Privacy & data handling for developers
- Provider credentials are encrypted with AES-256-GCM under a key held only in Sweep’s runtime secrets and never leave the connector boundary. You receive connection ids, never tokens.
- Inventory and Vault objects belong to the end user’s tenant. Developers see normalized metadata and, with
vault:read, short-lived signed download URLs for objects within their connection’s scope. - Retention: revoking a connection immediately stops access; the end user controls deletion of their Vault and account. Developer audit logs are retained for 24 months.
- Usage events are immutable, retained for accounting, and contain no end-user content.
- Sub-processors: Cloudflare (compute, storage, queues, email), Stripe (payments), Anthropic (intelligence; no training on content, zero-retention agreement).
- No advertising, no profiling, no data brokerage. Private content never trains models.
- Requests: privacy@trustysweep.com. Consumer policy: https://trustysweep.com/legal/privacy.