PRIVACY
Privacy Policy
Last updated: October 1, 2026
If you have questions, contact us at support@camelai.com
On this page
We at CamelQA, Inc. (doing business as camelAI, together with our affiliates, “camelAI”, “we”, “our” or “us”) respect your privacy and are strongly committed to keeping secure any information we obtain from you or about you. This Privacy Policy describes our practices with respect to Personal Information we collect from or about you when you use our website, application, and services (collectively, “Services”).
The Services include camelRun, our hosted runtime for AI agents: its console and API at agents.camelai.dev and run.camelai.com, its SDKs and command-line tool, and the camelRun plugin for ChatGPT and Codex.
1. Personal Information We Collect
We collect personal information relating to you (“Personal Information”) as follows:
Personal Information You Provide:
- Account Information: When you create an account with us, we collect information associated with your account, including your name, contact information, account credentials, and transaction history, (collectively, “Account Information”).
- Sign-in Information: If you sign in to camelRun with GitHub, we receive your GitHub username, account ID, and the date your GitHub account was created, which we use to decide whether a new account gets a sign-up credit. If you sign in with Google, we receive your Google account ID and your verified email address. We don’t receive your GitHub or Google password.
- Agent Content: When you use camelRun, we store what you and your agents create: agent configurations and instructions, conversation history (messages, model replies, and tool calls and their results), files and volumes, schedules, and the settings of channels such as Slack or email. We store the API keys and secrets you give us encrypted. Agent Content is also “Content” under this Privacy Policy.
- Financial Information: Our payment processor(s) will collect the financial information necessary to process your payments, such as your payment card number and authentication details. Please note, however, that we store only a tokenized version of such information. We do not maintain payment card information on our servers.
- User Content: When you use our Services, we collect Personal Information that is included in the input, file uploads, or feedback that you provide to our Services (“Content”).
- Communication Information: If you communicate with us, we collect your name, contact information, and the contents of any messages you send (“Communication Information”).
- Social Media Information: We have pages on social media sites like Twitter, YouTube and LinkedIn. When you interact with our social media pages, we collect Personal Information that you elect to provide to us, such as your contact details (collectively, “Social Information”). In addition, the companies that host our social media pages may provide us with aggregate information and analytics about our social media activity.
- Other Information You Provide: We collect other information that you may provide to us, such as when you participate in our events or surveys or provide us with information to establish your identity (collectively, “Other Information You Provide”).
Personal Information We Receive Automatically From Your Use of the Services:
- Log Data: Information that your browser or device automatically sends when you use our Services. Log data includes your Internet Protocol address, browser type and settings, the date and time of your request, and how you interact with our Services.
- Usage Data: We may automatically collect information about your use of the Services, such as the types of content that you view or engage with, the features you use and the actions you take, as well as your time zone, country, the dates and times of access, user agent and version, type of computer or mobile device, and your computer connection.
- camelRun Usage and Billing Data: We record how your camelRun account uses the service so we can bill for it and enforce limits: which models your agents call and how many tokens they use, runs, storage used, and the credit each of these costs.
- Device Information: Includes name of the device, operating system, device identifiers, and browser you are using. Information collected may depend on the type of device you use and its settings.
- Cookies: We use cookies for essential application uses only (for example, to monitor website usage) and to improve your experience (for example, by remembering your lightmode or darkmode preference). We do not use cookies for ads.
- A “cookie” is a piece of information sent to your browser by a website you visit. You can set your browser to accept all cookies, to reject all cookies, or to notify you whenever a cookie is offered so that you can decide each time whether to accept it. However, refusing a cookie may in some cases preclude you from using, or negatively affect the display or function of, a website or certain areas or features of a website.
- Some cookies expire after a certain amount of time, or upon logging out (session cookies), others survive after your browser is closed until a defined expiration date set in the cookie (as determined by the third party placing it), and help recognize your computer when you open your browser and browse the Internet again (persistent cookies).
For more details on cookies please visit All About Cookies.
2. How We Use Personal Information
We may use Personal Information for the following purposes:
- To provide, administer, maintain and/or analyze the Services;
- To improve our Services and conduct research;
- To communicate with you, including to send you information about our Services and events;
- To develop new programs and services;
- To prevent fraud, criminal activity, or misuse of our Services, and to protect the security of our IT systems, architecture, and networks;
- To carry out business transfers; and
- To comply with legal obligations and legal process and to protect our rights, privacy, safety, or property, and/or that of our affiliates, you, or other third parties.
