Privacy Policy

What Squiid collects when you route your project through one key, why we have it, how long we keep it and how to get it back or get rid of it.

Last updated: September 19, 2026 · Automate HQ Inc., 50 Alberigi Drive, Jessup, PA 18434, United States

1. Who we are and what this covers

Automate HQ Inc., 50 Alberigi Drive, Jessup, PA 18434, United States, operates squiid.io and the Squiid platform. Squiid is a product of Automate HQ Inc., the company that also operates riivet.ai and restitute.ai. This policy explains how we handle personal data when you visit the website, create an account, buy credits, and route traffic through our gateway to third-party providers.

There are two different roles to keep separate:

  • We are the controller of personal data about our customers and visitors: your account, your billing details, your usage metadata, your support tickets, the security logs that protect your account. This policy covers that.
  • We are a processor (a "service provider" under California law) for personal data that you or your agents push through the gateway inside requests to providers. You decide what that data is and why it is sent. Our obligations there are set by the Data Processing Addendum, not by this policy.

Providers you connect (Supabase, Twilio, Anthropic and the rest) are independent controllers of the data you send them under their own policies. Squiid does not control what they do with it.

2. What we collect

CategoryExamplesWhere it comes from
Account dataName, email address, password hash, organisation name, seat role, two-factor status, verified email for sign-in codesYou
Billing dataBilling address, country, tax ID or VAT number, plan, invoice history, credit purchases, balance, partial card details (brand, last four, expiry) and the Stripe customer IDYou and Stripe. We never see or store a full card number.
Usage metadataPer-request timestamp, connected service, endpoint or model, HTTP status, latency, token or unit counts, computed cost, which key was used, and the agent identifier: the audit trail behind your dashboard and invoiceGenerated by the gateway
Request contentRequest and response bodies. Not retained by default. Captured only if you switch on debug capture for a key, or briefly where needed to deliver a call, investigate abuse or meet a legal obligationYour code and your agents
Credentials held in custodyProvider API keys and tokens we issue or you connect, encrypted at rest and never shown in full againProviders and you
Support and communicationsEmails, support tickets, attachments you send, and our repliesYou
Security and device dataIP address, user agent, sign-in times and locations, rate-limit and anti-abuse signals, 2FA code delivery recordsAutomatically
Website dataConsent choice stored in your browser, an unsent signup draft stored in your tab, and (only after you opt in) aggregate analytics about pages viewedYour browser. See the Cookie Policy.

We do not intentionally collect special-category data (health, biometrics, race, religion, sexual orientation, trade-union membership) about our customers, and we ask you not to put it in a support ticket. What you route through the gateway to a provider is your decision and is governed by the DPA.

3. Why we use it, and our legal basis

PurposeData usedLegal basis (GDPR Art. 6)
Create and run your account, authenticate you, deliver 2FA codesAccount, securityContract
Route requests to providers and hold the credentials that make that possibleCredentials, usage metadataContract
Meter usage, take payment, apply tax, issue invoices and refundsBilling, usage metadataContract; legal obligation for tax records
Show you your dashboard, audit trail and spendUsage metadataContract
Send service email: balance warnings, expiry warnings, invoices, incident and change noticesAccount, billingContract
Prevent fraud and abuse, enforce spend caps, protect the platform and providersSecurity, usage metadataLegitimate interests; legal obligation
Support you when something breaksSupport, usage metadata, debug capture if enabledContract; legitimate interests
Improve and secure the platform using aggregated, de-identified statisticsUsage metadataLegitimate interests
Optional product analytics on the websiteWebsite dataConsent
Marketing email about SquiidAccountConsent, or legitimate interests for existing customers with an unsubscribe link in every message
Comply with law, respond to lawful requests, establish or defend legal claimsAny of the aboveLegal obligation; legitimate interests

We do not sell personal data, we do not share it for cross-context behavioural advertising, and we do not use your prompts, payloads or responses to train AI models. Where we rely on legitimate interests, we have balanced them against your rights; ask privacy@squiid.io for the assessment.

