Privacy Policy

Effective date: July 22, 2026

This Privacy Policy describes how Savantly LLC, a Texas limited liability company (“Savantly”, “we”, “us”), collects, uses, and shares information in connection with Headkey, a cognitive memory platform for AI agents (the “Service”). It should be read together with our Terms of Service.

Headkey is a business-to-business service. For content that our customers and their agents ingest into the Service, the customer decides what is collected and why — Savantly processes that content on the customer’s behalf. For account and usage information about the people who sign up for and operate the Service, Savantly determines the purposes of processing.

1. Information we collect

Account information. When you sign up we collect your name, email address, and organization details. Authentication is handled by our identity provider, Clerk; we do not store your password.

Customer Content. Your agents submit content to the Service — messages, documents, events, and data ingested from sources your organization connects (such as GitHub or Slack). What this contains is under your organization’s control and may include personal information about individuals (for example, the people mentioned in a conversation your agent ingests).

Derived data. This is the point of the Service and deserves a plain statement: Headkey processes ingested content with large language models to extract entities and form structured, revisable beliefs — statements like “X prefers Y” or “A works on B” — and those entities and beliefs can describe identifiable people. Derived data is stored alongside the content it came from, is attributed to the agent that learned it, and is treated as Customer Content belonging to your organization.

Usage and log data. We collect API request metadata, usage counters (for quota enforcement), security events, and standard server logs, including IP addresses and request identifiers.

2. How we use information

  • To provide the Service: storing, indexing, retrieving, and reasoning over your organization’s memories, entities, and beliefs.
  • To operate accounts, enforce plan limits, and secure the Service, including tenancy isolation and abuse prevention.
  • To communicate with you about the Service, including material changes to it or to these policies.
  • To improve the Service using aggregate, de-identified operational metrics.

We do not use Customer Content to train machine-learning models, and we do not sell personal information or share it for cross-context behavioral advertising.

3. Large language model processing

To perform extraction, belief reasoning, and embedding, the Service sends relevant portions of Customer Content to third-party model providers — currently OpenAI and Google — under agreements that restrict those providers from using the data to train their models. Model processing is transient: providers return results and do not become long-term stores of your content.

4. How we share information

We share information only with:

  • Subprocessors that host and operate the Service on our behalf — cloud infrastructure, database, search, and caching providers; Clerk for authentication; and the model providers described above.
  • Your organization. Content and derived data are visible within your organization according to the visibility and sharing policies its administrators configure (private, scoped, or organization-wide).
  • Legal recipients, where required by law or to protect the rights, safety, or property of Savantly, our customers, or others.
  • Successors in a merger, acquisition, or asset sale, subject to this policy.

5. Retention and deletion

Customer Content and derived data are retained while your organization’s account is active. The Service provides deletion tools at several levels: organization administrators can delete individual memories, beliefs, and entities (including derived beliefs about a person), and an organization owner can permanently offboard the organization, which deletes its data across all of our data stores and records a deletion receipt. Offboarding is irreversible. Residual copies in backups and logs are purged on a rolling basis.

Account information and security logs are retained as long as needed for the purposes above and to meet legal obligations.

6. Security

We protect information with industry-standard measures: encryption in transit, hashed API credentials, per-organization tenancy isolation enforced at every data store, role-based access to administrative operations, and security-event logging. No system is perfectly secure; notify us immediately at [email protected] if you suspect a vulnerability or breach.

7. Your rights and choices

Depending on where you live, you may have rights to access, correct, delete, or receive a copy of your personal information.

  • If you operate a Headkey account, contact us at the address below and we will honor applicable rights over your account information.
  • If your information appears in content or beliefs held by one of our customers, that organization controls the data; please direct requests to it, and we will support the organization in fulfilling them using the Service’s correction and deletion tools.

8. Children

The Service is not directed to children under 13, and we do not knowingly collect personal information from them.

9. Changes to this policy

We may update this policy from time to time. Material changes will be announced via the Service or by email to organization administrators, and the effective date above will be updated.

10. Contact

Savantly LLC (Texas, USA) — privacy questions and requests: [email protected].