Aggregated or De-Identified Information: We may aggregate or de-identify Personal Information so that it may no longer be used to identify you and use such information to analyze the effectiveness of our Services, to improve and add features to our Services, to conduct research and for other similar purposes. In addition, from time to time, we may analyze the general behavior and characteristics of users of our Services and share aggregated information like general user statistics with third parties, publish such aggregated information or make such aggregated information generally available. We may collect aggregated information through the Services, through cookies, and through other means described in this Privacy Policy. We will maintain and use de-identified information in anonymous or de-identified form and we will not attempt to reidentify the information, unless required by law.
3. Disclosure of Personal Information
In certain circumstances, we may provide your Personal Information to third parties without further notice to you, unless required by the law:
- Vendors and Service Providers: To assist us in meeting business operations needs and to perform certain services and functions, we may provide Personal Information to vendors and service providers, including providers of hosting services, customer service vendors, cloud services, email communication software, web analytics services, and other information technology providers, among others. Pursuant to our instructions, these parties will access, process, or store Personal Information only in the course of performing their duties to us.
- Business Transfers: If we are involved in strategic transactions, reorganization, bankruptcy, receivership, or transition of service to another provider (collectively, a “Transaction”), your Personal Information and other information may be disclosed in the diligence process with counterparties and others assisting with the Transaction and transferred to a successor or affiliate as part of that Transaction along with other assets.
- Legal Requirements: We may share your Personal Information, including information about your interaction with our Services, with government authorities, industry peers, or other third parties (i) if required to do so by law or in the good faith belief that such action is necessary to comply with a legal obligation, (ii) to protect and defend our rights or property, (iii) if we determine, in our sole discretion, that there is a violation of our terms, policies, or the law; (iv) to detect or prevent fraud or other illegal activity; (v) to protect the safety, security, and integrity of our products, employees, or users, or the public, or (vi) to protect against legal liability.
- Affiliates: We may disclose Personal Information to our affiliates, meaning an entity that controls, is controlled by, or is under common control with camelAI. Our affiliates may use the Personal Information we share in a manner consistent with this Privacy Policy.
- Business Account Administrators: When you join a camelAI Enterprise or business account, the administrators of that account may access and control your camelAI account. In addition, if you create an account using an email address belonging to your employer or another organization, we may share the fact that you have a camelAI account and certain account information, such as your email address, with your employer or organization to, for example, enable you to be added to their business account.
- Other Users and Third Parties You Share Information With: Certain features allow you to display or share information with other users or third parties. For example, you may share conversations with other users via shared links or send information to third-party applications via integrations. Be sure you trust any user or third party with whom you share information.
4. Service Providers
These service providers process Personal Information on our behalf to run the Services:
- Amazon Web Services (United States) hosts camelRun: its servers, database, file storage, backups, logs, and inbound email for agents’ email addresses.
- Cloudflare carries traffic to our websites and to camelRun, hosts our websites and some of our other Services, and sends our emails, such as billing notices.
- Stripe processes payments. When you buy credit, you enter your payment details on Stripe’s pages, and we receive only what we need to record the payment, such as its amount and status, the card’s brand and last four digits, and Stripe’s fingerprint of the card, which lets us offer a sign-up credit only once per card.
- AI model providers, such as OpenRouter, Anthropic, OpenAI, Amazon Bedrock, Microsoft Azure, and Google, receive the prompts, messages, files and tool results that an agent sends to its model, and return the model’s reply. Which provider receives them depends on the model you choose. If you add your own provider API key, the request goes to that provider under your key and its terms.
- Web search providers, such as Exa, Brave, Parallel, and Firecrawl, receive the search queries and page addresses of agents that search or read the web.
- GitHub and Google sign you in when you choose them, under their own privacy policies.
Agents can also send data to tools, MCP servers, websites, and channels (such as Slack, email, or GitHub) that you or your agent configure. That data goes where you direct it, and the recipient’s own terms and privacy policy apply.
5. The camelRun Plugin for ChatGPT and Codex
When you connect the camelRun plugin, ChatGPT or Codex signs in to your camelRun account with your permission and calls camelRun’s tools for you, for example to create, run, list, or delete agents. We receive what those tool calls contain, such as an agent’s name and instructions or the message you ask an agent to answer, and handle it like any other use of camelRun under this Privacy Policy. We don’t receive the rest of your ChatGPT or Codex conversations. OpenAI’s privacy policy governs what OpenAI does with your conversations.
The plugin can reach only the camelRun account you connected. You can disconnect it at any time under Connected apps on the API tokens page of the camelRun console, which revokes its access at once.
