Golemry

Data & Security

Your automations act on your accounts. Here is exactly how that stays safe.

Last updated: July 2026

Your side

Connected accounts

Gmail, Stripe, anything you connect

keys never leave the vault

scoped tool calls

Golemry

Sandboxed run

fresh per run · torn down after

Overseer

reviews every run · records a verdict

outputs kept 30 days

your API key

Your model provider

Your chosen LLM

OpenAI · Anthropic · Google · OpenRouter

the agent never sees your key

Safe to let an agent act

Credentials never reach the agent

Connected accounts live in a vault (Composio), scoped to you. We keep only a reference, and the agent sees only the result, never your keys.

Your LLM key can't leak

Encrypted at rest, and used only to call your model. The key stays out of reach of the agent and its tools, so a run can't leak it.

Only the tools it needs

Each job gets only the specific tools it needs. A reply-drafting job can't read your inbox, send mail, or touch any other account.

Runs are isolated

Each run executes in an isolated sandbox that is torn down when it ends. One job's run can never reach another's.

Every run is reviewed

An independent overseer agent reviews every run, recording a verdict and flagging suspicious behavior or prompt injection.

Your data is yours

Your configurations and outputs belong to you. We never train general-purpose AI models on them, and run data is deleted after 30 days.

Where your data goes when a job runs

  1. Your connected accounts

    To do its work, the agent reads from or writes to the accounts you connected, such as Gmail or Stripe.

    Where

    Held by Composio, scoped to each job

    Retention

    Until you disconnect the account

  2. The run sandbox

    Each run happens in a fresh, isolated sandbox in the cloud. Your data is only there while the job runs.

    Where

    Google Cloud (US)

    Retention

    Erased when the run ends

  3. The AI model

    The agent sends your prompt and the content it works on to your chosen model, using your own key.

    Where

    The provider you choose: OpenAI, Anthropic, Google, or routed via OpenRouter

    Retention

    The provider's own policy applies

  4. Run traces

    A step-by-step record of each run, used to debug and diagnose problems when something goes wrong.

    Where

    Langfuse (EU)

    Retention

    30 days

  5. Golemry's storage

    Your job setup, run history, transcripts, and results are saved so you can return to them.

    Where

    Supabase (US); files in Google Cloud Storage (US)

    Retention

    Run outputs are kept 30 days

Exactly what we keep, and for how long

Stored data categories, where they live, and how long they are retained
CategoryWhereRetention
Account infoSupabase (US)Account lifetime
Job config, schedules & runsSupabase (US)For the life of the job
Agent conversation transcripts & memorySupabase (US)30 days
Run artifactsGoogle Cloud Storage (US)30 days
LogsGoogle Cloud (US)30 days
Observability tracesLangfuse (EU)30 days
Analytics & session replayPostHog (EU)Analytics retained long-term; recordings ~3 months

Core application data and job execution are hosted in the US (Supabase, Google Cloud, Temporal Cloud, Fly.io). Observability (Langfuse) and product analytics (PostHog) are EU-hosted. We do not claim EU residency for the overall data path.

Who else touches your data

Every external service (subprocessor) that processes your data.

Subprocessors grouped by category, with purpose, processing region, and retention
ServicePurposeRegionRetention
Connectors
ComposioConnectors and third-party tool accessUSUntil you revoke the connection
Hosting & infrastructure
SupabaseDatabase, storage and authenticationUSAccount and job lifetime; run outputs 30 days
VercelHosts and serves the web applicationUSOperational logs, short-term
CloudflareBot protection (Turnstile), privacy-friendly web analytics, and MCP server hostingGlobal edgePer Cloudflare's policy
Google Cloud (Cloud Run)Agent runtime for job executionUSEphemeral, no job content persisted beyond the run
Temporal CloudSchedule execution and orchestrationUSAccount and job lifetime
Fly.ioHosts the Temporal workerUSEphemeral compute
AI models
OpenAIModel inference for the model you choose, with your own keyUSPer the provider's own policy
AnthropicModel inference for the model you choose, with your own keyUSPer the provider's own policy
GoogleModel inference for the model you choose, with your own keyUSPer the provider's own policy
OpenRouterLLM provider routing for the model you choose, with your own keyUS (routes to your chosen provider)The LLM provider's own policy applies
Observability & analytics
LangfuseObservability and tracingEU (Frankfurt)30 days
PostHogProduct analytics and session replayEU (Frankfurt)Analytics retained long-term; session recordings ~3 months
Billing
AutumnBilling and subscription managementUSAccount term
StripePayment processingUSAccount term plus statutory payment-record retention
Email
ResendTransactional email and contact-form deliveryUSPer data processing agreement

Where personal data is processed in the US, those transfers rely on appropriate safeguards (Standard Contractual Clauses and, where the provider is certified, the EU-US Data Privacy Framework). Composio, our connections provider, is SOC 2 and ISO 27001:2022 attested and publishes a public trust center.

What we don't claim

We hold no SOC 2 report, ISO 27001 certification, published penetration-test summary, status page, or bug-bounty program for Golemry yet. Instead, we show you exactly how your data is handled today. The safeguards above are real and in place.

Security contact

Found a vulnerability or have a security question? We read every report.

security@golemry.com