Privacy Policy
Last updated September 18, 2026
This policy explains what Conductor (“Conductor”, “we”, “us”) collects, why we collect it, who we share it with, how long we keep it, and how you get rid of it. It covers the Conductor web application, the API, the command-line tools, and the integrations you choose to connect.
Who this applies to
Conductor is a business product used by teams. Each team works inside a workspace, and the workspace is the boundary for all access: only people invited to it can see what is in it. If you use Conductor through a workspace someone else created, that workspace’s administrators control its membership and its connected accounts.
What we collect
Account information
When you sign in with Google we receive your email address, your display name and the URL of your profile image, and we store a Google account identifier so we can recognise you the next time you sign in. We never receive or store your Google password.
Content you and your agents create
Work Items, documents, comments, reviews and approvals, knowledge pages, workflow definitions and their run history, agent configurations and transcripts, agent memories, and any files you upload. This content belongs to your workspace.
Connected third-party accounts
When you connect an account, say TikTok, Instagram, a Facebook Page, YouTube, Discord, GitHub or Google Drive, you authorise it on that platform’s own sign-in screen. We store the resulting access and refresh tokens in encrypted form, along with the account or page identifier, its display name, and the permissions you granted. We ask for only the permissions the feature you turned on actually needs.
Published content and how it performed
For content that Conductor publishes for you, we store where it went, when it was published, the platform’s identifier for the resulting post, and readings of that post’s public performance counters, taken on a schedule. Those counters are things like view, like, comment and share counts. We read them only for posts Conductor itself published for your workspace. We do not read, index or store your other posts, your followers, your direct messages, or anyone else’s content.
Model provider credentials
Conductor runs on your own model provider keys. Any API key you supply is stored using envelope encryption with a managed key service, and is used only to run the agents in your workspace.
Technical and usage data
Server logs, which record IP address, user agent, request path, timestamps and error details; records of integration deliveries and retries; and authentication cookies. Sign-in uses a single HTTP-only session cookie. We do not use advertising or cross-site tracking cookies.
How we use it
- To run the product: sign you in, limit access to your workspace, run your workflows and agents, and deliver approved content to the destinations you picked.
- To show your workspace how its published content performed, and to write the weekly summaries your agents read.
- To keep the service secure and reliable, which covers abuse prevention, rate limiting, debugging and backups.
- To send the transactional email you asked for: workspace invitations, review notifications and security notices.
We do not sell your data, rent it, or hand it to data brokers. We do not use your workspace content or your connected-platform data for advertising or ad targeting, and we do not use it to train machine-learning models.
Who we share it with
We use a small set of processors, each for one specific job:
- Google Cloud Platform hosts the application and stores files.
- Google Firebase Authentication handles sign-in.
- A managed PostgreSQL provider runs the primary database.
- Resend delivers transactional email.
- The AI model providers you configure receive the prompts and content your agents process, under that provider’s own terms. You choose which provider by supplying its key.
- The platforms you connect receive the content you approve for publication, at the destination you selected.
We may also disclose information where the law requires it, or to protect the rights, safety or property of Conductor, our users or the public. If Conductor is ever part of a merger or acquisition, we will give you notice before your information becomes subject to a different policy.
Data from TikTok and other connected platforms
We use data from a platform’s API only to provide the features you turned on in your workspace, and only for as long as your connection stays active. In TikTok’s case that means two things and nothing else. First, uploading and publishing the content your workspace approved to the TikTok account your workspace connected. Second, reading back the public performance counters of those published videos, so your workspace can see how its own content did. We show that information only to people in your workspace, inside Conductor. We do not embed it, syndicate it, or display your posts or their metrics publicly. We do not share it with third parties, and we handle it according to the relevant platform’s developer terms and policies.
How long we keep it
- Workspace content stays until you delete it or delete the workspace.
- Connection tokens stay until you disconnect the account or revoke access on the platform. At that point the stored tokens are deleted.
- Performance readings are deleted with the Post they belong to, or when the connection they were read through is removed.
- Server logs are kept for a limited operational period, currently up to 30 days, then rotated out.
- Backups are kept on a rolling schedule and overwritten in the ordinary course.
Your choices and rights
- See your data. Everything in your workspace is visible in the application, and reachable through the API and the CLI.
- Disconnect an account. Go to Settings, then Integrations, and disconnect any connection whenever you want. You can also revoke Conductor’s access from the platform’s own security settings.
- Delete content. Delete individual Work Items, documents or knowledge pages in the application.
- Delete your account or workspace. Email us at support@rexipe.io from your account address. We will delete the account, any workspace where you are the only administrator, and the connection tokens and performance readings that go with them, within 30 days.
- Depending on where you live you may have further rights, such as access, correction, portability, erasure or objection. Write to us at the address above and we will honour them.
Security
Traffic is encrypted in transit with TLS. Third-party tokens and model provider keys are encrypted at rest. Access to a workspace depends on membership, and we check it on every request. Sessions use HTTP-only cookies. No system is perfectly secure, and we will notify affected users of any breach that materially affects them.
International transfers
Conductor is operated from the United States and your information is processed there. If you use Conductor from another country, you are transferring your information to the United States.
Children
Conductor is a workplace product and is not aimed at children. We do not knowingly collect information from anyone under 16. If you think a child has given us information, contact us and we will delete it.
Changes
We will update this page when our practices change, and revise the “last updated” date at the top. We will announce material changes in the application or by email.
Contact
Questions, requests or complaints go to support@rexipe.io.