Privacy Policy
Last updated: September 27, 2026
This Privacy Policy explains how Infragate, LLC (“we”, “us”, or “our”) collects, uses, and discloses information when you use our Services. It also describes your privacy rights and how the law protects you.
1. Interpretation and Definitions
Section titled “1. Interpretation and Definitions”Interpretation
Section titled “Interpretation”Words with capitalized initial letters have meanings defined below. These definitions apply whether they appear in singular or plural form.
Definitions
Section titled “Definitions”For the purposes of this Privacy Policy:
- Account - a unique profile created for you to access our Services.
- Affiliate - any entity that controls, is controlled by, or is under common control with a party.
- Company - refers to Infragate, LLC, located at 1207 Delaware Ave, Suite 679, Wilmington, Delaware 19806, United States.
- Cookies - small files placed on your device by a website to store browsing data.
- Device - any device capable of accessing the Services, such as a computer, mobile phone, or tablet.
- Organization - a workspace that one or more Accounts belong to. Most of our Services are organization-scoped.
- Personal Data - any information related to an identified or identifiable individual.
- Services - the Website together with the products described in Section 2: ShareCube, Lanyard, Cairn and Capa.
- Service Provider - any third party processing data on behalf of the Company.
- Third-Party Social Media Service - websites or networks that allow login or account creation. We offer Google and GitHub.
- Usage Data - automatically collected data about your interactions with the Services.
- Website - refers to infragate.ai, infragate.co, sharecube.io and capa.sh, and all of their subdomains.
- You - the individual using the Services, or the organization on whose behalf you use them.
2. The Services this policy covers
Section titled “2. The Services this policy covers”This policy covers all four Infragate products, each of which handles data differently. The product-specific sections are Sections 6 to 9.
| Product | What it is | Where it runs |
|---|---|---|
| ShareCube | Editable documents (“artifacts”) with comments, sharing and AI chat | sharecube.io, app.sharecube.io |
| Lanyard | A gateway that connects your AI agents to third-party MCP servers on your behalf | lanyard.infragate.ai, <project>.lanyard.infragate.ai |
| Cairn | Telemetry and analytics for AI agent sessions | cairn.infragate.ai, cairn.infragate.co |
| Capa | A command-line tool that runs on your own machine, plus a hosted OAuth relay and package registry | capa.sh, capa.infragate.ai |
Who the controller is
Section titled “Who the controller is”-
When you sign up yourself, for your own use, we are the controller of your Account data.
-
When you use one of our Services inside an organization that someone else administers (your employer, for example), that organization decides what is collected and why, and it is the controller. We act as its processor. This applies to ShareCube organization content, Lanyard audit records, Cairn telemetry, and any account created through your organization’s single sign-on.
If your organization is the controller, direct access and deletion requests to it first. We will help it respond. That processing is governed by our Data Processing Agreement, which applies automatically to every organization and does not need to be requested or signed.
3. Data we collect
Section titled “3. Data we collect”Data you give us
Section titled “Data you give us”| Category | What |
|---|---|
| Account | Email address, first and last name, profile photo |
| Profile | Company or organization name, job title or role |
| Organization | Organization name, logo, domain verification records, membership and roles |
| Billing | Billing address and tax ID, collected at checkout. Card details go directly to Stripe and never reach our servers |
| Invitations | The email address of anyone you invite who is not yet a user. Stored for 7 days, then deleted |
| Support | Whatever you put in an email to us |
Data your organization gives us
Section titled “Data your organization gives us”If your organization uses single sign-on, its identity provider sends us your email address, first and last name, and group memberships, and your Account is created automatically. Administrators of an SSO organization manage your profile; you cannot edit it yourself.
Organization administrators can also upload a reporting hierarchy (a CSV naming each person’s manager), which feeds organization charts and usage analytics. The uploaded file is deleted after 7 days; the hierarchy it describes is kept.
Administrators control session length, domain verification, membership, and, in Cairn, per-person usage reporting. Where your employer controls the Account, your employer is the controller for this data.
