Legal
Privacy Policy
This policy explains what personal data Caminu collects when you use our service, what we do with it, who we share it with, and the choices you have. We follow Singapore's Personal Data Protection Act 2012 (the PDPA), the EU General Data Protection Regulation (the GDPR), the UK GDPR, and the California Consumer Privacy Act / California Privacy Rights Act (the CCPA / CPRA) where they apply to you.
The short version
- We collect the data you give us (account, billing, briefs, connected-app credentials), data your usage generates (logs, device, telemetry), and the content your coworkers produce.
- We use it to run the service, support you, bill you, keep things secure, and improve features.
- We do not sell your personal data and we do not use your content to train foundation models for anyone else's benefit.
- We share data only with the subprocessors we need to run the service (listed below) and where the law requires.
- You can access, correct, export, or delete your data at any time — see Your rights.
Who we are
In plain English
Caminu Pte. Ltd., a Singapore-incorporated private company, is the data controller.
The data controller (under GDPR) and organisation responsible (under PDPA) is Caminu Pte. Ltd., a private company limited by shares incorporated in Singapore.
We have appointed a Data Protection Officer ("DPO") as required by the PDPA. You can reach the DPO at dpo@caminu.com.
What we collect
In plain English
Account info, things you send to coworkers, the apps you connect, how you use Caminu, and payment info handled by our processor.
Information you give us directly
- Account — name, email address, password (hashed), workspace name, optional profile picture.
- Briefs and content — the briefs, prompts, messages, files, and other inputs you submit to coworkers, and the outputs they generate.
- Connected-service authorisations — OAuth tokens, API keys, or other credentials you provide so coworkers can access apps you connect (e.g. Gmail, Stripe, Notion, WhatsApp). We do not see your password for those services — we store short-lived tokens that grant scoped access.
- Billing — name on card, billing address, and country. We do not store full card numbers — they are handled directly by Stripe.
- Support — anything you tell us when you contact support.
Information we collect automatically
- Service logs — events your account generates (sign-in, coworker created, task started, task completed), timestamps, and request metadata.
- Device and connection — IP address, user agent, device type, approximate location derived from IP, language preference.
- Traces — for each coworker run we keep a step-by-step trace so you (and we, for support and abuse investigation) can audit what happened.
- Telemetry — aggregate performance, error, and usage metrics needed to keep the service reliable.
Information from third parties
- Data your coworker reads from a Connected Service in the course of performing the work you briefed (e.g. the emails it triages, the invoices it categorises).
- Limited profile information from identity providers if you sign in with one (e.g. Google).
Why we collect it
In plain English
To run Caminu for you, support you, bill you, keep it secure, improve it, and meet legal duties.
- To provide the service — create accounts, build and run coworkers, connect to third-party apps, generate outputs, send notifications.
- To support you — respond to your questions, investigate issues, recover lost work.
- To bill you — process payments, send invoices, calculate usage, recover unpaid amounts.
- To keep things secure — detect and prevent fraud, abuse, bot activity, and security incidents; protect the rights and safety of users and others.
- To improve the service — understand which features are used, fix bugs, build new capabilities, train internal evaluation and abuse-detection models on aggregated/anonymised signals.
- To communicate — send service updates, security alerts, billing notices, and (only with your consent or where legally permitted) product-news emails you can opt out of any time.
- To comply with law — respond to lawful requests, meet tax and accounting requirements, enforce our terms.
How AI handles your data
In plain English
Your data goes to AI providers to do the work you briefed. They process it on our instruction and don't use it to train their public models.
To run a coworker, Caminu transmits relevant portions of your briefs, prompts, and connected-service data to large-language-model providers (currently Anthropic and OpenAI, accessed via the Vercel AI Gateway, with provider choice depending on the task). Those providers act as our subprocessors, are bound by contract to process your data only on our documented instructions, and have committed to zero data retention on the API tier we use — meaning your inputs and outputs are not stored by the provider after the request completes and are not used to train their general models.
We do not use your Content or Outputs to train foundation models owned by Caminu or by any third party for the benefit of other customers. We may use aggregated, de-identified signals (e.g. error rates, latency, abuse patterns) for service operations.
