Home
Suites
PricingDocsLog inStart free
What this isData categoriesWhere data flowsController vs processorSub-processorsIsolation & tenancyExport & deletion controlsProduct-improvement signalsContact

On this page

What this isData categoriesWhere data flowsController vs processorSub-processorsIsolation & tenancyExport & deletion controlsProduct-improvement signalsContact

Legal & trust

Privacy PolicyTerms of ServiceHow Estelle improves
Estelle/data

Data Collection & Processing

Effective date: July 15, 2026

A developer-facing companion to the Privacy Policy: precisely what Estelle collects, where each piece flows, which sub-processors touch it, and the concrete controls to get it out or delete it. If you only read one privacy document, read the policy; if you want the data map, this is it.

What this is

This notice describes the actual data flow through Estelle so a security reviewer or a privacy-conscious developer can evaluate it quickly. It is consistent with, and subordinate to, the Privacy Policy.

Data categories

Estelle handles five categories of data. Nothing else is collected.

identity
Email and auth identifiers, for sign-in and account ownership.
credentials
Your BYOK model-provider key, encrypted app-side before storage. Stored as ciphertext; never returned or shared.
content
Code and content you ingest, and the derived index, embeddings, and facts Estelle builds from it, all under your namespace.
usage
Metadata about how you use Estelle: capabilities called, request and memory-token counts, error rates, latency. Not the content itself.
billing
Plan, subscription state, and invoices, via Stripe. Card data lives with Stripe, not us.

Where data flows

The path a request takes:

  • Your agent or tool calls Estelle over MCP or the OpenAI-compatible API at api.fatelabs.ca/v1 with your account key.
  • Estelle retrieves the grounded slice of your namespace, then calls your model provider using your decrypted provider key, for that request only.
  • The model's response passes back through Estelle's grounding and verification, and the cited answer returns to you.
  • Derived memory is written back under your namespace so recall works next session. Usage metadata is recorded for metering.

Note. The prompts and code sent onward to your model provider are governed by that provider's data terms. Estelle transmits them to reach the model you chose; it never adds itself, or anyone else, as a recipient for training.

In transit, all traffic to and from Estelle is served over TLS. At rest, your data lives in our providers' encrypted storage, and your BYOK provider key is additionally encrypted by Estelle before it is written to the database, so the database only ever holds ciphertext.

Controller vs processor

For your account and billing data, Fate Labs acts as a data controller. For the code and content you ingest and the memory derived from it, Fate Labs acts as a data processor, processing it on your instructions to provide the service, and you are the controller of that content. Enterprise customers who need this allocation captured in a signed Data Processing Addendum can request one at khai@fatelabs.ca.

Sub-processors

These are the third parties that process data on our behalf, as integrated in the product today. We maintain a dated list and give notice of additions (for example, by email or an in-product notice) before a new sub-processor begins handling your data.

Supabase
Auth + primary Postgres (identity, usage, encrypted credentials, derived content).
Railway
Backend hosting / compute.
Vercel
Web app + site hosting and delivery.
Stripe
Billing and payments (holds card data).
Voyage AI
Embeddings for indexing and retrieval of your memory.
OpenRouter
Optional model routing, only when selected as your provider path.
Resend
Transactional email.

Your chosen model provider is not our sub-processor: it is reached with your key under your agreement with them. Our sub-processors process data primarily in the United States; if you require specific processing regions or transfer safeguards, contact khai@fatelabs.ca.

Isolation & tenancy

Every customer has a dedicated namespace. Stored queries append the tenant predicate at the database layer, so a query physically cannot span tenants by accident, and recall for your team only reads your namespace. This is the structural basis for the isolation guarantee in the Privacy Policy.

Export & deletion controls

The controls below are real product capabilities, not manual promises:

export
Export the stored memory and facts for a namespace, so your data is portable.
remove source
Right-to-be-forgotten: drop a single source from every fact's lineage; facts left with no other support are removed entirely.
clear file
Remove all of a file's chunks from the index (used automatically when a changed file is re-indexed, and available on request).
delete namespace
Clear an entire namespace; closing your account deletes your namespaces.

Use the dashboard, or email khai@fatelabs.ca. When you delete a source or a namespace, it is removed from active storage promptly; residual copies in encrypted backups age out on our standard 30-day rotation.

Product-improvement signals

The only data used to improve Estelle for everyone is aggregated, anonymized usage metadata (which capabilities are used, error rates, latency, feature demand), plus public market research. Your code content is never in that set. Opt out anytime; see How Estelle improves itself for the full, honest account.

Contact

Data questions and security reviews: khai@fatelabs.ca. We will share the current sub-processor list and answer security-review questions on request.

Need a data map for procurement?

Email khai@fatelabs.ca and we will share the current sub-processor list, answer security-review questions, and provide a signed Data Processing Addendum on request.

Read the docsContact us

Estelleby Fate Labs

Product

SuitesPricingDocs

Legal & trust

PrivacyTermsData & processingHow Estelle improves

Contact

khai@fatelabs.ca

© 2026 Honour Systems Inc., doing business as Fate Labs.