1. Who we are and what this covers
Automate HQ Inc., 50 Alberigi Drive, Jessup, PA 18434, United States, operates squiid.io and the Squiid platform. Squiid is a product of Automate HQ Inc., the company that also operates riivet.ai and restitute.ai. This policy explains how we handle personal data when you visit the website, create an account, buy credits, and route traffic through our gateway to third-party providers.
There are two different roles to keep separate:
- We are the controller of personal data about our customers and visitors: your account, your billing details, your usage metadata, your support tickets, the security logs that protect your account. This policy covers that.
- We are a processor (a "service provider" under California law) for personal data that you or your agents push through the gateway inside requests to providers. You decide what that data is and why it is sent. Our obligations there are set by the Data Processing Addendum, not by this policy.
Providers you connect (Supabase, Twilio, Anthropic and the rest) are independent controllers of the data you send them under their own policies. Squiid does not control what they do with it.
2. What we collect
| Category | Examples | Where it comes from |
|---|---|---|
| Account data | Name, email address, password hash, organisation name, seat role, two-factor status, verified email for sign-in codes | You |
| Billing data | Billing address, country, tax ID or VAT number, plan, invoice history, credit purchases, balance, partial card details (brand, last four, expiry) and the Stripe customer ID | You and Stripe. We never see or store a full card number. |
| Usage metadata | Per-request timestamp, connected service, endpoint or model, HTTP status, latency, token or unit counts, computed cost, which key was used, and the agent identifier: the audit trail behind your dashboard and invoice | Generated by the gateway |
| Request content | Request and response bodies. Not retained by default. Captured only if you switch on debug capture for a key, or briefly where needed to deliver a call, investigate abuse or meet a legal obligation | Your code and your agents |
| Credentials held in custody | Provider API keys and tokens we issue or you connect, encrypted at rest and never shown in full again | Providers and you |
| Support and communications | Emails, support tickets, attachments you send, and our replies | You |
| Security and device data | IP address, user agent, sign-in times and locations, rate-limit and anti-abuse signals, 2FA code delivery records | Automatically |
| Website data | Consent choice stored in your browser, an unsent signup draft stored in your tab, and (only after you opt in) aggregate analytics about pages viewed | Your browser. See the Cookie Policy. |
We do not intentionally collect special-category data (health, biometrics, race, religion, sexual orientation, trade-union membership) about our customers, and we ask you not to put it in a support ticket. What you route through the gateway to a provider is your decision and is governed by the DPA.
3. Why we use it, and our legal basis
| Purpose | Data used | Legal basis (GDPR Art. 6) |
|---|---|---|
| Create and run your account, authenticate you, deliver 2FA codes | Account, security | Contract |
| Route requests to providers and hold the credentials that make that possible | Credentials, usage metadata | Contract |
| Meter usage, take payment, apply tax, issue invoices and refunds | Billing, usage metadata | Contract; legal obligation for tax records |
| Show you your dashboard, audit trail and spend | Usage metadata | Contract |
| Send service email: balance warnings, expiry warnings, invoices, incident and change notices | Account, billing | Contract |
| Prevent fraud and abuse, enforce spend caps, protect the platform and providers | Security, usage metadata | Legitimate interests; legal obligation |
| Support you when something breaks | Support, usage metadata, debug capture if enabled | Contract; legitimate interests |
| Improve and secure the platform using aggregated, de-identified statistics | Usage metadata | Legitimate interests |
| Optional product analytics on the website | Website data | Consent |
| Marketing email about Squiid | Account | Consent, or legitimate interests for existing customers with an unsubscribe link in every message |
| Comply with law, respond to lawful requests, establish or defend legal claims | Any of the above | Legal obligation; legitimate interests |
We do not sell personal data, we do not share it for cross-context behavioural advertising, and we do not use your prompts, payloads or responses to train AI models. Where we rely on legitimate interests, we have balanced them against your rights; ask privacy@squiid.io for the assessment.
4. What we see when your agents call a provider
Because your traffic passes through our gateway, we handle it in transit. What we keep is deliberately narrow: by default, metadata only. That metadata is what lets us show you which agent spent what, where, and when, and it is what your invoice is built from.
Request and response bodies are not stored by default. If you turn on debug capture for a key, bodies are stored for the retention window you pick (up to 30 days) so you can inspect them, and you are responsible for the personal data that capture contains: turn it off for keys handling sensitive traffic.
Provider credentials are encrypted at rest with a managed key-management service and decrypted only in the moment a request is signed. Staff do not have routine access; emergency access is restricted, approved and logged.
6. International transfers
Squiid is operated from the United States, and our infrastructure vendors run global networks. If you are in the EEA, the UK or Switzerland, your personal data will be transferred to, and processed in, the United States and other countries whose laws may differ from your own.
For those transfers we rely on the European Commission's Standard Contractual Clauses (Module Two, controller-to-processor, or Module Three where onward transfers apply), together with the UK International Data Transfer Addendum and the Swiss amendments, plus supplementary measures: encryption in transit and at rest, minimisation to metadata, access controls, and a policy of challenging unlawful government access requests. Where a vendor is certified under the EU–US Data Privacy Framework we may rely on that instead.