4. What we see when your agents call a provider

Because your traffic passes through our gateway, we handle it in transit. What we keep is deliberately narrow: by default, metadata only. That metadata is what lets us show you which agent spent what, where, and when, and it is what your invoice is built from.

Request and response bodies are not stored by default. If you turn on debug capture for a key, bodies are stored for the retention window you pick (up to 30 days) so you can inspect them, and you are responsible for the personal data that capture contains: turn it off for keys handling sensitive traffic.

Provider credentials are encrypted at rest with a managed key-management service and decrypted only in the moment a request is signed. Staff do not have routine access; emergency access is restricted, approved and logged.

5. Who we share data with

  • Providers you connect. We forward your requests, with your credential attached, to the provider you addressed. Nothing goes to a provider you have not enabled.
  • Subprocessors and vendors that run the platform: Stripe (payments and tax), Resend (transactional email), Cloudflare (network, security, storage), Vercel (hosting) and Supabase (application database). The current list, with roles and locations, is in the DPA.
  • Professional advisers (auditors, accountants and lawyers) under confidentiality.
  • Authorities, where we are legally required to disclose. We review each request, push back on overbroad ones, and notify you unless legally prohibited.
  • A successor, in a merger, acquisition or sale of assets. We will tell you before your data moves to a different controller, and this policy continues to apply until you are given notice of a new one.

6. International transfers

Squiid is operated from the United States, and our infrastructure vendors run global networks. If you are in the EEA, the UK or Switzerland, your personal data will be transferred to, and processed in, the United States and other countries whose laws may differ from your own.

For those transfers we rely on the European Commission's Standard Contractual Clauses (Module Two, controller-to-processor, or Module Three where onward transfers apply), together with the UK International Data Transfer Addendum and the Swiss amendments, plus supplementary measures: encryption in transit and at rest, minimisation to metadata, access controls, and a policy of challenging unlawful government access requests. Where a vendor is certified under the EU–US Data Privacy Framework we may rely on that instead.

You can request a copy of the relevant transfer mechanism, with commercial terms redacted, from privacy@squiid.io. Providers you choose to connect may process data in regions they control: check the region settings on each service page before you route regulated data.

7. How long we keep things

DataRetention
Account dataFor the life of the account, then 30 days, after which it is deleted or anonymised
Invoices, receipts and tax records7 years, as required by tax and accounting law
Usage metadata / audit trail13 months rolling, then aggregated into de-identified statistics
Request and response bodiesNot retained by default; up to 30 days if you enable debug capture
Provider credentialsUntil you disconnect the service or close the account, then deleted and revoked
Security and sign-in logs12 months
Support correspondence24 months after the ticket closes
Marketing consent and suppression recordsUntil withdrawn, plus a permanent suppression entry so we do not email you again
Website analytics (only if you consented)14 months

We may keep data longer where needed to resolve a dispute, enforce our agreements or comply with a legal hold.

8. Security

We use TLS for data in transit and AES-256 for data at rest; credentials get an additional layer of envelope encryption with a managed key-management service. Access to production is role-based, requires multi-factor authentication, and is logged. Passwords are hashed with a modern memory-hard algorithm. We run dependency scanning, keep audit logs, separate environments, and review access regularly.

No system is perfectly secure. Protect your side too: keep your account email secure, keep your Squiid key secret, scope keys to only the services an agent needs, and set spend caps. If we become aware of a breach affecting your personal data we will notify you and the relevant supervisory authority as required by law: see the DPA for the timelines that apply when we act as your processor. Report a vulnerability to security@squiid.io.

