaving the EU we rely on the EU–US Data Privacy Framework where the provider is certified, and otherwise on the European Commission's Standard Contractual Clauses. If we add EU-region hosting, this section and the sub-processor list will be updated.

7. How long we keep data

DataRetention
Account dataUntil you delete your account, then up to 30 days in backups
Workspace contentUntil you delete it or the workspace; execution history is pruned on the schedule of your plan
CredentialsUntil you delete them or the workspace
Payment recordsAs long as Romanian tax and accounting law requires (5–10 years depending on record type)
Technical logs30 days
Idle free-tier workspacesPaused after inactivity; the workspace data is kept and the workspace resumes on your next visit

8. Security

Each workspace runs in isolated infrastructure with its own database; credentials are encrypted with a per-workspace key; all traffic is over TLS; access to production systems is restricted to the operator. No system is perfectly secure, and if we become aware of a breach affecting your data we will notify you and the supervisory authority as the GDPR requires.

9. Your rights

Under the GDPR you can ask us to: access the personal data we hold about you; correct it; delete it; restrict or object to processing based on legitimate interest; receive it in a portable format; and withdraw consent at any time where consent was the basis. Write to [email protected]; we respond within one month. You also have the right to lodge a complaint with a supervisory authority — in Romania, the ANSPDCP (Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal, dataprotection.ro) — or with the authority in your own EU country.

Most of this you can do yourself: account settings let you edit your profile, export workflows, and delete your account and workspaces.

If you need a data processing agreement because you process other people's personal data through the Service, email [email protected].

10. Children

The Service is not intended for anyone under 16, and we do not knowingly collect data from children. If you believe a child has created an account, contact us and we will delete it.

11. Changes

We will post changes here and update the date above. For material changes we will notify you by email or in the app before they take effect.

12. Contact

Teslaru Roland Persoană Fizică Autorizată (PFA), [REGISTERED ADDRESS], Romania — [email protected]

PretzelGraph

PretzelGraph is a visual agent runtime. Design how your agent thinks — its loop, its tools, its memory — on a canvas, then run it as a chat assistant, an automation, or a building block inside a bigger workflow.

  • Product
  • How it works
  • Build
  • Pricing
  • Self-host
  • Developers
  • Documentation
  • GitHub
  • Node SDK
  • Changelog
  • Legal
  • Terms of Service
  • Privacy Policy
  • Cookie Policy
  • Acceptable Use
  • Legal Notice