Home
Suites
PricingDocsLog inStart free
The short versionWho this coversWhat we collectHow we use itWhat we never doThird-party processorsHow long we keep itYour rights & controlsHow we protect itInternational transfersChildrenChangesContact

On this page

The short versionWho this coversWhat we collectHow we use itWhat we never doThird-party processorsHow long we keep itYour rights & controlsHow we protect itInternational transfersChildrenChangesContact

Legal & trust

Terms of ServiceData & processingHow Estelle improves
Estelle/privacy

Privacy Policy

Effective date: July 15, 2026

Estelle gives your coding agent a grounded memory of your codebase. That job only works if your code stays yours. This policy explains what Fate Labs collects, what we do with it, and, just as important, what we structurally cannot and will not do. For the mechanics of the data flow, see the Data & Processing notice; for the honest account of how the product improves, see How Estelle improves itself.

The short version

These three commitments are the reason to trust Estelle with a codebase. They are not marketing: they follow from how the product is built (bring your own model and key, per-tenant isolation, a gate that treats your code as ground truth).

Your code and memory are isolated to your namespace.

Every team's codebase, memory, and derived facts live under a dedicated namespace, and every stored query is scoped to that namespace at the database layer. We do not co-mingle one customer's data with another's, and Estelle's recall for your team only ever reads your namespace.

We do not train on, or mine, your code content.

Because you bring your own model and key, your code goes to your model provider under your terms, so Estelle structurally cannot use your code content to train a model. We also do not read your code to build features or improve the product for anyone else. Estelle's memory and grounding operate on your code for you, and only for you.

We improve Estelle from usage metadata, not your content.

Estelle gets better from how the product is used, aggregated and anonymized signals like which capabilities are called, error rates, and latency, plus public market research. It does not learn from the private contents of your repositories. You can opt out of product-improvement analytics at any time.

Note. The rest of this document is the standard, detailed version. If anything below appears to contradict the three commitments above, the commitments govern, and please tell us so we can fix the text.

Who this covers

“Estelle” is the service operated by Honour Systems Inc. (incorporated in Ontario, Canada), doing business as Fate Labs (“we”, “us”). This policy applies to the Estelle web app, dashboard, the API at api.fatelabs.ca, the hosted MCP server, and the CLI. It covers people who create an account, and the teammates they invite. It does not change the terms under which your own model provider (the one whose key you bring) handles the prompts and code you send them; that relationship is directly between you and that provider.

You can reach us about anything in this policy at khai@fatelabs.ca.

What we collect

We collect the minimum needed to run accounts, bill capacity, and keep the service reliable. In plain terms:

Account data
Your email and authentication identifiers, managed through our auth provider. If you sign in with a third party (for example Google), we receive your email and a stable account id, not your password.
Provider keys (BYOK)
The API key or token for your own model provider, so Estelle can call the model on your behalf. It is encrypted before it reaches our database (see How we protect it) and is never shown back to you or shared.
Usage metadata
Which capabilities you call, request counts, memory-tokens held, error rates, and latency, tied to your account for metering and reliability. This is metadata about your usage, not the content of your repositories.
Derived memory
The index, embeddings, and structured facts Estelle builds from the code and content you ingest, stored under your namespace so recall works across sessions. This is processed on your behalf; see What we never do.
Billing data
Plan, subscription status, and invoices, handled by our payments processor (Stripe). We do not store full card numbers; Stripe does.
Operational logs
Request logs, IP address, and diagnostic events needed for security, abuse prevention, and debugging, retained for a limited window.

We do not sell personal data, and we do not run third-party advertising trackers on the product surfaces.

How we use it

We use the data above only for these purposes:

  • To run the service: authenticate you, build and serve your grounded memory, call your model with your key, and return cited answers.
  • To meter and bill: measure capacity and usage against your plan, and process payments for paid tiers.
  • To keep it reliable and secure: monitor errors and latency, prevent abuse, and debug incidents.
  • To improve the product from usage metadata: understand which capabilities are used, where the product errors, and what to build next, using aggregated, anonymized signals and public research. See How Estelle improves itself, and opt out under Your rights & controls.
  • To communicate with you: transactional email (sign-in, receipts, security notices) through our email provider. Product email is opt-out.

We process this data to provide the service you asked for, to meet our legal and tax obligations, and, where the law requires it, with your consent. We do not sell your personal data.

What we never do

This section states the guarantees from the summary as concrete negatives, so there is no ambiguity:

  • We do not use the content of your repositories to train, fine-tune, or evaluate any model, ours or anyone else's.
  • We do not use your code content to build features or improve the product experienced by other customers.
  • We do not co-mingle your namespace with another tenant's, and we do not let one customer's recall read another's data.
  • We do not sell, rent, or trade your personal data or your code.
  • We do not mark up your model tokens or route your model traffic anywhere except to the provider whose key you supplied.

Important. Because Estelle is bring-your-own-key, the raw prompts and code your agent sends to your model provider are governed by their privacy terms, not ours. Choose a provider whose data policy you are comfortable with; Estelle never adds itself as a training recipient of that traffic.

