Privacy policy
How Continual collects, uses, and shares personal information across our website, product, and business operations.
Last updated
1. Overview
This Privacy policy explains how Continual, Inc. (“Continual,” “we,” “us,” or “our”) handles personal information when you visit our websites, use the Continual service, communicate with us, or otherwise interact with our business.
This policy covers information Continual handles for its own business purposes. When a customer uses Continual to process personal information in its data, systems, applications, or agent workflows (“Customer content”), that customer controls the data and Continual processes it on the customer's behalf. The customer's privacy notices and our agreement with that customer, including our Data processing addendum, govern that processing.
2. Information we collect
Information you provide
- Account and profile information, such as your name, work email address, organization, role, profile details, and account credentials or authentication identifiers.
- Customer content, such as prompts, messages, files, code, project data, instructions, outputs, connection settings, and information accessed from Customer systems at your direction.
- Communications, including support requests, feedback, sales inquiries, meeting details, survey responses, and other messages you send us.
- Billing information, such as billing contact, company name, address, tax information, plan, and transaction details. Payment-card details are provided directly to Stripe; we do not receive or store the full card number.
Information collected automatically
- Device and network information, such as IP address, browser type, operating system, device identifiers, language, and approximate location derived from IP address.
- Website and product activity, such as pages viewed, referring pages, navigation, clicks, feature use, timestamps, errors, and interactions. Session replay or similar diagnostics may be collected where enabled.
- Service and usage information, such as workspace, project, user, thread, run, and deployment identifiers; model and tool used; token, runtime, compute, storage, database, and network quantities; outcomes; and related billing events. We use this information to operate, secure, support, and bill for the Service.
- Cookies and similar technologies, which can recognize a browser, preserve preferences and sessions, measure activity, and connect a website visit to information you later provide.
Information from other sources
We may receive information from:
- your employer, workspace administrator, or another authorized user;
- identity, payment, analytics, marketing, support, and security providers;
- Customer systems you choose to connect, according to the connection and permissions you authorize; and
- public sources and business-data providers for sales, security, fraud prevention, and account administration.
3. How we use information
We use personal information to:
- provide, operate, maintain, and improve the Service;
- create and administer accounts, workspaces, permissions, and connections;
- carry out user and customer instructions, including sending data to selected models, tools, and Customer systems;
- meter usage, manage credits and plans, process payments, and provide invoices and billing support;
- authenticate users, prevent abuse and fraud, protect systems, and investigate security incidents;
- provide support and send service, security, billing, and administrative messages;
- analyze website and product performance and understand how our services are used;
- respond to inquiries, manage sales relationships, and send marketing communications where permitted;
- enforce our agreements, protect rights and safety, and comply with legal obligations; and
- create and use aggregated or de-identified information that does not reasonably identify a person or customer.
4. How we disclose information
We may disclose personal information:
- Within your workspace. Workspace owners and other authorized users may see your profile, activity, content, and usage according to their permissions.
- To service providers. We use providers for hosting, infrastructure, authentication, AI models, analytics, customer relationship management, communications, security, billing, and payment processing. They may process information only to provide services to us or as otherwise described in their terms and privacy notices.
- To Customer systems. We exchange information with applications, accounts, tools, and services that a customer or user connects or directs the Service to use.
- For legal and safety reasons. We may disclose information when we reasonably believe it is necessary to comply with law or valid legal process; enforce agreements; investigate fraud, abuse, or security issues; or protect people, rights, and property.
- In a corporate transaction. Information may be disclosed in connection with financing, due diligence, a merger, acquisition, reorganization, bankruptcy, or sale of assets, subject to appropriate confidentiality protections.
- With your direction or consent. We disclose information when you ask us to or otherwise consent.
We do not sell personal information for money. We do not use personal information for cross-context behavioral advertising. If that changes, we will update this policy and provide any legally required choices.
5. Key providers and integrations
The providers below support important parts of the current Service. The exact providers involved can depend on the features, configuration, and Customer systems you use.
| Provider | Purpose and information involved |
|---|---|
| Clerk | Authentication and account directory; name, email, account and organization identifiers, session, device, and security data. |
| Stripe | Payment methods, checkout, and payment processing; billing contact, address, payment method, transaction, tax, fraud, and customer identifiers. Stripe receives payment-card details directly. |
| Metronome | Usage metering, credits, plans, invoices, and billing orchestration; workspace and customer identifiers, plan and contract data, metered usage quantities and event metadata, charges, credits, and payment status. We do not send prompt or file contents to Metronome for billing. |
| Google Cloud | Core hosting, managed databases, object and file storage, networking, logging, and infrastructure; account identifiers, Customer content, stored files and records, and technical and security data. |
| Cloudflare | DNS, network security, content delivery, custom domains, and hosting and storage for deployed applications; network and request data, deployment artifacts, application content, configuration, and runtime data. |
| Databricks (Neon) | Managed PostgreSQL and branch databases used by the Service, Customer projects, and deployed applications; workspace and project identifiers, schemas, database records, queries, configuration, connection information, and usage quantities. |
| TensorLake | Cloud sandboxes and compute for agent work; project code and files, commands, environment configuration, execution state, and runtime logs. |
| GitHub | Source control and Customer-selected repository connections; account and repository identifiers, repository content, branches, commits, issues, pull requests, events, and authorization information as configured by Customer. |
| OpenAI | Platform-managed AI model processing; prompts, instructions, relevant Customer content and tool context, outputs, and technical and usage metadata needed to provide the selected model. |
| Anthropic | Platform-managed AI model processing; prompts, instructions, relevant Customer content and tool context, outputs, and technical and usage metadata needed to provide the selected model. |
| Google Gemini | Platform-managed AI model processing; prompts, instructions, relevant Customer content and tool context, outputs, and technical and usage metadata needed to provide the selected model. |
| OpenRouter | AI model routing and inference; prompts, instructions, relevant Customer content and tool context, outputs, and technical and usage metadata. The underlying inference provider depends on the model and routing selected. |
| xAI | AI model processing when an xAI model is selected through a platform-managed router; prompts, instructions, relevant Customer content and tool context, outputs, and technical and usage metadata needed to provide the selected model. |
| PostHog | Product analytics and diagnostics used to operate, secure, and improve the Service; user ID, email, IP address, device and browser data, pages, product interactions, and session diagnostics where enabled. |
| HubSpot | Website analytics, forms, meeting scheduling, sales, and customer communications; contact and company details, form responses, page paths, referrer, IP address, cookie or visitor identifiers, and communication history. |
| Google Analytics | Website measurement where enabled; page and session activity, referrer, browser and device data, IP-derived approximate location, and cookie or device identifiers. We do not intentionally send names, email addresses, or Customer content to Google Analytics. |
The providers involved depend on the features and Customer systems you use. Each provider's own privacy materials describe its processing. Customer-selected services process information under Customer's agreement and settings with that provider. Continual's current processors for Customer Personal Data are listed on our Subprocessors page.
