Cortya

Privacy Policy

Last revised July 29, 2026

This policy explains what Cortya ("Cortya," "we," "us," or "our") stores when you use Cortya, why, and who processes it on our behalf. Cortya is deliberately data-minimal: we store what is needed to run analytics for your organization and nothing more.

What we store

DataWhy
Account email addressSign-in (magic-link / one-time code) and service notifications.
Subscription status & plan tierTo grant access to paid features. Payment card details are handled by Stripe — we never see or store your full card number.
Usage & cost snapshots derived from your Anthropic organizationThe analytics and governance findings that are the product — token counts, USD cost, and metadata bucketed by day, model, workspace, and key.
A reference to your encrypted Anthropic Admin keyTo read your usage on your behalf. The key itself is stored encrypted in a vault, not in our application database — see below and our Security page.
Operational logsSecurity and reliability. Logs are scrubbed of secrets — your Admin key is never written to a log.

Your Anthropic Admin key

The Admin key is the most sensitive thing you entrust to us, and we treat it that way. It is stored encrypted in Azure Key Vault, server-side only. It is decrypted transiently in server memory solely to call Anthropic's Usage & Cost APIs, is never returned to your browser, never logged, and never shared with any third party or other customer. Our application database holds only a pointer to the vaulted secret plus the last four characters for display. Full details are on our Security & key-custody page.

How we use data

We use your data only to operate Cortya for you: to authenticate you, to fetch and present your usage and governance analytics, to bill your subscription, and to keep the service secure and reliable. We do not sell your data, we do not use it to train models, and we do not use one customer's data to serve another.

Sub-processors

We rely on the following processors to run the service. Each receives only the data needed for its function:

Retention, deletion, and revocation

You can revoke your Anthropic Admin key at any time from your dashboard (or by rotating it in your Anthropic account); revocation immediately stops all further access and removes the stored key material. On account closure we delete your account data and derived usage snapshots within a reasonable period, except where we must retain limited records to meet legal or accounting obligations. To request deletion or a copy of your data, contact us.

Security

We protect data with encryption in transit and at rest, tenant isolation, least-privilege access, and secrets kept out of source and logs. See our Security page for the key-custody model.

Changes

We may update this policy from time to time and will post the updated version here with a new date.

Contact

Privacy questions or data requests: hello@cortya.com.