Waitlist and early access
Section titled “Waitlist and early access”When you join a waitlist through a form on our Website we collect your email address and name and, optionally, your company, role and the product you are interested in. We use it for one thing: to tell you when access to that product opens. Joining a waitlist does not subscribe you to a mailing list, and we do not send marketing from it. We keep a waitlist entry for one year, and you can ask us to remove your details sooner at privacy@infragate.co.
Waitlist sign-ups are also posted to our internal Slack workspace so the team sees them.
Usage Data
Section titled “Usage Data”Collected automatically, and may include IP address, browser type and version, pages visited, visit time and duration, device identifiers and diagnostic data. On a mobile device this may include the model and operating system.
Data from Google and GitHub sign-in
Section titled “Data from Google and GitHub sign-in”If you sign in through Google or GitHub we receive the profile data those providers release for sign-in: typically your name, email address and avatar. For sign-in we request only openid email profile (Google) and read:user user:email (GitHub); we do not request access to your repositories.
This is separate from connecting a GitHub or GitLab account to Capa, which does request repository access. See Section 9.
Internal analytics
Section titled “Internal analytics”We keep an internal reporting copy of user id, email and name, and of organization membership, so we can measure product usage. It is not shared outside the Company.
4. Cookies and local storage
Section titled “4. Cookies and local storage”Our public websites use Google Analytics, and only if you agree. That covers infragate.ai, sharecube.io, capa.sh, blog.infragate.ai and docs.infragate.ai. The consoles, the CLI and everything you sign in to run no analytics, and none of our sites run advertising pixels, session recorders or a tag manager.
On those public sites, a banner asks before any analytics cookie is set:
- Until you choose, or if you decline, Google Analytics runs in consent mode with cookies off. Google receives a cookieless ping for each page view (the page, referrer, browser type and your IP address, which Google does not store) and we see only rough, modelled totals.
- If you accept, Google Analytics sets
_gacookies for up to 2 years so it can tell a returning visitor from a new one. We use this to see which pages get read. Advertising and ad personalization signals stay off either way. - Your answer is kept in an
analytics_consentcookie for 180 days. Change it any time by opening infragate.ai, sharecube.io or capa.sh with#cookie-settingsat the end of the address. Declining deletes the_gacookies.
Google processes this data under Google’s privacy policy, in the United States.
Other cookies and storage:
- Session cookies set by our identity service, to keep you signed in. These are
HttpOnlyand are required, because authentication will not work without them. - Local storage and session storage in the ShareCube, Lanyard and Cairn consoles, to hold your sign-in tokens and preferences such as theme, recently viewed items and navigation state. This stays in your browser.
- Stripe sets its own fraud-prevention cookies on pages where you enter or manage a payment method. These are governed by Stripe’s privacy policy.
5. How we use data, and our legal bases
Section titled “5. How we use data, and our legal bases”| Purpose | Legal basis (UK/EU GDPR) |
|---|---|
| Providing, maintaining and supporting the Services; managing your Account and access rights | Performance of a contract |
| Taking payment, preventing fraud, and meeting tax and accounting obligations | Contract; legal obligation |
| Securing the Services, investigating abuse, enforcing rate limits and plan quotas | Legitimate interests |
| Diagnosing faults and improving the Services | Legitimate interests |
| Service and security announcements you cannot opt out of | Contract; legitimate interests |
| Optional marketing email, if we ever send it | Consent, withdrawable at any time |
| Responding to legal requests, defending claims, and business transfers | Legal obligation; legitimate interests |
We do not sell personal information, and we do not share it for cross-context behavioural advertising.
We do not use your content to train machine learning models. That covers ShareCube artifacts and comments, Cairn telemetry, and Lanyard tool call data. Where content is sent to an AI model to answer a request you made, it is sent for that request only. See Sections 6 and 8.