7. Customer content and connected systems
Customers decide what Customer content to submit, which systems to connect, which models and tools to use, and who can access their workspace. When a user directs an agent or application to read from or write to a connected system, data may move between Continual, the selected provider, and that system. The provider's own terms and privacy notice apply to its processing.
If you submit personal information about another person, you are responsible for having an appropriate legal basis and providing any required notice. If you want to exercise a right concerning Customer content, contact the customer that controls the relevant workspace. We will assist that customer as required by our agreement and applicable law.
AI model training
We do not use Customer content to train, retrain, fine-tune, or otherwise develop generalized artificial intelligence or machine-learning models, and we require our platform-managed model providers not to use it for those purposes. We may use Customer content for model improvement only if the customer's workspace administrator expressly opts in to a separately described program.
Customer-selected model providers process information under the customer's agreement with them, including their data-use terms and settings.
Service data may include feature and tool usage, model and provider identifiers, token and resource quantities, timing, latency, retries, success or failure states, and sanitized error codes. We may use this information and aggregated or de-identified information that does not reasonably identify a customer or individual or reveal Customer content to operate, secure, troubleshoot, evaluate, and improve the Service, including its system prompts, model routing, tool selection, retrieval, orchestration, guardrails, and runtime behavior.
Service data does not include the contents of Customer content. We do not use raw prompts, responses, files, code, connected-system records, tool inputs or outputs, or error payloads containing Customer content for generalized product improvement except when needed to provide support requested by the customer or when the customer expressly opts in.
8. Legal bases
Where law requires a legal basis, we process personal information as needed to perform a contract or take requested steps before a contract; for our legitimate interests in operating, securing, supporting, improving, and marketing our business; with consent; and to comply with legal obligations. We consider the impact on your rights before relying on legitimate interests.
You may withdraw consent at any time, but withdrawal does not affect processing already completed. You can unsubscribe from marketing email using the link in the message. We may still send transactional, security, billing, and account messages.
9. Retention
We keep personal information for as long as reasonably needed for the purposes described in this policy, including to provide the Service, maintain security and business records, comply with law, resolve disputes, and enforce agreements. Retention depends on the type of information, the sensitivity and risk, customer configuration, contractual commitments, and legal requirements.
After termination, Customer content is generally available for export for 30 days and may then be deleted, subject to backups, legal holds, security needs, and our agreement with the customer. Billing, transaction, audit, and security records may be kept longer where needed for legitimate business or legal purposes. Aggregated or de-identified information may be retained without a time limit.
10. Security and international transfers
We use reasonable administrative, technical, and organizational measures designed to protect personal information. No method of storage or transmission is completely secure, so we cannot guarantee absolute security. Please report suspected security issues to security@continual.ai.
Continual is based in the United States, and we and our providers may process information in the United States and other countries. Where required, we use recognized transfer mechanisms such as standard contractual clauses and require appropriate safeguards.
11. Your rights and choices
Depending on where you live, you may have rights to request access to, correction of, deletion of, or a copy of personal information; object to or restrict processing; withdraw consent; or appeal a decision about a request. You may also have the right not to receive discriminatory treatment for exercising a privacy right.
To make a request about information Continual controls, email privacy@continual.ai. We may need to verify your identity and authority. Authorized agents may submit requests where permitted by law. We may deny or limit a request where an exception applies and will explain the reason where required.
If your request concerns information in a customer workspace, contact that customer first. Residents of the EEA, United Kingdom, or Switzerland may also complain to their local data protection authority. Residents of jurisdictions that provide an appeal right may appeal by replying to our decision.
12. Children
The Service is for business users who are at least 18 years old. We do not knowingly collect personal information directly from children. If you believe a child has provided personal information to us, contact privacy@continual.ai.
13. Changes and contact
We may update this policy as our services and practices change. We will post the updated version here and revise the date above. If a change materially affects your rights, we will provide additional notice where required.
For privacy questions, requests, or complaints, email privacy@continual.ai or write to Continual, Inc., 95 3rd St, San Francisco, CA 94103, Attn: Privacy.