9. Your rights (GDPR / UK GDPR)

If you are in the EEA, the UK or Switzerland you have the right to:

  • Access: get a copy of the personal data we hold about you.
  • Rectification: have inaccurate data corrected; most of it you can edit yourself in the dashboard.
  • Erasure: have data deleted where we no longer need it, subject to our legal retention duties (we cannot delete an issued invoice).
  • Restriction: have processing paused while a dispute about accuracy or legitimate interests is resolved.
  • Portability: receive the data you gave us in a structured, machine-readable format, or have it sent to another controller.
  • Object: object to processing based on legitimate interests, and to direct marketing at any time, with no reason needed.
  • Withdraw consent: at any time, without affecting processing already carried out.
  • Not be subject to a decision based solely on automated processing that produces a legal or similarly significant effect. We do not make such decisions; automated spend caps and abuse limits pause traffic, they do not profile you.
  • Complain to your supervisory authority. We would appreciate the chance to fix it first.

10. Your rights (California and other US states)

Under the CCPA as amended by the CPRA, and comparable laws in Virginia, Colorado, Connecticut, Utah, Texas and other states, you may have the right to know what we collect and why, to access a copy, to correct inaccuracies, to delete, to opt out of sale/sharing and of targeted advertising, to limit the use of sensitive personal information, and not to be discriminated against for exercising any of these rights.

We have not sold personal information or shared it for cross-context behavioural advertising in the preceding 12 months, and we do not do so now. We do not knowingly sell or share the personal information of anyone under 16. We do not use or disclose sensitive personal information for purposes beyond those permitted without a right to limit.

In the preceding 12 months we collected the categories described in "What we collect" (identifiers, commercial information, internet activity, and, where you enable debug capture, whatever your traffic contains) for the business purposes in "Why we use it", and disclosed them for business purposes to the vendors listed in the DPA.

You may use an authorised agent, with written permission we can verify. We honour Global Privacy Control signals as an opt-out for the browser that sends them.

11. How to make a request

Email privacy@squiid.io with the subject "Data Request", or use the privacy controls in your dashboard. Tell us which right you are exercising and, if you are acting for someone else, include proof of authority.

  1. Verification. We verify you against the account: usually by confirming control of the account email and, where the request is sensitive, a second factor. We ask only for what we need to verify, and we do not create a new account to do it.
  2. Acknowledgement within 10 days.
  3. Response within 30 days (GDPR) or 45 days (US state laws). Complex requests can be extended once by a further 60 days (GDPR: two months); we will tell you why.
  4. Cost. Free, unless a request is manifestly unfounded or repetitive, in which case we may charge a reasonable fee or decline and explain why.
  5. Appeal. If we refuse, you may appeal by replying to our decision. We respond to appeals within 45 days and will tell you how to contact your regulator.

If your request concerns data you routed through the gateway on behalf of your own users, you are the controller: send that request to us under the DPA and we will help you answer it.

12. Children

Squiid is a developer tool for businesses and professionals. It is not directed to children, and we do not knowingly collect personal data from anyone under 16. If you believe a child under 16 has given us personal data, email privacy@squiid.io and we will delete it promptly.

If your own product serves children, that is your responsibility as controller: check each provider's rules and applicable law (COPPA, the UK Age Appropriate Design Code, GDPR Art. 8) before routing that traffic through Squiid.

13. Cookies and browser storage

This site keeps a consent record in your browser, stores an unsent signup draft in your tab so a refresh does not lose your work, and loads optional analytics only after you agree. Stripe sets its own cookies on the checkout page for fraud prevention. The full list, and the switch to change your mind, is in the Cookie Policy.

14. Changes to this policy

We will post an updated version here with a new "last updated" date. For material changes we give at least 30 days' notice by email and in the dashboard, and where the law requires consent for the change, we will ask for it rather than assume it.

15. Contact

Privacy questions and data requests: privacy@squiid.io. Everything else legal: legal@squiid.io.

Automate HQ Inc.
50 Alberigi Drive, Jessup, PA 18434, United States

Our EU and UK representatives under GDPR Art. 27, where appointed, will be listed here. Data protection officer: not appointed; privacy requests are handled by the team at the address above.


This document is a template prepared for the Squiid product and has not been reviewed by counsel. Questions: legal@squiid.io.