ConstellaOne
HomeTerms of Service

ConstellaOne

Privacy Policy

Version 1.0Effective August 1, 2026

This Policy explains how ConstellaOne handles personal information through its website, customer portal, AI-powered digital agents, communications, and related services.

1. Scope and our role

ConstellaOne LLC, a Colorado limited liability company doing business under the ConstellaOne brand ("ConstellaOne," "we," "us," or "our"), provides AI-powered digital agents for business operations. This Privacy Policy applies when you visit constellaone.com, submit an assessment or inquiry, create or use an account, interact with an agent, connect a third-party service, or communicate with us (collectively, the "Services").

For account, website, billing, support, and service-administration information, ConstellaOne generally decides why and how information is processed. For personal information a business customer directs us to process through an agent, ConstellaOne generally acts as a service provider or processor on that customer's behalf. In that situation, the customer's privacy notice and instructions also apply, and requests about the customer's data may need to be directed to that customer.

2. Information we collect

Information you provide

  • Identity and contact information: name, business email, organization, role, phone number if provided, and communications preferences.
  • Account and onboarding information: login identifier, authentication credentials handled by our authentication provider, account settings, authorized users, agent configuration, legal-document acceptances, and onboarding responses.
  • Customer Content: prompts, chat and communication history, uploaded documents, notes, instructions, tasks, meeting and calendar information, generated documents, workflow records, and other material you choose to submit.
  • Agent memory and business context: customer-specific facts, preferences, decisions, relationships, operating procedures, prior interactions, and other context used to make an agent useful to your organization.
  • Connected-service data: content and metadata from email, calendar, storage, communication, or other services you authorize, subject to the permissions you grant.
  • Billing and commercial records: subscription, invoice, payment-status, transaction, and tax information. A payment provider may collect complete payment-card details directly; ConstellaOne does not need to store complete card numbers when a provider handles them.
  • Support and feedback: correspondence, issue details, call or meeting notes, survey responses, and product feedback.

Information collected automatically

When you use the Services, we and our infrastructure providers may collect IP address, date and time, browser and device type, operating system, referring page, pages or features used, session and authentication events, approximate location derived from IP address, diagnostic records, performance data, and security logs. We do not use this information to infer sensitive characteristics.

Information from others

We may receive information from your organization or administrator, people who communicate with your agent, services you connect, referral partners, and providers that help us prevent fraud, authenticate users, process payments, or operate the Services.

3. How we use information

  • provide, configure, personalize, and operate agents, customer memory, communications, research, drafting, document generation, automations, and requested integrations;
  • create and administer accounts, authenticate users, record legal acceptance, bill customers, and manage the customer relationship;
  • respond to support requests and inquiries, troubleshoot, communicate service notices, and provide onboarding;
  • monitor reliability and usage, debug errors, evaluate features, and improve the safety, quality, and usefulness of the Services;
  • protect accounts and systems, prevent fraud and abuse, investigate incidents, enforce agreements, and preserve service integrity;
  • comply with law, respond to lawful requests, establish or defend legal claims, and maintain required business records;
  • send marketing communications where permitted. You may unsubscribe from marketing email, but we may still send transactional or security messages.

Where required, we rely on consent for a particular processing activity. We may also process information to perform a contract, comply with law, and pursue legitimate operational, security, and business interests that are not overridden by applicable privacy rights.

4. AI processing and model providers

To perform requested work, Customer Content may be sent to and processed by AI models and trusted providers supporting model inference, agent execution, hosting, storage, and communication. This may include prompts, files or relevant excerpts, chat history, instructions, connected-service content, and customer-specific memory selected for the task.

We limit the information sent to what is reasonably needed for the requested function and use commercial provider offerings and configurations intended not to use Customer Content to train generalized provider models without authorization. ConstellaOne does not use Customer Content to train a generalized AI model unless we first disclose that use and obtain any consent required by law or contract. Human reviewers may access content only when reasonably necessary for support, safety, security, legal compliance, or at your request, subject to confidentiality and access controls.

AI systems can infer or generate information that is incorrect or unexpected. Customers control what information they provide and must avoid submitting sensitive or regulated information unless its use has been approved and the Services have been configured for it.

5. Service providers used by ConstellaOne

As of this Policy's effective date, the production architecture and deployed website code identify the following providers. A provider processes information only for the functions that use it.

  • OpenAI: AI model inference for supported agent tasks.
  • Supabase: account authentication, database, and customer-portal data services.
  • Cloudflare: website delivery, serverless functions, network security, and related logs.
  • Resend: delivery of website assessment, intake, and operational email.
  • Orgo: isolated computing environments used to run configured customer-agent workloads.
  • AgentMail: agent email transport for customers who enable email workflows.
  • Fly.io: hosting for supported platform and gateway services.
  • Tailscale: secured network connectivity and associated connection metadata for supported infrastructure.

