Scope
This policy applies to usesalus.ai, app.usesalus.ai, Salus accounts and workspaces, our hosted APIs, and communications with us. A customer decides which agent actions and context to submit to Salus. When product data relates to that customer’s users or other individuals, the customer controls the integration and the information it supplies.
Information we collect
Account and workspace information. When you register or join a workspace, we collect information such as your name, email address, authentication data, workspace membership and role. We also store the agents, tools, environments, policies, settings, API-key metadata, and other configuration you create.
Action and decision information. When a protected action crosses Salus, we may receive the tool name and arguments; request, agent, project, principal, session, and tool-call identifiers; execution mode and structured context; and any trusted input, evidence, lineage, delegation, or transaction value your integration supplies. Salus resolves the applicable policy, rule, registered configuration, and configured facts. A decision record may contain the verdict and enforcement status, reason, matched rule and policy version, timing, missing or resolved facts, evidence references, recovery instructions, execution status, and provider outcome.
Raw audio, full transcripts, raw payment-card data, and unrelated personal information are not required for the standard authorization path. An integration can still supply personal information in tool arguments, evidence, or structured context, so customers should send only what the action requires and configure redaction appropriately.
Service, security, and support information. We collect request and diagnostic information needed to operate and secure the service, such as timestamps, network and device information, error reports, audit activity, usage, and performance data. If you contact us, we keep the communication and the information you provide.
Billing information. If you purchase a paid service, we receive subscription, plan, payment-status, and transaction records. Stripe processes payment details; Salus does not need to store full payment-card numbers.
Website and inquiry information. If you apply for a pilot, we collect the name, work email, and organization you submit through a Salus endpoint hosted on Vercel. We use that information to respond to your inquiry and discuss a possible Salus pilot. Resend delivers the submission notification to our inbox. If you subscribe through our blog or newsletter, Beehiiv processes the information you submit there.
Where information comes from
We receive information directly from account holders and website visitors; from customer administrators; from Salus SDKs, APIs, proxies, and protected tool routes; and from integrations or evidence resolvers a customer chooses to connect.
How we use information
We use information to provide runtime authorization and decision receipts; authenticate users and enforce workspace permissions; operate shadow, approval, replay, export, and support features; bill for paid services; monitor reliability and security; prevent abuse; respond to inquiries; comply with law; and improve the service.
Salus evaluates proposed agent actions using customer configuration, policy, evidence, and enabled checks. Depending on the result, Salus can allow the action, return a revision, request approval, or block it. Customers choose the actions they govern, the policy they apply, and whether a route runs in shadow or enforcement mode.
Where applicable law requires a legal basis, we process information as needed to provide the service or take requested pre-contract steps, for our legitimate interests in operating and securing Salus, with consent where we ask for it, and to meet legal obligations.
Website analytics
Vercel Web Analytics measures aggregate page views, referrers, approximate location, and device information without using cookies or storing a persistent visitor identifier. We also use Google Analytics to measure page views and selected interactions such as pilot and demo clicks. Google Analytics may process device and browser information, approximate location, session activity, and a first-party identifier. Salus does not send the name or email entered in the pilot form to either analytics service.
Where opt-in consent is required, Google Analytics remains off until you choose “Allow analytics.” Elsewhere, it starts with the site and can be turned off at any time using the control below.
Advertising storage, advertising personalization, and Google Signals are disabled in our website configuration. Learn more about how Google uses information from sites that use its services.
Service providers and integrations
Our default hosted product uses Fly.io for compute; Supabase on AWS for PostgreSQL; AWS services including SageMaker and S3; Resend for transactional email; Sentry for error and performance monitoring; Stripe for billing; OpenAI for enabled model-backed features; and GitHub Actions for software delivery.
Customer-configured integrations—including Slack, GitHub scanning, Retell, Vapi, optional model providers, and customer-selected webhook or export destinations—may receive the information needed for the feature only when a customer enables it. Those destinations are also subject to the customer’s agreement with the provider.
Our marketing surfaces use Vercel for website hosting, pilot submissions, and cookieless aggregate analytics; Google Analytics for the measurement described above; Beehiiv for the blog and newsletter; and Resend for pilot-inquiry notifications. Marketing services do not receive Salus product decision data from us.
We may also disclose information when required by law, to protect Salus, our customers, or others, or as part of a merger, financing, acquisition, or sale of assets subject to appropriate protections. We do not sell product data or use it for targeted advertising.
Retention, export, and deletion
Product payload retention is configurable from 1 to 365 days and is 30 days by default. The scheduled retention process scrubs stored payload content and event-level transaction values after the configured period while preserving structural audit records. Audit history, account records, security records, and backup copies have separate lifecycles and may be kept as needed to operate and secure the service, meet legal obligations, and resolve disputes.
Workspace administrators can export workspace-scoped decision records in supported formats. Workspace owners can delete a workspace and its tenant data, and users can delete their accounts. We keep pilot inquiries and business communications while needed to respond, manage the relationship, and meet legal or security requirements.
Security and processing location
We use technical and organizational measures intended to protect information, including encrypted connections, encryption at rest, scoped credentials, tenant isolation, and audited access controls. More detail is available on our Trust page. No system is completely secure, and we cannot guarantee absolute security.
Salus is based in the United States. The hosted authorization service runs primarily on Fly.io in San Jose, and production PostgreSQL runs on Supabase in AWS us-west-1. Our providers and customer-configured destinations may process information in other locations.
Your choices and rights
Depending on where you live, you may have rights to access, correct, delete, or receive a copy of personal information; object to or restrict certain processing; withdraw consent; or appeal a response. Email founders@usesalus.ai to make a request. We may verify your identity and authority before completing it.
If Salus processes information about you on behalf of one of our customers, contact that customer first. We will support the customer in responding as required. We will not discriminate against you for exercising an applicable privacy right.
Your Google Analytics choice
You can allow or turn off Google Analytics and change that choice later. Turning it off does not affect the site or pilot form.
Changes and contact
We may update this policy as Salus changes. We will revise the effective date above and provide additional notice when required. For a privacy question or request, email founders@usesalus.ai.