Privacy Policy
Effective date: July 15, 2026
Estelle gives your coding agent a grounded memory of your codebase. That job only works if your code stays yours. This policy explains what Fate Labs collects, what we do with it, and, just as important, what we structurally cannot and will not do. For the mechanics of the data flow, see the Data & Processing notice; for the honest account of how the product improves, see How Estelle improves itself.
The short version
These three commitments are the reason to trust Estelle with a codebase. They are not marketing: they follow from how the product is built (bring your own model and key, per-tenant isolation, a gate that treats your code as ground truth).
Your code and memory are isolated to your namespace.
Every team's codebase, memory, and derived facts live under a dedicated namespace, and every stored query is scoped to that namespace at the database layer. We do not co-mingle one customer's data with another's, and Estelle's recall for your team only ever reads your namespace.
We do not train on, or mine, your code content.
Because you bring your own model and key, your code goes to your model provider under your terms, so Estelle structurally cannot use your code content to train a model. We also do not read your code to build features or improve the product for anyone else. Estelle's memory and grounding operate on your code for you, and only for you.
We improve Estelle from usage metadata, not your content.
Estelle gets better from how the product is used, aggregated and anonymized signals like which capabilities are called, error rates, and latency, plus public market research. It does not learn from the private contents of your repositories. You can opt out of product-improvement analytics at any time.
Note. The rest of this document is the standard, detailed version. If anything below appears to contradict the three commitments above, the commitments govern, and please tell us so we can fix the text.
Who this covers
“Estelle” is the service operated by Honour Systems Inc. (incorporated in Ontario, Canada), doing business as Fate Labs (“we”, “us”). This policy applies to the Estelle web app, dashboard, the API at api.fatelabs.ca, the hosted MCP server, and the CLI. It covers people who create an account, and the teammates they invite. It does not change the terms under which your own model provider (the one whose key you bring) handles the prompts and code you send them; that relationship is directly between you and that provider.
You can reach us about anything in this policy at khai@fatelabs.ca.
What we collect
We collect the minimum needed to run accounts, bill capacity, and keep the service reliable. In plain terms:
We do not sell personal data, and we do not run third-party advertising trackers on the product surfaces.
How we use it
We use the data above only for these purposes:
- To run the service: authenticate you, build and serve your grounded memory, call your model with your key, and return cited answers.
- To meter and bill: measure capacity and usage against your plan, and process payments for paid tiers.
- To keep it reliable and secure: monitor errors and latency, prevent abuse, and debug incidents.
- To improve the product from usage metadata: understand which capabilities are used, where the product errors, and what to build next, using aggregated, anonymized signals and public research. See How Estelle improves itself, and opt out under Your rights & controls.
- To communicate with you: transactional email (sign-in, receipts, security notices) through our email provider. Product email is opt-out.
We process this data to provide the service you asked for, to meet our legal and tax obligations, and, where the law requires it, with your consent. We do not sell your personal data.
What we never do
This section states the guarantees from the summary as concrete negatives, so there is no ambiguity:
- We do not use the content of your repositories to train, fine-tune, or evaluate any model, ours or anyone else's.
- We do not use your code content to build features or improve the product experienced by other customers.
- We do not co-mingle your namespace with another tenant's, and we do not let one customer's recall read another's data.
- We do not sell, rent, or trade your personal data or your code.
- We do not mark up your model tokens or route your model traffic anywhere except to the provider whose key you supplied.
Important. Because Estelle is bring-your-own-key, the raw prompts and code your agent sends to your model provider are governed by their privacy terms, not ours. Choose a provider whose data policy you are comfortable with; Estelle never adds itself as a training recipient of that traffic.
Third-party processors
We use a small set of vetted infrastructure providers (sub-processors) to run Estelle. Each receives only the data it needs for its function. This list reflects the services actually integrated in the product today; the authoritative, dated list lives in the Data & Processing notice.