6. ShareCube
Section titled “6. ShareCube”Your artifacts
Section titled “Your artifacts”ShareCube stores the documents you and your agents create, called artifacts, together with their version history, comments, project names and organization membership. Artifacts may contain whatever you choose to put in them.
To operate the product we also process artifact content: we extract text to build a full-text search index and a per-organization concept graph, and we generate preview cards and summaries for publicly shared items. All of this runs on our own infrastructure.
Who can see an artifact
Section titled “Who can see an artifact”There are three visibility levels:
- Private - visible only to members of the project it belongs to.
- Organization - visible to everyone in your organization.
- Public - readable by anyone holding the link, without signing in, and it may be indexed by search engines. A signed-in user from another organization may also be able to comment on a public artifact.
Please do not put sensitive personal data in an artifact you intend to share publicly.
Artifacts can load third-party content
Section titled “Artifacts can load third-party content”A shared artifact is user-authored HTML or Markdown and runs in a sandboxed frame. It can load resources from, or send requests to, third parties we neither control nor vet. Treat an artifact from someone you do not trust the way you would treat any other untrusted web page.
AI chat
Section titled “AI chat”ShareCube’s chat sends the artifact content or selection you are asking about, together with your conversation, to a large language model through AWS Bedrock, so the model can answer. The models currently configured are Anthropic Claude (Sonnet and Haiku) and OpenAI’s gpt-oss, all accessed inside AWS. Chat may also use an AWS-operated web search connector.
Chat transcripts are retained for 90 days. Chat content is not used to train models.
Version history, notifications and presence
Section titled “Version history, notifications and presence”- Previous versions of an artifact are kept for 90 days and then deleted.
- Notifications and digest emails include the artifact name and up to 280 characters of the comment that triggered them.
- Artifacts and comments you author appear on a profile timeline visible to your organization. You can make your timeline private in settings.
- Each comment keeps the name its author had when they wrote it, so a discussion still reads correctly after someone leaves the organization. While the author is a member we show their current name instead. The stored name is part of the organization’s content and is deleted with the comment, the artifact or the organization.
- Edge and API access logs record the IP address, browser, page or endpoint, and outcome of each request, and which signed-in user made it. They are kept for 30 days and used for security and for answering access requests.
- While you have an artifact open, other viewers can see that you are viewing it.
Connecting an AI client
Section titled “Connecting an AI client”When you connect an AI client such as Cursor, Claude or ChatGPT to ShareCube over MCP, the content it fetches goes to that provider under that provider’s terms, not ours. You can revoke a connection in Settings. MCP access tokens last 1 hour and refresh tokens 30 days; API keys you create do not expire until you delete them.
7. Lanyard
Section titled “7. Lanyard”Credentials for the accounts you connect
Section titled “Credentials for the accounts you connect”Lanyard stores the credentials for the third-party services you connect to it: OAuth access and refresh tokens, and API tokens you paste in.
These are envelope-encrypted with AES-256-GCM under a per-record key from a multi-region AWS KMS key with rotation enabled and a restrictive key policy. Tokens you paste are additionally encrypted in your browser before they reach us. Stored alongside the encrypted credential, in plaintext, are the owner’s email address, the server URL, the issuer, the granted scopes, and the text of the last refresh error.
Credentials are kept until you delete the connection or leave the organization. Deleted records remain in point-in-time database backups for up to 35 days.
Deleting a connection in Lanyard does not revoke the token with the provider. To fully revoke access, also remove the authorization in the provider’s own settings.
What we record about calls
Section titled “What we record about calls”The content of your tool calls, meaning the arguments and the results, is not stored or logged. Our logs write only an allowlist of fields, and every value passes through a secret scrubber.
We do record metadata about each call, because the product’s audit log, security controls, rate limiting and billing depend on it: time, organization, project, user, API key id, the server host and tool name, outcome, error and upstream status, latency, and the client IP address and user agent. Aggregates over this metadata power the usage dashboards.
