Privacy Policy
Last updated: 18 September 2026
Descles ("we", "us") operates descles.com. This policy explains what the Descles control plane and model gateway handle, why, and what rights you have.
1. Your model traffic passes through us
Descles is a gateway: a request your agent sends to us is forwarded to the provider endpoint you configured, and the response is streamed back to your client. That means the content of those requests and responses — prompts, messages, tool definitions, model output — is transmitted through our infrastructure in transit to a provider you chose. We do not use it to train models, we do not sell it, and we do not share it with anyone other than the endpoint you are routing to.
What we record about a call is its governance and usage record, not the conversation:
- which workspace, group and agent made the call, and which key it used;
- the provider label you gave the endpoint and the model string you sent;
- token counts (input, output, cached), an estimated cost, and latency;
- the names of the tools the model proposed — not their contents, unless a rule holds one;
- the policy decision for that call, and any error type;
- timestamps and a trace identifier.
One exception, and it matters: when policy holds a tool call for approval, the approval record keeps the tool name and the arguments the model proposed, because that is what an operator has to read before deciding. If you do not want a particular argument value recorded, do not let a rule route it to approval — deny it, or keep it out of the prompt.
2. Provider credentials
- Stored with us (hosted BYOK). The endpoint and key are encrypted at rest (AES-GCM) and are never returned by any list or read endpoint. Agents authenticate with Descles agent keys instead, so the provider credential stays out of your machines.
- Per-request BYOK. You send the provider endpoint and key as headers on each call. We forward the credential for that call and do not store it.
3. Your account and workspace
- Identity. Sign-in is handled by Clerk, on GitHub, Google or email. We receive your name, email address, avatar and the account identifier from Clerk. The browser never supplies the email used to provision a workspace.
- Workspace records. Your organization, its person groups, agents, budgets, policy documents, approval decisions and audit records. Agent keys are stored as hashes; the plaintext is shown once when the key is issued.
- Roadmap votes and feedback. If you vote on a planned feature while signed in, we record the vote against your account so one account counts once. Email we receive is kept as ordinary correspondence.
4. Payments
Paid plans are sold by Waffo Pancake, our Merchant of Record, who is the seller on your receipt. Card details and billing details go to Waffo Pancake and never reach us — we receive only the order record: a reference, the product, the amount, the currency and the email address you gave at checkout. Waffo Pancake's privacy policy governs what it does with the payment itself.
5. Cookies and analytics
- Session cookies set by Clerk, so you stay signed in. Without them the console and account actions cannot work.
- Aggregate page analytics via Vercel Analytics, which counts page views without setting cookies and without building a profile of you.
We run no advertising or cross-site tracking tag on this site.
6. Who else is involved
| Clerk | Identity and sign-in. |
|---|---|
| Vercel | Serving this site, the docs and the console front end. |
| AWS | The gateway and control plane run in AWS Asia Pacific (Sydney), with records on encrypted storage. |
| Waffo Pancake | Payments, receipts and any applicable sales tax. |
| Your model provider | Whatever endpoint you route to receives the traffic you route to it. |
We do not sell personal data.
7. Where data is processed
The gateway and control plane run in AWS Asia Pacific (Sydney). Our processors operate globally, so your account and workspace records may be processed outside your country, including in the United States and the European Union. Where the law requires it, transfers rely on the processor's standard contractual clauses.
8. Keeping and deleting
Gateway and governance records are kept while your workspace is active, so budgets, traces and the audit chain stay coherent. Ask us to delete your workspace and we remove your workspace records and traces within 30 days, except records we must keep to satisfy tax, accounting or legal obligations — order records, typically, which are held by Waffo Pancake under its own policy. Message content is not in our records to delete.
9. Your rights
Depending on where you live, you may have the right to access, correct, delete or port your data, to object to or restrict its processing, and to complain to a data-protection authority. Write to outreach@descles.com and we will answer within the period your law allows. Because most of what we hold is about your workspace rather than about you personally, a request usually resolves to an export of that workspace plus a statement of what we hold.
10. Security
Traffic to the gateway and console is encrypted in transit. Stored provider credentials are encrypted at rest with AES-GCM and are never returned by an API. Agent keys are stored as hashes. Each workspace is isolated: one organization cannot see another's agents, traces, budgets or approvals. Governance events are appended to a signed hash chain, so tampering breaks verification. No system is perfect, and we cannot promise security incidents will never happen.
11. Children
Descles is a tool for people running agents at work. It is not directed at children, and we do not knowingly collect information from anyone under 16.
12. Changes
If this policy changes in substance, the date at the top changes and a material change is announced on the site. See also our terms and refund policy, or write to outreach@descles.com.