Privacy Policy
Last updated 13 September 2026
Who we are
Your Cadre, Inc, a Delaware corporation (“YourCadre”, “we”, “us”) builds Cade, a platform that runs AI agents against the business systems our customers already use, to automate steps in their operational workflows.
This policy explains what information we handle, why, and what control you have over it. It covers yourcadre.ai and the Cade platform.
Questions, requests, or complaints: privacy@yourcadre.ai · 1717 N Street NW, Ste 1, Washington, DC 20036, USA
Data processing agreements: legal@yourcadre.ai · Security and vulnerability reports: security@yourcadre.ai
Who the data belongs to
Two distinct relationships, and the difference decides who controls what:
Our customers are businesses who engage us. They are the controller of the data in their own systems. We act as their processor: we handle it on their instructions, under a written agreement, to deliver the service they asked for.
You, as an individual — an employee of a customer, or a visitor to our site — may have information about you handled by us. Where that happens because your employer engaged us, your employer’s own privacy policy governs the relationship and we act on their instructions. Requests about that data are usually fastest through them, though you can always contact us directly.
What we handle
Account information. Names, work email addresses, and role for the people at a customer who use Cade.
Connected business systems. With a customer’s explicit authorization, Cade connects to the systems they nominate — which may include accounting, job management, file storage, calendar, phone, and photo platforms. What we read and write in each is limited to the scopes that customer grants and to the specific workflow steps they have asked Cade to perform.
Credentials. We never store a customer’s passwords. Access is by OAuth token or API key, held in a secrets manager and resolved at call time; credentials are not written into configuration, logs, or source code.
Operational records. Run traces, timings, errors, and the decisions Cade made — what we need to show a customer what their agents did, to debug, and to measure whether the work is correct.
Website usage. Four pages on yourcadre.ai — the home page, contact, what-we-automate and the FAQ — load Vercel Web Analytics, which records page views and approximate location derived from IP address. It sets no cookies and does not identify you or follow you across sites. We use no other analytics or tracking tools anywhere, and the Cade platform itself carries none.
Why we handle it
- To deliver the service the customer engaged us for: running their agents against their systems.
- To show the customer what happened, and to let a person review, approve, or correct an agent’s work.
- To measure and improve the accuracy of the specific agents deployed for that customer.
- To secure the service, investigate incidents, and prevent abuse.
- To meet legal and contractual obligations.
We do not sell personal information. We do not serve advertising, and we do not use customer data for advertising or to build advertising profiles.
Google Workspace data
This section governs data we access through Google APIs, and it controls over anything more general elsewhere in this policy.
What we access. Only where a customer explicitly authorizes it, and only the scopes they grant. Depending on the workflows a customer deploys, this may include Google Drive files and folders, Google Sheets content, Google Calendar events, and permission to send email on their behalf.
How we use it. Solely to provide and improve the specific, user-facing features the customer has asked for — for example, creating a job folder when a proposal is signed, writing a cost line onto a spreadsheet, or reading the timestamp on a calendar event to measure how long scheduling takes.
Limited Use. YourCadre’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- We do not transfer Google user data to third parties except as necessary to provide or improve the features above, to comply with applicable law, or as part of a merger or acquisition with the customer’s consent.
- We do not use Google user data for advertising of any kind.
- We do not use Google user data to develop, improve, or train generalized artificial intelligence or machine learning models.
- We do not allow humans to read Google user data unless we have the customer’s specific consent, it is necessary for security or to comply with law, or the data has been aggregated and anonymized for internal operations.
Diagnostics. When we need to investigate why an agent’s output was wrong, we work from a redacted or aggregated extract that carries no Google user data. Where a fault cannot be diagnosed without seeing the records themselves — because the identifying detail is the evidence — we ask the customer first, in writing, for that specific investigation, and the request and the answer are recorded.
Revoking access. A customer can withdraw our access at any time from their Google Account permissions page or, for a whole domain, from the Google Workspace admin console. Revocation takes effect immediately and stops all further access.
AI processing
Cade uses third-party large language models to perform the work customers deploy it for. Customer data is sent to those model providers only as needed to carry out that work.