Audit history is retained by plan: 7 days on Free, 30 days on Pro and Team, 365 days on Enterprise. Recent activity is kept for 30 days. Edge access logs, which include IP addresses, are kept for 30 days.
The servers you connect to
Section titled “The servers you connect to”When one of your agents calls a tool, the arguments and the credential go to whichever upstream MCP server you chose to connect. Those servers are third parties acting at your direction, not our service providers, and what they do with the data is governed by their terms, not ours. We register with providers as the OAuth client “Lanyard by Infragate”.
We email the connection owner about expiring credentials and changed tools.
Console
Section titled “Console”The Lanyard console loads Google Fonts and uses Google’s favicon service to show an icon for each connected server. The favicon request tells Google your IP address and the domain of the server you connected. There is no analytics in the console.
8. Cairn
Section titled “8. Cairn”Cairn is agent observability. It exists to retain and analyse the telemetry you send it, so it is the Service that holds the most sensitive data.
What you send
Section titled “What you send”Cairn ingests OpenTelemetry spans and events from your agents and stores their attributes, including attributes we do not recognise. Depending on how you configure your agent, those attributes can include user prompts, assistant responses, and tool inputs and results. Our setup instructions show how to switch that on (OTEL_LOG_USER_PROMPTS, OTEL_LOG_ASSISTANT_RESPONSES, OTEL_LOG_TOOL_DETAILS).
You choose what to send. If you do not want prompt and response content in Cairn, do not enable those flags.
Redaction is best effort
Section titled “Redaction is best effort”Every attribute is screened for personal data with Amazon Comprehend before it is stored. This is a best-effort filter, not a guarantee: it analyses English only, it is not a secrets scanner, and an organization administrator can turn it off. Anything stored while redaction is off stays unredacted. Do not send secrets, payment card data, health data or special-category personal data to Cairn.
Retention
Section titled “Retention”Cairn telemetry currently has no automatic expiry: sessions, spans, events and metrics are retained until you ask us to delete them. Queue buffers holding not-yet-redacted payloads clear within about 4 days. We are working on configurable retention; until then, email privacy@infragate.co to have data deleted.
Analysis
Section titled “Analysis”- Session evaluation is opt-in. When you enable it, rendered sessions, which may include prompts, replies and commands, are sent to Amazon Nova Lite through AWS Bedrock for scoring.
- Per-person profiles. Organization administrators can see per-person reporting: name, email, cost, usage patterns, and where sessions stall. If you deploy Cairn across a team, this is monitoring of your staff, and giving them notice and having a lawful basis for it is your responsibility, not ours.
Cairn telemetry is not used to train models.
The Cairn console loads Google Fonts. There is no analytics in the console.
9. Capa
Section titled “9. Capa”Capa is a command-line tool that runs on your own machine.
- No telemetry. The CLI sends us no analytics, usage data or crash reports.
- Local activity traces. Tool arguments and result previews for the last 10,000 calls per project are stored in
~/.capa/capa.dbon your machine. They are never uploaded. - Update check. Every command checks
api.github.comfor the latest release. That request is unauthenticated, but it tells GitHub your IP address, user agent and the time. - Local web UI. Capa’s local web interface loads Google Fonts.
Connecting GitHub or GitLab
Section titled “Connecting GitHub or GitLab”capa auth runs the OAuth exchange through an edge function at capa.infragate.ai/auth, which exists so the OAuth client secrets stay out of the CLI. It stores nothing: it swaps the authorization code for tokens and redirects them straight to the CLI listening on your own machine. Token refresh is proxied the same way. If you supply a personal access token with --access-token instead, it never touches our infrastructure at all.
The access Capa requests is broader than sign-in:
| Provider | Scopes | What that means |
|---|---|---|
| GitHub | repo | Read and write access to all of your public and private repositories |
| GitLab | read_api, read_repository | Read access to the API and to repositories |
You can revoke this at any time in your GitHub or GitLab account settings.
