ExecBound

ExecBound Privacy Notice

Effective September 22, 2026 · Version 2026-09-22.

Scope and contact

ExecBound LLC operates the ExecBound website and hosted Community service. This notice describes information used to provide those services. Contact justin.pitt@execbound.ai with privacy questions or requests about your information. Enterprise services may have additional agreements and notices.

Information we collect

When you request Community access, we collect your email address, its domain, the version of the terms/privacy notice you acknowledge, request timestamps, and information about whether the request was queued, invited, claimed, refused or expired. We record information needed to prevent duplicate requests and abuse.

When you claim or use a workspace, we process the tenant and account information you provide, authentication and session records, credentials stored in protected forms, settings, and activity generated by your use. Activity may include agent and resource identifiers, action arguments, policy decisions, approval decisions, execution results and audit records. Do not put personal, customer, employer or confidential production data into a hosted learning environment; use synthetic examples.

If you use a configured external sign-in provider, we process the identity information needed for that sign-in. If an optional assistant is enabled and you use it, your prompt and the selected record context may be sent to the configured AI provider to produce the requested explanation or proposal. Do not include sensitive information in prompts.

We also receive information you send in support messages. Hosting and security systems may process technical information such as request timestamps, IP addresses, browser information and operational logs. The marketing page does not embed advertising or third-party analytics scripts. The application uses cookies and related session mechanisms for sign-in, request protection and essential application functions.

Optional aggregate analytics

With consent, we collect page/CTA counts on the website and onboarding-event counts in the console. Collection is off until you accept. Change your website choice with Privacy preferences, or console choice in My account. Counts contain no visitor IDs, credentials, prompts or action contents. Storage inventory, fields and retention.

How we use information

We use information to respond to access requests, deliver invitations and service notices, establish accounts, operate the service, enforce limits, investigate failures or abuse, provide support, and understand whether people can successfully evaluate the product. Signup does not subscribe you to a separate marketing mailing list.

Sharing and service providers

The hosted deployment uses Render for application/static hosting and Supabase for PostgreSQL. Email and optional identity/AI providers depend on deployment configuration. Contact us for the current named provider list, locations and contractual details before sending regulated or production data. Unverified providers and regions are not represented as fixed.

Service providers process information as needed to host the service, store its data and backups, deliver email, and support configured sign-in or assistant features. Access depends on the function they provide; not every provider receives every category of information. We do not use the signup form to sell personal information or provide advertising audiences.

Tenant administrators can access information associated with their tenant according to the product's access controls. We may disclose information when required by law, to protect the service and people against abuse, or in connection with a business transaction subject to applicable obligations. We do not promise that information is never disclosed to anyone else.

Retention

The signup lifecycle worker schedules removal of the email address from a signup-request record 30 days after the request is refused or expires, or 90 days after it is claimed. Successful cleanup depends on the scheduled worker running. Domain names, timestamps and funnel records remain after that address field is cleared.

That cleanup does not delete your account, correspondence, tenant activity, hosting logs or backup copies. Those records are handled separately for operating the service, security, support and applicable legal obligations. Community access is persistent; the sleeping of inactive agents does not delete the tenant or its history. Persistence does not promise indefinite storage or unlimited hosted resources. Contact us to request access, correction, account closure or deletion; we will explain the applicable process and any information we must retain.

Security and your choices

We use access controls and other safeguards to protect information. No service can guarantee absolute security. Keep sign-in links and credentials private and notify us if you believe an account is being misused.

You can choose not to request access, stop using the service, and contact us about your information. Available privacy rights depend on applicable law. We may need to verify your identity and authority before acting on a request, including where a request concerns an organization-managed tenant. The public evaluation is intended for adults acting for business purposes, not children.

Changes

The effective version of this notice is identified above. If practices change materially, we will provide notice appropriate to the change and applicable requirements. Recorded signup acceptance identifies the version shown for that request.