Privacy Policy
Last updated: 2026-06-23
Salty is an agent-first CRM: a REST API, MCP server, and CLI that let you and your AI agents manage customer data. This policy explains what we collect, how we use and share it, and the choices you have.
Who we are
Salty (“we”, “us”) provides the Salty service at trysalty.com, including the API, MCP server, CLI, webhooks, and admin web app. For workspace CRM data you submit, you are the data controller and we are your processor; for account and billing data, we are the controller.
Information we collect
Account data — your email and workspace name (via Supabase Auth), and billing identifiers returned by our payments provider. Workspace content — the CRM records you or your agents create: people, companies, deals, notes, tasks, activities, custom objects, and any attributes you define. Usage and technical data — API request logs (timestamp, route, method, status, which key/token was used), rate-limit and quota counters, and webhook delivery records, used for operating the service, billing, and abuse prevention. We do not collect or store payment card numbers (see Payments).
How we use information
To provide and secure the service, authenticate requests, enforce plan limits and rate limits, deliver webhooks, process payments, provide support, and comply with legal obligations. Where the GDPR applies, our legal bases are performance of a contract (operating your workspace), legitimate interests (security, abuse prevention, product analytics), consent (where required), and legal obligation.
AI and model training
We do not sell personal data, and we do not use your workspace CRM data to train machine-learning models. Your data is used to run your workspace and the features you request.
Payments
Payments are processed by Dodo Payments, which acts as the Merchant of Record and is the seller of record for your subscription. Dodo collects and processes your payment method and billing details (including the billing country/zip needed to calculate tax) under its own privacy policy. We receive only non-card billing identifiers and subscription status — we never see or store full card details.
Subprocessors
We rely on the following providers to deliver the service:
- Supabase — database, authentication, and storage (United States).
- Dodo Payments — payment processing and Merchant of Record.
- Amazon Web Services (SES) — transactional email (United States).
- Railway — hosting for the API and MCP server (United States).
- Vercel — hosting for the web app, and Cloudflare for DNS and network.
- Mintlify — documentation hosting.
- Sentry, PostHog, Axiom, and Better Stack — error monitoring, product analytics, logging, and uptime, where enabled. These receive operational metadata (e.g. event names, workspace identifiers, error traces), not your CRM record contents.
Data retention
We retain workspace content for as long as your workspace is active. API usage logs and webhook delivery records are retained for a limited period for security, billing, and troubleshooting. When you delete a record it moves to a recoverable trash for 30 days and is then permanently purged. When you delete your workspace, we immediately revoke its API keys and tokens and remove the corresponding data from our primary systems; residual copies may persist briefly in backups before being overwritten.
International transfers
Our infrastructure is primarily in the United States. If you access Salty from outside the US, your data will be transferred to and processed in the US and other countries where our subprocessors operate, with appropriate safeguards where required.
Security
We encrypt data in transit (TLS) and rely on our infrastructure providers’ encryption at rest. Access is scoped per workspace, credentials are stored hashed, and webhooks are signed. See our Security page for details and how to report a vulnerability.
Your rights and choices
You can export your full workspace data at any time — one click from the dashboard, or GET /workspace/export via the API — and delete your entire workspace yourself from the dashboard. You can also request correction or deletion by contacting us. Depending on where you live, you may have rights to access, port, correct, delete, or restrict processing of your personal data (GDPR), or to know about and delete personal information and opt out of “sale”/“sharing” (CCPA/CPRA) — note that we do not sell personal data. To exercise any right, contact privacy@trysalty.com.
Children
Salty is not directed to children under 16, and we do not knowingly collect their data.
Changes to this policy
We may update this policy as the service evolves. We will revise the “Last updated” date above and, for material changes, provide additional notice.
Contact
Privacy questions and requests: privacy@trysalty.com.