Third-party capabilities
Section titled “Third-party capabilities”Capa installs and runs skills, hooks, MCP servers and plugins from GitHub, GitLab, registries and URLs you point it at. That code runs on your machine with your permissions, and we do not review it. Install only what you trust.
Capa Registry
Section titled “Capa Registry”For content published to the Capa Registry we store the publisher identity in the package manifest (name and email), stars, and issue authorship. Package listings and issue authorship are public. Registry content is served publicly and may be mirrored into catalogs.
10. Who we share data with
Section titled “10. Who we share data with”Service providers
Section titled “Service providers”These process data on our behalf, under contract:
| Provider | What they process | Where |
|---|---|---|
| Amazon Web Services | Hosting, storage, databases, email (SES), AI models (Bedrock), personal-data screening (Comprehend) | United States, with edge processing at AWS locations worldwide |
| Stripe | Subscription and credit payments, billing address, tax ID, card details | United States and Ireland |
| Slack | Waitlist sign-up notifications to our internal workspace | United States |
| Web fonts, and favicons in the Lanyard console. Receives visitor IP addresses | Global CDN | |
| Google, GitHub | Sign-in, when you choose social login | United States |
We will update this list when it changes. The same list is Schedule 3 of the Data Processing Agreement, where it serves as the contractual subprocessor schedule, and changes there carry 30 days’ notice and a right to object.
Third parties you choose to connect
Section titled “Third parties you choose to connect”Separately from the above, data goes to third parties because you told it to. These act at your direction under their own terms, and we are not responsible for them:
- Upstream MCP servers you connect through Lanyard.
- AI clients such as Cursor, Claude or ChatGPT that you connect to ShareCube.
- Resources loaded by a shared ShareCube artifact.
- GitHub and GitLab, when you connect them to Capa.
Everyone else
Section titled “Everyone else”We may also disclose data:
- In a merger, acquisition or sale. You will be notified before a different policy applies to your data.
- To law enforcement or public authorities where required by law.
- Where necessary to comply with laws, protect our rights and property, prevent fraud or wrongdoing, protect user or public safety, or defend against legal claims.
- With your consent, for anything else.
11. How long we keep data
Section titled “11. How long we keep data”| Data | Retention |
|---|---|
| Account and organization records | For as long as the Account exists. Deleting the Account removes them immediately |
| Sessions | 30 days |
| Authorization codes | 5 minutes |
| Pending invitations, and the invitee’s email | 7 days |
| Removed organization memberships | 30 days |
| Uploaded reporting hierarchy files | 7 days |
| ShareCube artifacts, comments and projects | Until you delete them; deletion purges the content |
| ShareCube previous versions | 90 days |
| ShareCube chat transcripts | 90 days |
| ShareCube edge and API access logs | 30 days |
| Lanyard credentials | Until the connection is deleted or you leave the organization |
| Lanyard audit history | 7 days (Free), 30 days (Pro, Team), 365 days (Enterprise) |
| Lanyard recent activity and edge access logs | 30 days |
| Cairn telemetry | No automatic expiry. Deleted on request, see Section 8 |
| Waitlist entries | 1 year from sign-up, or sooner if you ask us to remove them |
| Billing records and invoices | Kept by us and by Stripe as long as tax and accounting law requires |
| Operational logs | Varies by component, from 14 days to indefinite. We are standardising this |
| Database backups | Deleted records remain restorable for up to 35 days |
Where we say “deleted on request”, see Section 13.
12. Where your data is processed
Section titled “12. Where your data is processed”Our infrastructure runs in the United States (AWS us-east-1). Some processing happens at AWS edge locations worldwide: ShareCube uploads are handled at the CloudFront location nearest you, and Lanyard and Capa run edge functions. Logs from that processing stay in the region where it ran.
If you are in the UK, EU or another jurisdiction that restricts international transfers, your data will be transferred to the United States. That transfer is covered by our Data Processing Agreement, which incorporates the EU Standard Contractual Clauses (Module Two) and the UK Addendum, and sets out the equivalent position for Switzerland. It applies automatically; you do not need to ask us for it. If your procurement process needs a countersigned copy, email privacy@infragate.co.
