Privacy
This summary describes how Noodle Seed handles data during the public beta, including the no-card Free start and self-service paid plans. It will be expanded into a full policy before general availability.
What we collect
On this public website, Statsig collects page views, clicks, device and browser context, performance data, a pseudonymous per-device identifier, and session replay data so we can understand and improve the experience. Form inputs are masked and the lead form is blocked from session replay; named analytics events do not contain submitted contact details or prompt text. When you sign in with Google to the separate console, we receive your account identity (your email and a stable subject identifier) to create your workspace. We also store the deployment metadata and operational records needed to run and secure the service and administer subscriptions, such as which apps you deployed and safety-control counters.
Secrets and tokens are protected by design
Service credentials and secrets are stored through the credential broker, never in manifests, widget payloads, or logs. Our logging is structurally redacted: no code path logs a request header, request body, bearer token, secret value, or continuation token. Tool-call payloads and the contents your server processes are not retained as logs.
How we use data
We use the data above only to operate, secure, debug, and improve the hosted service, and to administer subscriptions, pooled usage limits, and safety controls. We do not sell personal data.
Subprocessors
The hosted service runs on Google Cloud, which processes data on our behalf to provide compute, storage, and key management. Statsig processes website analytics and session replay data on our behalf. We will publish a full subprocessor list as the service matures.
Your choices
You can delete the apps you deploy at any time. To request access to or deletion of your account data, contact us and we will help.
Contact
Privacy questions? Email hello@noodleseed.com.