Skip to the content
How it worksOne engineerAgenciesSecurityPricing
EN | ES
Book a call
Menu
How it worksOne engineerAgenciesSecurityPricing
Book a call
EN | ES

Privacy policy

Effective 4 October 2026

This policy says what personal data Ingot handles, why, who else sees it, how long we keep it and what you can do about it.

1. Who we are

Cloud Wise Consulting LLC, 1021 E Lincolnway, Suite #6259, Cheyenne, WY 82001, USA ("Ingot", "we"), runs this website and the Ingot service. Write to us at contact@ingot.run.

We play two roles. For our website, our email list, our customers' accounts and billing, we decide how personal data is used: we are the controller. For personal data inside the systems a customer connects, the customer decides, and we process it on their behalf: we are the processor. Our terms and any data processing agreement govern that second role. If your data sits in a customer's systems, please contact that customer first.

2. What we collect and why

  • Account data: name, email address, role, workspace membership and sign-in details (passkeys, Google sign-in, or a password we keep only as a salted hash). We use it to give you access and keep your account safe.
  • Workspace data: the sites, cloud projects, repositories and settings you connect, and the keys you add, which we keep encrypted. We use it to run the service.
  • Run data: what the agents read and produce while they work: logs, metrics, check results, code, findings, tickets, proposed changes and transcripts. It can include personal data that sits in the customer's systems. We use it only to run the service for that customer.
  • Billing data: the name, email, business details and address you give Stripe, your plan and your invoices. Stripe handles your card; we never see the full number. We use it to bill you and to meet tax and accounting law.
  • Email list: your email and, if you add them, your company, the plan you looked at, the language of the form you used, and the time you joined. We send one email to confirm at once, in that language, then write only when there is news. To leave the list, use the unsubscribe link in our email, or your mail app's unsubscribe button; we delete your entry at once. You can also write to us. To limit abuse, we count sign-ups by a hash of your IP address and delete that count, normally within a day.
  • Messages: what you send us by email, and our replies. We use them to answer you.
  • Call bookings: when you book a call, your name, email, company, any notes you add, and the emails of any guests you invite. We use them to hold the call and prepare for it.
  • Technical data: when you send the email-list form, Google Cloud logs your IP address, browser and the time, for 30 days. The log never holds your email. The console keeps a record of sign-ins and of changes in each workspace, for security.

Cookies. This website sets no cookies and loads no analytics or ads. The console sets one cookie that keeps you signed in; it is needed for the service to work. The site's language switch stores your choice only in your browser. "Book a call" takes you to Cal.com's own site, which sets its own cookies under its own policy.

Legal bases. Where the EU or UK GDPR applies, we rely on: the contract with you, for accounts, workspaces and billing; your consent, for the email list (withdraw it at any time); steps you ask us to take before a contract, for booked calls; our legitimate interests in keeping the service secure and answering messages; and legal duties, for tax records.

We do not sell personal data, share it for targeted ads, or use customer data to train AI models. We make no decision about you by automated means alone that has legal or similar effects.

3. Who processes it for us

  • Google Cloud (Google LLC) hosts the website, the service and its data, and the email list. For a booked call, Google Calendar holds the event and Google Meet runs the call.
  • Anthropic (Anthropic, PBC) runs the AI models. It receives what the agents read and write, so that they can work. If you use your own API key for a model by agreement, your provider receives it under your account instead.
  • Stripe (Stripe, Inc.) takes payments, holds billing details and hosts the billing page.
  • Cal.com (Cal.com, Inc.) runs the booking page for calls and receives what you enter there.
  • Mailgun (Mailgun Technologies, Inc.) sends our emails, and tells us of each new email-list sign-up.
  • GitHub, Slack and Atlassian (Jira) receive what the service sends to the accounts you connect: pull requests, tickets, alerts and summaries.

Each processes data only to provide its service to us or to you. We will list any new company here and email account owners before it starts. We may also disclose data when the law requires it, to protect rights and safety, or to a buyer of the business, who must keep this policy.

4. Transfers abroad

We are based in the United States, and we store and process data there. The email list sits in Google Cloud's us-central1 region. Our processors may handle data in other countries. When we move personal data from the EU, the UK or Switzerland to the United States, we rely on the standard contractual clauses approved for that purpose, in our data processing agreement and in our processors' terms.

5. How long we keep it

  • Run data: 30 days, unless the customer sets another period.
  • Account and workspace data: while the account is open, and up to 30 days after a plan ends, so that the customer can ask for an export. Then we delete it.
  • Billing records: as long as tax and accounting law requires, normally 7 years.
  • Email list: until you unsubscribe or ask us to delete it. Otherwise we delete it automatically 24 months after you join, normally within a day after that date.
  • Technical logs: 30 days. The IP count for the email list: normally a day.
  • Messages and call bookings: as long as we need them to answer you and keep a record of our dealings, normally up to 3 years.

6. Security

We protect data with access limits, encryption and the measures on our security page. Agents that watch read customers' systems with read-only access. Ingot holds deploy access only where a customer grants it. Each customer has its own runner and cloud identity. No system is perfectly secure. If a breach affects your data, we will tell you as the law requires. Report security problems to security@ingot.run.

7. Your rights

Depending on where you live, you may have the right to see the personal data we hold about you, correct it, delete it, receive a copy to take elsewhere, limit or object to how we use it, and withdraw consent. To use any of these rights, write to contact@ingot.run. We may ask you to prove who you are. We answer within one month, or sooner if the law requires. We will not treat you worse for using your rights.

If the data is in a customer's systems, we pass your request to that customer and help them answer it. If you are in the EU or the UK, you may also complain to your data protection authority.

Ingot is for businesses, and not for anyone under 18. We do not knowingly collect children's data.

8. Changes

We will post changes here and update the date at the top. For a material change, we email account owners before it takes effect.

We may offer this policy in other languages as a courtesy. If a translation differs from the English text, the English text prevails.

9. Contact

Cloud Wise Consulting LLC, 1021 E Lincolnway, Suite #6259, Cheyenne, WY 82001, USA. Email: contact@ingot.run.

Agents that watch production and fix what breaks.

EN | ES

Product

How it worksFor one engineerFor agenciesStart with WatchPricingSecurity

Company

About IngotContactTermsPrivacyBilling

© 2026 Ingot. Ingot is a product of Cloud Wise Consulting LLC.