Anthropic is not listed because the reviewed production source did not establish it as a current provider. We may add or replace providers as the Services evolve; we will update this Policy when a change materially affects how personal information is processed.

6. How we disclose information

We may disclose relevant information:

  • to the providers above and other contractors that support hosting, security, billing, support, analytics, legal, and professional services under appropriate obligations;
  • to integrations, recipients, collaborators, and systems you or your organization instruct an agent to use;
  • to your organization's account owners and administrators, who may manage users, permissions, content, and agent activity;
  • when reasonably necessary to comply with law or legal process, protect rights and safety, investigate misuse, or enforce an agreement;
  • in a financing, merger, acquisition, reorganization, bankruptcy, or transfer of some or all of our business, subject to appropriate confidentiality protections;
  • with your direction or consent.

We do not sell personal information for money, and we do not use or disclose personal information for cross-context behavioral or targeted advertising. We do not disclose Customer Content for a provider's independent marketing.

7. Data retention and deletion

We retain account, Customer Content, agent memory, and service records for the customer relationship and as needed to provide the Services. The precise period depends on customer configuration, the type of record, connected-service behavior, and contractual requirements. When an account or item is deleted, we remove it from active systems within a reasonable period unless continued retention is needed for security, fraud prevention, dispute resolution, legal compliance, or another permitted purpose. Residual copies may remain in encrypted or access-controlled backups until those backups cycle out.

We retain legal-acceptance, billing, transaction, security, and audit records for the period reasonably necessary to document the relationship, comply with law, and establish or defend legal claims. Deidentified information may be retained where it cannot reasonably be linked back to a person.

To request deletion of an account or personal information, email [email protected]. An organization administrator may also control or delete information in a business account. We will verify the request and explain if an exception prevents complete deletion. Before closing an account, export any Customer Content you need.

8. Security

We use administrative, technical, and organizational safeguards designed for the nature of the information and service, which may include access controls, authentication, encryption in transit, provider security controls, logging, least-privilege practices, and incident-response procedures. We review safeguards as the platform evolves. No method of storage or transmission is completely secure, and we cannot guarantee that unauthorized access, loss, or misuse will never occur. You are responsible for protecting credentials, configuring appropriate permissions, and promptly reporting suspected compromise.

9. International processing

ConstellaOne and its providers may process information in the United States and other countries where they operate. Those countries may have different data-protection laws. Where legally required, we use recognized transfer safeguards or another lawful transfer mechanism.

10. Your choices and privacy rights

Depending on where you live and subject to legal exceptions, you may have the right to:

  • confirm whether we process your personal information and access or obtain a portable copy of it;
  • correct inaccurate personal information;
  • delete personal information;
  • withdraw consent where processing is based on consent;
  • opt out of sale, targeted advertising, or certain profiling. We do not currently engage in sale or targeted advertising as described above;
  • appeal our response to a privacy request; and
  • not receive discriminatory treatment for exercising a privacy right.

Submit a request or appeal by emailing [email protected] with the subject "Privacy Request" or "Privacy Appeal." Describe your request and the account or relationship involved. We may verify your identity and authority, and we will respond within the period required by applicable law. If another organization controls the information, we may direct you to it. An authorized agent may submit a request where the law permits, subject to verification.

You can unsubscribe from marketing messages using the link in the message. Browser privacy signals are not currently necessary to opt out because we do not sell personal information or use it for targeted advertising. If those practices change, we will provide the required controls and recognize legally required universal opt-out signals.

11. Colorado privacy notice

Colorado residents acting in an individual or household context may have rights under the Colorado Privacy Act to access, correct, delete, and obtain a portable copy of personal data, and to opt out of sale, targeted advertising, and certain profiling. The categories we collect, processing purposes, categories disclosed, and recipient categories are described in Sections 2, 3, 5, and 6. We do not currently sell personal data, process it for targeted advertising, or use it for profiling in furtherance of decisions that produce legal or similarly significant effects.

Use the request and appeal process in Section 10. If an appeal is denied, Colorado residents may contact the Colorado Attorney General. These disclosures do not concede that the Act applies to every processing activity or business-customer record.

12. Children

The Services are for business users and are not directed to children under 13. We do not knowingly collect personal information directly from children under 13. If you believe a child has provided information, contact us so we can investigate and delete it where appropriate. Customers must not use the Services to process children's information without all required authorization and an appropriate written agreement with ConstellaOne.

13. Policy changes and versions

We may update this Policy as our practices, providers, Services, or law changes. We will identify each version and effective date and preserve prior published versions in our legal archive. We will provide additional notice or request consent when legally required. Material changes apply prospectively from the stated effective date.

14. Contact

Questions, privacy requests, appeals, and account-deletion requests may be sent to:

ConstellaOne LLC
Colorado limited liability company
Website: constellaone.com
Email: [email protected]

Home/Terms of Service/Version archive