Your own model provider (Anthropic, OpenAI, Moonshot / Kimi, Google, DeepSeek, or any OpenAI-compatible endpoint) is reached with the key you provide and acts under your agreement with them, not ours. These providers process data primarily in the United States. Enterprise customers who need a signed Data Processing Addendum can request one at khai@fatelabs.ca.
How long we keep it
We keep data only as long as it is needed for the purpose it was collected:
- Account and billing records: for as long as your account is active, and afterward for up to seven years as needed to meet tax, accounting, and legal obligations.
- Derived memory and namespace data: until you delete it or close your account. Deleting a source or a namespace removes it from active storage promptly; residual copies in encrypted backups age out on our standard 30-day rotation.
- Operational logs: retained for a limited diagnostic window of about 90 days, then deleted or anonymized.
- Usage metadata used for product improvement: aggregated and anonymized; aggregate statistics may be retained indefinitely because they no longer identify you or your code.
Your rights & controls
You control your data. Estelle ships real mechanisms for each of these, not just a promise:
- Access & export: export your namespace's stored memory and facts. Estelle exposes a per-namespace export so your data is portable, not locked in.
- Correction: re-index a changed file to replace stale content, or update your account details in the dashboard.
- Deletion (right to be forgotten): remove a single source from every fact that referenced it (a right-to-be-forgotten cascade), clear a file, or delete an entire namespace. Closing your account deletes your namespaces.
- Opt out of product-improvement analytics: turn off the aggregated usage signals described in How Estelle improves itself. Metering needed to bill and to keep the service running continues, because it is required to provide the service.
To exercise any of these, use the dashboard controls or email khai@fatelabs.ca. We respond within a reasonable time and within any period required by applicable law.
Fate Labs is early-stage and does not currently offer region-specific privacy terms (such as EU/UK GDPR or California CCPA/CPRA disclosures); we will introduce them if and when we serve those regions. If a data-protection law that applies to you grants rights beyond those above, email us and we will honour what that law requires.
How we protect it
We follow established security best practices. Concretely, and verifiable in the product:
- Your provider key is encrypted on our side before it is written to the database, so the database only ever stores ciphertext, never the raw key.
- Data is scoped per namespace, and every stored query appends the tenant predicate at the data layer so it cannot be omitted by accident.
- Access to production is limited, traffic is served over TLS, and secrets live in a secret manager, never in source.
- The grounding gate treats your real code as the source of truth and refuses content injected into it, so memory cannot be poisoned into leaking or fabricating.
Note. We describe our practices honestly. We follow established security best practices, but no system is perfectly secure and we cannot guarantee absolute security. We do not currently claim any formal certification (for example SOC 2 or ISO 27001) or regulatory status (for example HIPAA, or PCI beyond Stripe's own scope). If and when we complete such a program, we will say so here with the report available.
If we ever become aware of a personal-data breach that affects you, we will notify affected customers and any regulators without undue delay, as required by applicable law, and describe what happened and the steps we are taking.
International transfers
Our infrastructure providers process data primarily in the United States. If you access Estelle from the EEA, the UK, or another region with cross-border transfer rules, using the service involves transferring your data to the United States, and we rely on appropriate safeguards for that transfer. If your organization requires a specific transfer mechanism (such as Standard Contractual Clauses) or a regional data-residency option, contact khai@fatelabs.ca.
Children
Estelle is a developer tool for professional use and is not directed to children. You must be at least 18 years old to use it. We do not knowingly collect personal data from anyone under 18; if we learn we have, we will delete it.
Changes to this policy
We may update this policy as the product and the law evolve. Material changes will be announced (for example, by email or an in-product notice), and the effective date at the top will change. Your continued use after a change takes effect means you accept the updated policy.
Contact
Privacy questions and data-rights requests: khai@fatelabs.ca. Estelle is operated by Honour Systems Inc. (incorporated in Ontario, Canada), doing business as Fate Labs.