We use model providers under commercial terms that do not permit training on our customers’ data, and we do not use customer data — Google Workspace data included — to develop or train generalized AI or machine learning models, our own or anyone else’s.
Every customer gets their own isolated deployment. There is no shared, multi-tenant installation of Cade in any configuration. A customer’s data is held in the cloud account dedicated to their deployment — by default an isolated account we provision and operate for them alone, and for customers who ask, an account of their own. We do not use one customer’s data to build, train, tune, or improve another customer’s agents, and no customer’s data is reachable from another customer’s deployment.
What does carry across customers is what we learn about our own platform — how to design an agent, where a workflow tends to break, which configurations hold up in production. That is engineering knowledge about our software, it contains no customer data, and improving the platform with it is how every customer gets a better product over time.
Who we share with
We share data with service providers who help us run the platform, each bound by contract to handle it only on our instructions:
| Provider | What for |
|---|---|
| Anthropic | Large language model inference |
| Amazon Web Services | Hosting, storage, secrets management |
| Supabase | Database for the engine, which holds record identifiers, labels and derived measurements — never the records themselves |
| Vercel | Hosting for yourcadre.ai and its page-view analytics. Nothing a customer’s agents produce passes through it |
| Google Workspace | Our own email and documents, including the addresses above |
We also disclose information where we are legally required to, and to protect our rights or someone’s safety.
Where data is held
Customer data is processed in the United States — us-east-1. Every provider we use processes in the United States. We serve US customers only today; if that changes, this section will carry the transfer terms that change requires.
How long we keep it
We keep each kind of data only as long as it does the job it was collected for.
| What | How long |
|---|---|
| Account information | For the life of the account, then up to 90 days |
| Data read from a customer’s connected systems | Up to 90 days, or until the engagement ends — whichever comes first |
| Credentials (OAuth tokens, API keys) | Until revoked, or immediately on termination |
| Run traces — the record of what an agent did on each execution | 90 days |
| Approval and gate records — who approved which action, and when | 12 months |
| Security and audit logs | 12 months |
| Backups | Purged on our normal backup cycle, within 35 days |
Deletion on request. A customer can ask us to return or delete their data at any time. We action it within 30 days of a written request, except where we are required to keep something by law. Data is removed from live systems within that window and from backups on the normal backup cycle described above — a backup snapshot cannot be edited in place, so it expires rather than being amended.
Evaluation data is the one exception, and it holds references rather than content. To measure whether an agent is doing its job correctly we keep sets of labelled examples drawn from a customer’s deployment. An evaluation set records the identifier of a record in the customer’s own system and the judgement made about it — never the record itself. Those identifiers are meaningless outside the deployment that holds the data they point at, and the data they point at stays there and expires on the schedule above. These evaluation sets are retained indefinitely — they are how we can tell whether a change to an agent made it better or worse, which is not possible against data that expires.
Security
We protect data with access controls, encryption in transit and at rest, and credentials held in a managed secrets store rather than in code or configuration. Access to customer data is limited to people who need it to do their job.
We hold no third-party security certification today. SOC 2 Type II is on our roadmap and we intend to begin readiness ahead of our first enterprise contract; we will say where we have got to rather than claim a status we have not reached. Our current approach is set out in our Security & Compliance Roadmap, available on request.
To report a vulnerability, contact security@yourcadre.ai.
No system is perfectly secure.
Your rights
Depending on where you live, you may have the right to access, correct, delete, or receive a copy of your personal information, to object to or restrict its processing, and to withdraw consent. Where we process data on a customer’s behalf, we will refer your request to them and support them in answering it.
To make a request: privacy@yourcadre.ai. We will not discriminate against you for exercising these rights.
Children
Cade is a business product. It is not directed to anyone under 16, and we do not knowingly collect information from children.
Changes
We will update this policy as the service changes. Material changes will be notified to customers by email to the account contact before they take effect.
Contact
privacy@yourcadre.ai · legal@yourcadre.ai for data processing agreements · security@yourcadre.ai for vulnerability reports
Your Cadre, Inc, 1717 N Street NW, Ste 1, Washington, DC 20036, USA