Privacy Policy
What we collect when you contact us, what we deliberately never collect from your infrastructure, and how to have any of it deleted.
Last updated 26 July 2026
1. Who we are
Odonat AI (“Odonat”, “we”) provides an autonomous reliability control plane deployed inside customer infrastructure. For website and deployment enquiries, Odonat is the data controller. For data processed inside a customer’s own VPC, the customer is the controller and Odonat is a processor under the applicable data processing agreement.
2. What we collect from this website
- Deployment enquiry details: name, work email, phone number, company, role, and deploy frequency, submitted voluntarily through the request form.
- Technical request data: IP address and request timestamps, retained transiently for rate limiting and abuse prevention.
We do not run third-party advertising or cross-site tracking on this site, and we do not sell personal data.
3. What we never collect from your infrastructure
This is the part that matters to a security reviewer. The Odonat agent runs inside your VPC and is engineered so that proprietary material does not leave it:
- Code diffs and telemetry are processed in volatile memory and overwritten on task completion. There is no persistent disk write for proprietary source.
- All outbound traffic to foundation models passes through a local egress proxy that redacts credentials and personal data by regex and entropy analysis, and drops the request if redaction fails.
- The agent requires zero inbound ports. Telemetry is ingested by outbound polling or internal cluster event buses.
4. Why we use it
- To respond to a deployment enquiry and scope an installation.
- To send information about the product where you have consented, which you may withdraw at any time.
- To protect the service from abuse, and to meet legal obligations.
5. How long we keep it
Deployment enquiry records are retained for up to 24 months from last contact, then deleted. Rate-limiting records are retained for no more than 15 minutes. Customer code and telemetry processed by the agent are not retained at all.
6. Sharing
We share personal data only with infrastructure and communication providers acting on our instructions, and where required by law. We do not sell or rent it.
7. Your rights
Depending on where you live, you may have the right to access, correct, export, or delete your personal data, to object to processing, and to withdraw consent. Email contact@odonat.ai and we will respond within 30 days. You may also complain to your local supervisory authority.
8. Security
Traffic to this site is encrypted with TLS 1.2 or better. Sessions are stored server-side and identified by an HttpOnly, Secure cookie. Authentication is delegated to an OpenID Connect provider using authorization code flow with PKCE; we never see your password.
9. Changes
Material changes will be posted here with an updated date, and where required we will ask for consent again.