6. Data Retention
For camelRun, we keep data for these periods:
| Data | How long we keep it |
|---|---|
| Agents: their configuration, conversation history, tool results, schedules, and channel conversations | Until you delete the agent. An agent created without a key is temporary and expires one day after it is created, unless you set a different lifetime. We delete a deleted or expired agent’s data from our live systems within minutes, and keep only its ID so the ID is never reused. |
| Files: files in volumes (including an agent’s workspace) and files attached to messages | Until you delete them or the agent or volume that holds them. We delete their contents from our live systems within two days after that. |
| Backups | Database backups are kept for 7 days. Earlier versions of stored files are kept for 30 days after they are changed or deleted. So deleted data is gone from backups within about 35 days of its deletion. |
| Email received by an agent’s email address | Large raw messages we store separately are deleted after 7 days. What the agent reads from a message is part of its conversation history, and the addresses, subject lines, and message IDs of its email threads are deleted with the agent or the email channel. |
| Server logs | 30 days. Our logs record IDs, sizes, timings, and error types, not what you or your agents write. Short-lived performance logs are kept for 1 day, and our email service’s logs for 7 days. |
| Console sign-in sessions | 12 hours, or until you sign out. |
| Connected apps (such as the ChatGPT and Codex plugin) | Until you disconnect them or delete your account. Their expired access tokens are deleted a day after they expire. |
| Account information: your GitHub username and account ID or your Google account ID and email address, API tokens, provider API keys, and billing email recipients | Until you delete your account. When you do, we stop your sign-in and tokens at once and delete this information within minutes. |
| Billing records: credit purchases, usage totals, refunds, and sign-up credit records | As long as we need them for tax, accounting, and legal purposes, including after your account is deleted. They hold amounts, dates, and payment IDs; for card payments, the card’s brand, last four digits, and expiry date; and, to give a sign-up credit only once, the GitHub account ID and card fingerprint that claimed it. If you signed up with GitHub, your account ID on these records is your GitHub username. They don’t hold your agents’ content. Stripe keeps its own payment records under its privacy policy. |
| Emails to our support inbox | As long as we need them to help you and to keep a record of what we did. |
For our other Services, we’ll retain your Personal Information for only as long as we need in order to provide our Service to you, or for other legitimate business purposes such as resolving disputes, safety and security reasons, or complying with our legal obligations. How long we retain Personal Information will depend on a number of factors, such as the amount, nature, and sensitivity of the information, the potential risk of harm from unauthorized use or disclosure, our purpose for processing the information, and any legal requirements.
7. Deleting and Exporting Your Data
You can delete a camelRun agent at any time from the console, the API, the SDKs, the CLI, or the ChatGPT and Codex plugin. You can also delete volumes and files, revoke API tokens, and disconnect connected apps yourself. Deleted data is removed on the schedule above.
To get a copy of your data, select Export data on the Account page of the camelRun console. The download holds your agents’ configurations and full conversation histories, your files, and your billing and usage records. It leaves out secrets, API keys, and tokens.
To delete your account, select Delete account on the same page. Your sign-in and tokens stop working at once. We then delete your agents, files, volumes, and account information, usually within minutes, and delete your customer record at Stripe, which removes your saved cards. We keep only the billing records described above. Any prepaid credit left on the account is forfeited. Deleting an account can’t be undone. If you sign up again later with the same GitHub or Google account, you start with a new, empty account.
You can also ask us to export or delete your data by emailing support@camelai.com and telling us the GitHub account or Google email address you sign in with. To protect your account, we’ll confirm the request with the email address on your account or on your public GitHub profile before we act on it. We’ll respond within 30 days.
8. Your Rights
Depending on location, individuals may have certain statutory rights in relation to their Personal Information. For example, you may have the right to:
- Access your Personal Information and information relating to how it is processed;
- Delete your Personal Information from our records;
- Rectify or update your Personal Information;
- Transfer your Personal Information to a third party (right to data portability);
- Restrict how we process your Personal Information;
- Withdraw your consent—where we rely on consent as the legal basis for processing at any time;
- Object to how we process your Personal Information;
- Lodge a complaint with your local data protection authority.
You can exercise some of these rights through your camelAI account. If you are unable to exercise your rights through your account, please submit your request to support@camelai.com.
A note about accuracy: camelAI uses AI models to generate responses by reading a user’s request and predicting the most relevant output. In some cases, the generated output may not be fully factually accurate. For this reason, you should not rely solely on the factual accuracy of AI-generated output. If you notice that output contains factually inaccurate information about you and you would like us to correct the inaccuracy, you may submit a correction request to support@camelai.com. Given the technical complexity of how AI models work, we may not be able to correct the inaccuracy in every instance.