13. Your rights
Section titled “13. Your rights”Wherever you are, you can ask us to:
- Access the personal data we hold about you, and receive a copy in a portable format
- Correct anything inaccurate
- Delete your data
- Object to or restrict processing based on our legitimate interests
- Withdraw consent to marketing at any time, without affecting anything done before
Email privacy@infragate.co. We will respond within 30 days, and will tell you if we need longer. We will not charge you or treat you differently for exercising a right.
If your organization administers your Account, ask your organization first. We act on its instructions for that data and will refer your request to it.
How to delete your Account. Go to the Security page of your account settings and choose Delete my account. Your personal organization must be the only one you belong to, so leave or delete any other organization first; if you own one, delete it or transfer ownership and leave. Deletion is immediate, removes your profile and your personal organization along with the Account, and cannot be undone.
If your Account is administered by your organization through single sign-on, you will not see the option, because the Account belongs to that organization. Ask an administrator there.
Two things survive: invoices and payment records we and Stripe must keep for tax and accounting, and database backups, from which deleted records age out within 35 days. If you would rather we did it for you, email privacy@infragate.co from the address on the Account and we will do it within 30 days.
In the UK or EU, you also have the right to complain to your data protection supervisory authority.
In California and other US states with privacy laws, the rights above cover the access, correction, deletion and portability rights those laws give you. We do not sell personal information and do not share it for cross-context behavioural advertising, so there is nothing to opt out of; we honour Global Privacy Control signals as a matter of course. We do not use personal data to make decisions that produce legal or similarly significant effects about you.
14. Security
Section titled “14. Security”Infragate is built with security as a priority.
- All traffic is encrypted in transit, and data is stored with server-side encryption at rest.
- Lanyard credentials are additionally envelope-encrypted with per-record keys from a rotating KMS key (Section 7).
- Access to production data is governed by IAM policies on the principle of least privilege.
- The content of tool calls through the Lanyard gateway is not stored or logged. Call metadata is; see Section 7 for exactly what. ShareCube artifacts and Cairn telemetry are stored by design, because showing them back to you is the product.
No method of transmission or storage is completely secure, and we do not claim otherwise.
Reporting a vulnerability. Email security@infragate.co. Please give us a reasonable chance to fix an issue before disclosing it publicly.
Breach notification. If a breach affects your personal data and is likely to result in a risk to your rights, we will notify you and the relevant supervisory authority without undue delay, and within 72 hours of becoming aware of it where the law requires that.
15. Children’s Privacy
Section titled “15. Children’s Privacy”Our Services are not directed at children. You must be at least 18 to use them, and we do not knowingly collect personal data from anyone under 13. If you believe a child has given us personal data, contact us and we will remove it.
16. Links to Other Websites
Section titled “16. Links to Other Websites”Our Services may link to sites we do not operate. We are not responsible for their privacy practices. Please review their policies individually.
17. Changes to This Privacy Policy
Section titled “17. Changes to This Privacy Policy”We may update this Privacy Policy. The “Last updated” date at the top changes whenever we do, so it always names the version you are reading.
Where a change is material, we ask you to accept the updated policy the next time you sign in, and we record which version you accepted and when. Signing in requires accepting it.
We do not rely on a notice email to tell you about a change, so the date above and that prompt are how you will know. You can read the current policy at any time without signing in.
18. Contact Us
Section titled “18. Contact Us”- 📄 Data Processing Agreement, including the Standard Contractual Clauses: docs.infragate.ai/data-processing-agreement
- 📧 Privacy, and requests about your data: privacy@infragate.co
- 🔐 Security and vulnerability reports: security@infragate.co
- 📧 Everything else: contact@infragate.co
- 📮 Post: Infragate, LLC, 1207 Delaware Ave, Suite 679, Wilmington, Delaware 19806, United States