Last updated: April 9, 2026
Privacy Policy
This policy explains how WYRE AI, LLC ("WYRE", "we", "us") collects, uses, and protects your information when you use Conduit.
1. Information We Collect
Account information: When you sign in via Microsoft Entra ID or Auth0, we receive your email address, display name, and organization identifier. We do not receive or store your Microsoft or identity provider password.
Vendor API credentials: You provide API keys, tokens, or other credentials for the third-party tools you connect. These are encrypted at rest with AES-256 and stored in our database.
Usage data: We log which tools are called, timestamps, and response metadata for audit and debugging. Request logs are retained for up to 90 days. We do not log the full content of API responses from your vendor tools.
Organization data: If you create or join a team, we store the organization name, membership list, role assignments, and team structure.
2. How We Use Your Information
- Authentication: Verify your identity and manage access
- Proxying: Inject your vendor credentials into API requests on your behalf
- Audit logging: Provide your organization with a record of tool usage
- Billing: Process payments when paid plans are introduced (via Stripe)
- Communication: Send transactional emails (invitations, welcome, security notices) via Resend
- Improvement: Understand usage patterns to improve the service (aggregated, not individual)
3. Data Storage and Security
- Hosted on Microsoft Azure (East US 2 region)
- Vendor credentials encrypted at rest with AES-256 using a hardware-secured master key
- All connections encrypted in transit with TLS 1.2+
- Database access restricted to the gateway application via network-level controls
- No vendor data is cached or stored beyond the duration of a proxied request
4. Third-Party Services
We use the following third-party services:
- Microsoft Entra ID / Auth0: User authentication
- Stripe: Payment processing (when paid plans are active)
- Resend: Transactional email delivery
- Azure Container Apps: Application hosting
- Azure Database for PostgreSQL: Data storage
Each of these services has its own privacy policy. We only share the minimum information necessary for each service to function. The complete, current list of our subprocessors is maintained at /subprocessors.
5. Data Retention
- Vendor credentials: Stored until you delete them or your account is terminated
- Audit logs: Retained for 90 days, then automatically deleted
- Request logs: Retained for 90 days, then automatically deleted
- Account information: Retained while your account is active; deleted upon request
6. Your Rights
You can:
- Access your stored data via the gateway dashboard and API
- Correct your information by updating your profile or credentials
- Delete your vendor credentials, organization, or entire account at any time
- Export your data via the gateway API
To exercise any of these rights, use the gateway dashboard or contact privacy@wyretechnology.com.
7. Cookies, Local Storage, and Analytics
Conduit uses:
- Session cookie (
gateway_session): Signed, HTTP-only cookie for authentication. Remains valid while you are active for up to 30 days from sign-in; expires after 7 days of inactivity or when you log out. - Theme preference (
gateway-theme): Stored in localStorage to remember your light/dark mode choice. Not transmitted to our servers. - Retro theme flag (
gateway-retro): Stored in localStorage only if you switch on the optional retro visual theme; removed when you switch it off. Not transmitted to our servers.
Product analytics. We use PostHog, a first-party product-analytics service, to understand how the product is used and to improve it (for example, which onboarding steps people complete). PostHog is configured cookieless — it sets no cookies and no persistent local storage on your device; an anonymous identifier exists only in memory for the duration of a page session. For signed-in users we associate usage events with your account and organization so we can measure activation and support you. We do not use advertising cookies, third-party ad pixels, or sell your data. PostHog is listed on our Subprocessors page.
8. Children's Privacy
Conduit is not directed at children under 13. We do not knowingly collect information from children. If you believe a child has provided us with personal information, contact us at privacy@wyretechnology.com.
9. International Data Transfers
Conduit is hosted in the United States. If you access the service from outside the US, your information will be transferred to and processed in the US. By using the service, you consent to this transfer.
10. Changes to This Policy
We may update this privacy policy from time to time. When we make material changes, we will notify you via email or a notice within the service. The "Last updated" date at the top reflects the most recent revision.
11. Contact
WYRE AI, LLC
Chattanooga, TN
privacy@wyretechnology.com