salty

Your data, your control

Last updated: 2026-06-23

Salty lets AI agents read and write your CRM, so trust is the product. Here, in plain language, is how we keep your data safe and yours.

We never train on or sell your data

Your CRM records are used to run your workspace and the features you ask for — nothing else. We don’t use your data to train machine-learning models, and we don’t sell personal data. Ever.

Agents can’t permanently delete anything

When you (or an agent) delete a record, it goes to a 30-day trash, not the void — one click restores it. There are deliberately no agent tools that hard-delete. So you can let an agent run on your CRM without fear of it wiping your contacts.

Hand out look-but-don’t-touch keys

Create a read-only API key for any agent or tool that should only read your data. It can list and look, but every write is refused. Least privilege, one checkbox.

Export everything, anytime

One click downloads a complete JSON export of your workspace — people, companies, deals, notes, tasks, activities, custom objects, and your schema. No tickets, no waiting. Your data is portable because it’s yours.

Delete everything, anytime

Close your account from the dashboard with a type-to-confirm. We immediately revoke every key and token and schedule your data for removal — no “contact us to cancel” dark patterns.

Solid security by default

Everything runs over TLS; data is encrypted at rest. API keys are hashed (argon2), OAuth uses 2.1 + PKCE, every query is scoped to your workspace, and webhooks are signed. Card details are handled by our payments provider — we never see them. Details and how to report an issue are on our Security page; the full data practices are in our Privacy Policy.