Lawful basis for processing (GDPR)
In plain English
If you're in the EU/EEA or UK, here's why we're allowed to process your data.
| What we do | Lawful basis |
|---|---|
| Provide the service you asked for | Performance of a contract (Art. 6(1)(b)) |
| Bill you and recover payment | Contract, and our legitimate interests (Art. 6(1)(f)) |
| Keep the service secure, detect abuse | Legitimate interests (Art. 6(1)(f)) |
| Improve the service using aggregated signals | Legitimate interests (Art. 6(1)(f)) |
| Send service emails (security, billing) | Contract |
| Send product-news emails | Consent (Art. 6(1)(a)) — withdrawable any time |
| Comply with tax, audit, or court orders | Legal obligation (Art. 6(1)(c)) |
International transfers
In plain English
Our service is global. Your data may be processed outside your country, under safeguards approved by law.
Caminu is operated from Singapore, with hosting and subprocessors in the United States, the European Union, and other regions. Where we transfer personal data from Singapore, the EU/EEA, the UK, or Switzerland to a country that has not received an adequacy decision, we rely on:
- Standard Contractual Clauses (EU SCCs, UK Addendum, Swiss SCCs as applicable) with each affected subprocessor;
- Comparable contractual safeguards required by the PDPA for transfers from Singapore (Section 26);
- Additional measures (encryption in transit and at rest, access controls, minimisation) where appropriate to the risk.
You can request a copy of the transfer safeguards in place at dpo@caminu.com.
How long we keep it
In plain English
As long as your account is active, plus a short tail for backups and legal duties. Then we delete or anonymise.
| Category | Retention |
|---|---|
| Account data | Until you delete your account, plus up to 30 days in backups |
| Coworker briefs, traces, outputs | Until you delete them, plus up to 30 days in backups |
| Service logs (security, abuse) | Up to 12 months |
| Billing & tax records | As required by Singapore tax law (up to 7 years) |
| Support tickets | Up to 24 months after resolution |
| Marketing email subscriptions | Until you unsubscribe |
After the relevant period we delete or anonymise the data. Where deletion is technically infeasible (e.g. immutable backups), we isolate and protect it until deletion is possible.
Your rights
In plain English
You can ask us to show you, correct, export, delete, or stop using your data. We'll respond within the legal time limit.
You have the right to:
- Access a copy of your personal data we hold;
- Correct inaccurate or incomplete data;
- Delete your data (subject to legal retention obligations);
- Export your data in a portable format;
- Restrict or object to certain processing where grounded in our legitimate interests;
- Withdraw consent at any time for processing based on consent (this does not affect prior processing);
- Lodge a complaint with a supervisory authority — in Singapore, the Personal Data Protection Commission (pdpc.gov.sg); in the EU/EEA, your local data-protection authority; in the UK, the Information Commissioner's Office.
California residents (CCPA / CPRA)
You have additional rights to know the categories of personal information collected, to delete personal information, to correct inaccurate information, to opt out of "sale" or "sharing" (we do neither), and to non-discrimination for exercising these rights. Authorised agents may submit requests on your behalf with verifiable permission.
To exercise any right, email dpo@caminu.com. We may need to verify your identity before responding and will reply within the time limit set by the applicable law (typically 30 days, extendable where the law allows).
Security
In plain English
Encryption in transit and at rest, scoped access, regular audits. No system is perfectly secure; we'll tell you if something material happens.
We implement administrative, technical, and physical safeguards including:
- TLS 1.2+ for data in transit and AES-256 for data at rest;
- Role-based access controls and least-privilege principles for internal access;
- Strong-authentication for our staff;
- Audit logging, monitoring, and intrusion-detection on production systems;
- Isolation of each customer's coworkers and data;
- Regular security reviews of code, infrastructure, and subprocessors;
- Documented incident-response procedures and (where the PDPA, GDPR, or other law requires) breach notification within the legally mandated time frame.
No service is perfectly secure. If you discover a vulnerability, please report it to security@caminu.com.
Children
In plain English
Caminu is not for children. We don't knowingly collect data from anyone under 18.
Caminu is intended for use by adults (18+). We do not knowingly collect personal data from children under the age of 18. If you believe we have inadvertently collected such data, contact dpo@caminu.com and we will delete it promptly.
Changes to this policy
In plain English
We may update this policy. If we make a material change, we'll let you know before it takes effect.
We may revise this Privacy Policy from time to time. If we make a material change, we will notify you in-app or by email at least 30 days before it takes effect. Non-material changes (e.g. clarifying language, restructuring) take effect when posted. The "last updated" date at the top of this page indicates the most recent revision.
Contact
In plain English
Get in touch about anything privacy-related.
Caminu Pte. Ltd. (Singapore).
- Data Protection Officer: dpo@caminu.com
- General privacy questions: privacy@caminu.com
- Security disclosures: security@caminu.com
In Singapore you may also lodge a complaint with the Personal Data Protection Commission at pdpc.gov.sg.