Last updated: July 18, 2026

Privacy Policy

Who this applies to

This policy describes how Duct, Inc. ("Duct", "we") handles information when you create an account, use the dashboard or SDK, or operate a shell for your product. It also covers data we process on your behalf when your end users or agents interact with your shell — you are responsible for informing your users and obtaining any consents required by your jurisdiction.

Information we collect

Account information — when you sign up or request access, we collect your name, email address, company name, and related account metadata.

Authentication sessions — when you sign in to the dashboard we set an httpOnly session cookie (duct_session, up to 7 days) so you stay signed in until you log out or the session expires. Authorized /admin operators receive a separate httpOnly admin session cookie on the marketing site.

Shell configuration — manifests, action definitions, permission settings, API endpoint metadata, widget settings, agent access profile configuration, and shell-to-shell network settings you configure in the dashboard or push via the SDK.

Usage and audit data — session identifiers, timestamps, caller type (human, agent, or cross-shell), action invocations, modality and intent metadata, outcomes, latency, consent state, redacted message previews, extracted entities (with sensitive fields redacted), LLM token usage counts, and cross-shell chain IDs when shell-to-shell is enabled.

Session data — during an active shell session, we temporarily store conversation context needed to route requests, enforce consent, and resume the session. This data is tied to short-lived session tokens and expires when the session ends or times out.

Support and communications — information you send through the support page or email.

Information we do not collect

We do not store Secret Keys in plaintext after issuance.

We do not sell your data or use your company's data, your end users' session content, or your API responses to train AI models.

We do not retain full message transcripts beyond what is needed for the active session and the redacted operational records described above.

How we use information

We use account and configuration data to provision shells, issue credentials, operate the dashboard, and send essential product communications. We do not use it for advertising.

We use usage and audit data to route requests, enforce permissions and consent, provide analytics in your dashboard, detect abuse, improve routing quality, and calculate billing where applicable.

Operational logs and audit telemetry are retained for platform operations. Partitioned interaction events are dropped after the retention window — currently 90 days by default. Longer retention may apply during security investigation, billing dispute, or legal obligation.

LLM processing

Duct uses large language models to classify intent, select actions, and synthesize responses. Prompts may be sent to third-party LLM providers using platform credentials or API keys you configure (bring-your-own-key). Providers process requests according to their own policies. We send only what is necessary for routing and response generation, and we redact known sensitive patterns from persisted previews and entity logs.

What we share

We do not sell personal information.

We share data with infrastructure providers (hosting, database, caching) solely to operate the service. These providers are bound by data processing agreements.

When an action is invoked, Duct sends the request to your configured API. When shell-to-shell is enabled and a user consents, limited metadata and delegation tokens are shared with the target shell to complete the cross-product call — both sides record an audit entry.

We may disclose information if required by law or to protect the security and integrity of the service.

Your rights

You can request access to, correction of, or deletion of your account data by contacting us through the support page. The dashboard includes an account-deletion control that removes your company profile, shells, and API keys; it does not yet purge all historical audit events, session backups, or infrastructure logs. Contact us for deletion requests that need fuller scope. If you are an end user of a product that embeds Duct, contact that product's operator first — they control the relationship with their users.

Security

We apply access controls, short-lived tokens, and redaction before persisting operational telemetry. For more detail on credentials, consent, and session handling, see our security page.

Changes

We may update this policy from time to time. We will notify account holders by email before material changes take effect. The "Last updated" date at the top reflects the most recent revision.

Contact

For privacy questions, use the support page.

See also: Terms of Service · Security · Cookies · Subprocessors