Third-party processors

We use a small set of vetted infrastructure providers (sub-processors) to run Estelle. Each receives only the data it needs for its function. This list reflects the services actually integrated in the product today; the authoritative, dated list lives in the Data & Processing notice.

Supabase
Authentication and the primary Postgres database (accounts, metadata, encrypted keys, derived memory).
Railway
Backend application hosting and compute for the API and workers.
Vercel
Hosting and delivery of the web app and marketing site.
Stripe
Subscription billing and payment processing. Stripe stores card data; we do not.
Voyage AI
Embeddings used to index and retrieve your memory. Per Voyage's terms, it does not train on customer content.
OpenRouter
Optional model routing when you choose it as your provider path. Your key, your model; used only to reach the model you selected.
Resend
Transactional email delivery (sign-in links, receipts, security notices).

Your own model provider (Anthropic, OpenAI, Moonshot / Kimi, Google, DeepSeek, or any OpenAI-compatible endpoint) is reached with the key you provide and acts under your agreement with them, not ours. These providers process data primarily in the United States. Enterprise customers who need a signed Data Processing Addendum can request one at khai@fatelabs.ca.

How long we keep it

We keep data only as long as it is needed for the purpose it was collected:

  • Account and billing records: for as long as your account is active, and afterward for up to seven years as needed to meet tax, accounting, and legal obligations.
  • Derived memory and namespace data: until you delete it or close your account. Deleting a source or a namespace removes it from active storage promptly; residual copies in encrypted backups age out on our standard 30-day rotation.
  • Operational logs: retained for a limited diagnostic window of about 90 days, then deleted or anonymized.
  • Usage metadata used for product improvement: aggregated and anonymized; aggregate statistics may be retained indefinitely because they no longer identify you or your code.

Your rights & controls

You control your data. Estelle ships real mechanisms for each of these, not just a promise:

  • Access & export: export your namespace's stored memory and facts. Estelle exposes a per-namespace export so your data is portable, not locked in.
  • Correction: re-index a changed file to replace stale content, or update your account details in the dashboard.
  • Deletion (right to be forgotten): remove a single source from every fact that referenced it (a right-to-be-forgotten cascade), clear a file, or delete an entire namespace. Closing your account deletes your namespaces.
  • Opt out of product-improvement analytics: turn off the aggregated usage signals described in How Estelle improves itself. Metering needed to bill and to keep the service running continues, because it is required to provide the service.

To exercise any of these, use the dashboard controls or email khai@fatelabs.ca. We respond within a reasonable time and within any period required by applicable law.

Fate Labs is early-stage and does not currently offer region-specific privacy terms (such as EU/UK GDPR or California CCPA/CPRA disclosures); we will introduce them if and when we serve those regions. If a data-protection law that applies to you grants rights beyond those above, email us and we will honour what that law requires.

How we protect it

We follow established security best practices. Concretely, and verifiable in the product:

  • Your provider key is encrypted on our side before it is written to the database, so the database only ever stores ciphertext, never the raw key.
  • Data is scoped per namespace, and every stored query appends the tenant predicate at the data layer so it cannot be omitted by accident.
  • Access to production is limited, traffic is served over TLS, and secrets live in a secret manager, never in source.
  • The grounding gate treats your real code as the source of truth and refuses content injected into it, so memory cannot be poisoned into leaking or fabricating.

Note. We describe our practices honestly. We follow established security best practices, but no system is perfectly secure and we cannot guarantee absolute security. We do not currently claim any formal certification (for example SOC 2 or ISO 27001) or regulatory status (for example HIPAA, or PCI beyond Stripe's own scope). If and when we complete such a program, we will say so here with the report available.

If we ever become aware of a personal-data breach that affects you, we will notify affected customers and any regulators without undue delay, as required by applicable law, and describe what happened and the steps we are taking.

International transfers

Our infrastructure providers process data primarily in the United States. If you access Estelle from the EEA, the UK, or another region with cross-border transfer rules, using the service involves transferring your data to the United States, and we rely on appropriate safeguards for that transfer. If your organization requires a specific transfer mechanism (such as Standard Contractual Clauses) or a regional data-residency option, contact khai@fatelabs.ca.

Children

Estelle is a developer tool for professional use and is not directed to children. You must be at least 18 years old to use it. We do not knowingly collect personal data from anyone under 18; if we learn we have, we will delete it.

Changes to this policy

We may update this policy as the product and the law evolve. Material changes will be announced (for example, by email or an in-product notice), and the effective date at the top will change. Your continued use after a change takes effect means you accept the updated policy.

Contact

Privacy questions and data-rights requests: khai@fatelabs.ca. Estelle is operated by Honour Systems Inc. (incorporated in Ontario, Canada), doing business as Fate Labs.

Questions about your data?

Reach us at khai@fatelabs.ca. To exercise any right below, email us or use the export and delete controls in your dashboard.

Read the docsContact us

Estelleby Fate Labs

Product

SuitesPricingDocs

Legal & trust

PrivacyTermsData & processingHow Estelle improves

Contact

khai@fatelabs.ca

© 2026 Honour Systems Inc., doing business as Fate Labs.