Cortya

Privacy Policy

Last revised July 29, 2026

This policy explains what Cortya ("Cortya," "we," "us," or "our") stores when you use Cortya, why, and who processes it on our behalf. Cortya is deliberately data-minimal: we store what is needed to run your agent teams and nothing more. Your agents run on your own keys; Cortya does not access your PHI or other sensitive data or systems, and for regulated workloads your agents run inside your own environment so that data never reaches us.

What we store

DataWhy
Account email addressSign-in (magic-link / one-time code) and service notifications.
Subscription status & plan tierTo grant access to paid features. Payment card details are handled by Stripe — we never see or store your full card number.
The agent teams you configureAgent names, templates, schedules, notify targets, and which of your tools each agent connects to — the setup needed to run your team.
Operational activity your agents produceThe activity feed that powers your dashboards — e.g. alert and ticket summaries, what an agent triaged, routed, or notified. This is operational metadata, not your underlying sensitive records or PHI.
Encrypted references to the credentials you connect (BYOK)So your agents can run on your own model and tool keys. Keys are stored encrypted in a vault, not in our application database — see below and our Security page.
Operational logsSecurity and reliability. Logs are scrubbed of secrets — your credentials are never written to a log.

Your credentials (BYOK)

The API keys you connect are the most sensitive thing you entrust to us, and we treat them that way. They are stored encrypted in Azure Key Vault, server-side only. A key is decrypted transiently in server memory solely to let your agents operate on your behalf, and is never returned to your browser, never logged, and never shared with any third party or other customer. Our application database holds only a pointer to the vaulted secret plus the last four characters for display. Full details are on our Security & key-custody page.

How we use data

We use your data only to operate Cortya for you: to authenticate you, to run and improve the agent teams you configure, to bill your subscription, and to keep the service secure and reliable. Cortya does not access your PHI or other sensitive data or systems — your agents act on your own keys, and only non-sensitive operational metadata reaches us. We do not sell your data, we do not use it to train models, and we do not use one customer's data to serve another.

Sub-processors

We rely on the following processors to run the service. Each receives only the data needed for its function:

Retention, deletion, and revocation

You can remove or rotate the credentials you've connected at any time from your account; removal immediately stops all further access and deletes the stored key material. On account closure we delete your account data and agent activity within a reasonable period, except where we must retain limited records to meet legal or accounting obligations. To request deletion or a copy of your data, contact us.

Security

We protect data with encryption in transit and at rest, tenant isolation, least-privilege access, and secrets kept out of source and logs. See our Security page for the key-custody model.

Changes

We may update this policy from time to time and will post the updated version here with a new date.

Contact

Privacy questions or data requests: hello@cortya.com.