You can request a copy of the relevant transfer mechanism, with commercial terms redacted, from privacy@squiid.io. Providers you choose to connect may process data in regions they control: check the region settings on each service page before you route regulated data.
7. How long we keep things
| Data | Retention |
|---|---|
| Account data | For the life of the account, then 30 days, after which it is deleted or anonymised |
| Invoices, receipts and tax records | 7 years, as required by tax and accounting law |
| Usage metadata / audit trail | 13 months rolling, then aggregated into de-identified statistics |
| Request and response bodies | Not retained by default; up to 30 days if you enable debug capture |
| Provider credentials | Until you disconnect the service or close the account, then deleted and revoked |
| Security and sign-in logs | 12 months |
| Support correspondence | 24 months after the ticket closes |
| Marketing consent and suppression records | Until withdrawn, plus a permanent suppression entry so we do not email you again |
| Website analytics (only if you consented) | 14 months |
We may keep data longer where needed to resolve a dispute, enforce our agreements or comply with a legal hold.
8. Security
We use TLS for data in transit and AES-256 for data at rest; credentials get an additional layer of envelope encryption with a managed key-management service. Access to production is role-based, requires multi-factor authentication, and is logged. Passwords are hashed with a modern memory-hard algorithm. We run dependency scanning, keep audit logs, separate environments, and review access regularly.
No system is perfectly secure. Protect your side too: keep your account email secure, keep your Squiid key secret, scope keys to only the services an agent needs, and set spend caps. If we become aware of a breach affecting your personal data we will notify you and the relevant supervisory authority as required by law: see the DPA for the timelines that apply when we act as your processor. Report a vulnerability to security@squiid.io.
9. Your rights (GDPR / UK GDPR)
If you are in the EEA, the UK or Switzerland you have the right to:
- Access: get a copy of the personal data we hold about you.
- Rectification: have inaccurate data corrected; most of it you can edit yourself in the dashboard.
- Erasure: have data deleted where we no longer need it, subject to our legal retention duties (we cannot delete an issued invoice).
- Restriction: have processing paused while a dispute about accuracy or legitimate interests is resolved.
- Portability: receive the data you gave us in a structured, machine-readable format, or have it sent to another controller.
- Object: object to processing based on legitimate interests, and to direct marketing at any time, with no reason needed.
- Withdraw consent: at any time, without affecting processing already carried out.
- Not be subject to a decision based solely on automated processing that produces a legal or similarly significant effect. We do not make such decisions; automated spend caps and abuse limits pause traffic, they do not profile you.
- Complain to your supervisory authority. We would appreciate the chance to fix it first.
10. Your rights (California and other US states)
Under the CCPA as amended by the CPRA, and comparable laws in Virginia, Colorado, Connecticut, Utah, Texas and other states, you may have the right to know what we collect and why, to access a copy, to correct inaccuracies, to delete, to opt out of sale/sharing and of targeted advertising, to limit the use of sensitive personal information, and not to be discriminated against for exercising any of these rights.
We have not sold personal information or shared it for cross-context behavioural advertising in the preceding 12 months, and we do not do so now. We do not knowingly sell or share the personal information of anyone under 16. We do not use or disclose sensitive personal information for purposes beyond those permitted without a right to limit.
In the preceding 12 months we collected the categories described in "What we collect" (identifiers, commercial information, internet activity, and, where you enable debug capture, whatever your traffic contains) for the business purposes in "Why we use it", and disclosed them for business purposes to the vendors listed in the DPA.
You may use an authorised agent, with written permission we can verify. We honour Global Privacy Control signals as an opt-out for the browser that sends them.
11. How to make a request
Email privacy@squiid.io with the subject "Data Request", or use the privacy controls in your dashboard. Tell us which right you are exercising and, if you are acting for someone else, include proof of authority.
- Verification. We verify you against the account: usually by confirming control of the account email and, where the request is sensitive, a second factor. We ask only for what we need to verify, and we do not create a new account to do it.
- Acknowledgement within 10 days.
- Response within 30 days (GDPR) or 45 days (US state laws). Complex requests can be extended once by a further 60 days (GDPR: two months); we will tell you why.
- Cost. Free, unless a request is manifestly unfounded or repetitive, in which case we may charge a reasonable fee or decline and explain why.
- Appeal. If we refuse, you may appeal by replying to our decision. We respond to appeals within 45 days and will tell you how to contact your regulator.
If your request concerns data you routed through the gateway on behalf of your own users, you are the controller: send that request to us under the DPA and we will help you answer it.
12. Children
Squiid is a developer tool for businesses and professionals. It is not directed to children, and we do not knowingly collect personal data from anyone under 16. If you believe a child under 16 has given us personal data, email privacy@squiid.io and we will delete it promptly.
If your own product serves children, that is your responsibility as controller: check each provider's rules and applicable law (COPPA, the UK Age Appropriate Design Code, GDPR Art. 8) before routing that traffic through Squiid.
14. Changes to this policy
We will post an updated version here with a new "last updated" date. For material changes we give at least 30 days' notice by email and in the dashboard, and where the law requires consent for the change, we will ask for it rather than assume it.
15. Contact
Privacy questions and data requests: privacy@squiid.io. Everything else legal: legal@squiid.io.
Automate HQ Inc.
50 Alberigi Drive, Jessup, PA 18434, United States