9. Additional U.S. State Disclosures
The following table provides additional information about the categories of Personal Information we collect and how we disclose that information. You can read more about the Personal Information we collect in “Personal Information We Collect” above, how we use Personal Information in “How We Use Personal Information” above, and how we retain Personal Information in “Data Retention” above.
| Category of Personal Information | Disclosure of Personal Information |
|---|---|
| Identifiers, such as your name, contact details, IP address, and other device identifiers | We may disclose this information to our affiliates, vendors and service providers to process in accordance with our instructions; to law enforcement and other third parties for the legal reasons described above; to parties involved in Transactions; to corporate administrators of enterprise or team accounts; and to other users and third parties you choose to share it with. |
| Commercial Information, such as your transaction history | We may disclose this information to our affiliates, vendors and service providers to process in accordance with our instructions; to law enforcement and other third parties for the legal reasons described above; to parties involved in Transactions; and to corporate administrators of enterprise or team accounts. |
| Network Activity Information, such as Content and how you interact with our Services | We may disclose this information to our affiliates, vendors and service providers to process in accordance with our instructions; to law enforcement and other third parties for the legal reasons described above; to parties involved in Transactions; and to other users and third parties you choose to share it with. |
| Geolocation Data | We may disclose this information to our affiliates, vendors and service providers to process in accordance with our instructions; to law enforcement and other third parties for the legal reasons described above; and to parties involved in Transactions. |
| Your account login credentials and payment card information (Sensitive Personal Information) | We disclose this information to our affiliates, vendors and service providers, law enforcement, and parties involved in Transactions. |
To the extent provided for by local law and subject to applicable exceptions, individuals may have the following privacy rights in relation to their Personal Information:
- The right to know information about our processing of your Personal Information, including the specific pieces of Personal Information that we have collected from you;
- The right to request deletion of your Personal Information;
- The right to correct your Personal Information; and
- The right to be free from discrimination relating to the exercise of any of your privacy rights.
We don’t “sell” Personal Information or “share” Personal Information for cross-contextual behavioral advertising (as those terms are defined under applicable local law). We also don’t process sensitive Personal Information for the purposes of inferring characteristics about a consumer.
Exercising your rights: To the extent applicable under local law, you can exercise privacy rights described in this section by submitting a request to support@camelai.com.
Verification: In order to protect your Personal Information from unauthorized access, change, or deletion, we may require you to verify your credentials before you can submit a request to know, correct, or delete Personal Information. If you do not have an account with us, or if we suspect fraudulent or malicious activity, we may ask you to provide additional Personal Information and proof of residency for verification. If we cannot verify your identity, we will not be able to honor your request.
Authorized Agents: You may also submit a rights request through an authorized agent. If you do so, the agent must present signed written permission to act on your behalf, and you may also be required to independently verify your identity and submit proof of your residency with us. Authorized agent requests can be submitted to support@camelai.com.
Appeals: Depending on where you live, you may have the right to appeal a decision we make relating to requests to exercise your rights under applicable local law. To appeal a decision, please send your request to support@camelai.com.
10. Children
Our Service is not directed to children under the age of 13. camelAI does not knowingly collect Personal Information from children under the age of 13. If you have reason to believe that a child under the age of 13 has provided Personal Information to camelAI through the Service, please email us at support@camelai.com. We will investigate any notification and, if appropriate, delete the Personal Information from our systems. If you are 13 or older, but under 18, you must have permission from your parent or guardian to use our Services.
11. Links to Third-Party Websites
The Service may contain links to other websites not operated or controlled by camelAI, including social media services (“Third Party Sites”). The information that you share with Third Party Sites will be governed by the specific privacy policies and terms of service of the Third Party Sites and not by this Privacy Policy. By providing these links we do not imply that we endorse or have reviewed these sites. Please contact the Third Party Sites directly for information on their privacy practices and policies.
12. Security
We implement commercially reasonable technical, administrative, and organizational measures to protect Personal Information both online and offline from loss, misuse, and unauthorized access, disclosure, alteration, or destruction. However, no Internet or email transmission is ever fully secure or error free. In particular, email sent to or from us may not be secure. Therefore, you should take special care in deciding what information you send to us via the Service or email. In addition, we are not responsible for circumvention of any privacy settings or security measures contained on the Service, or third-party websites.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we do, we will post an updated version on this page, unless another type of notice is required by applicable law.
14. How to Contact Us
Please contact support@camelai.com if you have any questions or concerns not already addressed in this Privacy Policy.