Data & Security
Your automations act on your accounts. Here is exactly how that stays safe.
Last updated: July 2026
Connected accounts
Gmail, Stripe, anything you connect
keys never leave the vault
scoped tool calls
Sandboxed run
fresh per run · torn down after
Overseer
reviews every run · records a verdict
outputs kept 30 days
your API key
Your chosen LLM
OpenAI · Anthropic · Google · OpenRouter
the agent never sees your key
Safe to let an agent act
Credentials never reach the agent
Connected accounts live in a vault (Composio), scoped to you. We keep only a reference, and the agent sees only the result, never your keys.
Your LLM key can't leak
Encrypted at rest, and used only to call your model. The key stays out of reach of the agent and its tools, so a run can't leak it.
Only the tools it needs
Each job gets only the specific tools it needs. A reply-drafting job can't read your inbox, send mail, or touch any other account.
Runs are isolated
Each run executes in an isolated sandbox that is torn down when it ends. One job's run can never reach another's.
Every run is reviewed
An independent overseer agent reviews every run, recording a verdict and flagging suspicious behavior or prompt injection.
Your data is yours
Your configurations and outputs belong to you. We never train general-purpose AI models on them, and run data is deleted after 30 days.
Where your data goes when a job runs
Your connected accounts
To do its work, the agent reads from or writes to the accounts you connected, such as Gmail or Stripe.
Where
Held by Composio, scoped to each job
Retention
Until you disconnect the account
The run sandbox
Each run happens in a fresh, isolated sandbox in the cloud. Your data is only there while the job runs.
Where
Google Cloud (US)
Retention
Erased when the run ends
The AI model
The agent sends your prompt and the content it works on to your chosen model, using your own key.
Where
The provider you choose: OpenAI, Anthropic, Google, or routed via OpenRouter
Retention
The provider's own policy applies
Run traces
A step-by-step record of each run, used to debug and diagnose problems when something goes wrong.
Where
Langfuse (EU)
Retention
30 days
Golemry's storage
Your job setup, run history, transcripts, and results are saved so you can return to them.
Where
Supabase (US); files in Google Cloud Storage (US)
Retention
Run outputs are kept 30 days
Exactly what we keep, and for how long
| Category | Where | Retention |
|---|---|---|
| Account info | Supabase (US) | Account lifetime |
| Job config, schedules & runs | Supabase (US) | For the life of the job |
| Agent conversation transcripts & memory | Supabase (US) | 30 days |
| Run artifacts | Google Cloud Storage (US) | 30 days |
| Logs | Google Cloud (US) | 30 days |
| Observability traces | Langfuse (EU) | 30 days |
| Analytics & session replay | PostHog (EU) | Analytics retained long-term; recordings ~3 months |
Core application data and job execution are hosted in the US (Supabase, Google Cloud, Temporal Cloud, Fly.io). Observability (Langfuse) and product analytics (PostHog) are EU-hosted. We do not claim EU residency for the overall data path.
Who else touches your data
Every external service (subprocessor) that processes your data.
| Service | Purpose | Region | Retention |
|---|---|---|---|
| Connectors | |||
| Composio | Connectors and third-party tool access | US | Until you revoke the connection |
| Hosting & infrastructure | |||
| Supabase | Database, storage and authentication | US | Account and job lifetime; run outputs 30 days |
| Vercel | Hosts and serves the web application | US | Operational logs, short-term |
| Cloudflare | Bot protection (Turnstile), privacy-friendly web analytics, and MCP server hosting | Global edge | Per Cloudflare's policy |
| Google Cloud (Cloud Run) | Agent runtime for job execution | US | Ephemeral, no job content persisted beyond the run |
| Temporal Cloud | Schedule execution and orchestration | US | Account and job lifetime |
| Fly.io | Hosts the Temporal worker | US | Ephemeral compute |
| AI models | |||
| OpenAI | Model inference for the model you choose, with your own key | US | Per the provider's own policy |
| Anthropic | Model inference for the model you choose, with your own key | US | Per the provider's own policy |
| Model inference for the model you choose, with your own key | US | Per the provider's own policy | |
| OpenRouter | LLM provider routing for the model you choose, with your own key | US (routes to your chosen provider) | The LLM provider's own policy applies |
| Observability & analytics | |||
| Langfuse | Observability and tracing | EU (Frankfurt) | 30 days |
| PostHog | Product analytics and session replay | EU (Frankfurt) | Analytics retained long-term; session recordings ~3 months |
| Billing | |||
| Autumn | Billing and subscription management | US | Account term |
| Stripe | Payment processing | US | Account term plus statutory payment-record retention |
| Resend | Transactional email and contact-form delivery | US | Per data processing agreement |
Where personal data is processed in the US, those transfers rely on appropriate safeguards (Standard Contractual Clauses and, where the provider is certified, the EU-US Data Privacy Framework). Composio, our connections provider, is SOC 2 and ISO 27001:2022 attested and publishes a public trust center.
What we don't claim
We hold no SOC 2 report, ISO 27001 certification, published penetration-test summary, status page, or bug-bounty program for Golemry yet. Instead, we show you exactly how your data is handled today. The safeguards above are real and in place.
Security contact
Found a vulnerability or have a security question? We read every report.
security@golemry.com