Legal

Privacy Policy

We collect the minimum data we need to run the platform, we do not sell your data and you can request export or deletion at any time. This policy explains what we collect, how we use it and the rights you have.

Last updated April 2026

Scope

This policy describes how Recursiv Labs, Inc. ("Recursiv," "we") collects, uses, and shares information when you use the Service, our website, and related products. It applies to people who sign up for and use Recursiv directly. If you are using an application that is built on Recursiv, the operator of that application is the controller of your data and their privacy policy applies; this policy then describes how Recursiv handles that data on their behalf as a processor.

What we collect

Account information: email address, name if provided, authentication identifiers, and profile fields you submit. Usage and telemetry: API calls, compute time, storage volume, IP address, browser and device metadata, log entries, and platform actions taken. Billing information: handled by our payment provider Stripe; we store only the minimum required for invoicing (card brand, last four digits, billing address, tax info). Project data: code, chat messages, memory entries, agent configurations, integrations, and uploads you create on the Service. Communications: support emails, sales conversations, and feedback you send us. We do not sell your data.

How we use information

We use your information to operate, maintain, and secure the Service; to bill you accurately; to provide customer support; to detect, prevent, and respond to abuse, fraud, and security incidents; to comply with legal obligations; and to improve the product through aggregated analytics. Agent interactions and project data are private to your account and organization by default. We do not use Customer Content to train foundation models.

Legal bases (EU/UK)

For users in the European Union, United Kingdom, and Switzerland, we process personal data on the following legal bases: contract (to deliver the Service you signed up for), legitimate interests (to secure and improve the Service, prevent fraud, and operate our business), consent (where we have asked for it, e.g., optional marketing emails), and legal obligation (to comply with applicable law).

Who we share with

We share information with subprocessors who help us run the Service under contracts that require them to protect your data. The current subprocessor list is published at recursiv.io/subprocessors and includes hosting, storage, payment, AI inference, integration, email, and analytics providers. We may share information in connection with a merger, acquisition, financing, reorganization, or sale of assets, in which case continued protection of personal data will be required of the successor. We disclose information to law enforcement only when legally required and will challenge overly broad requests.

International data transfers

Recursiv is based in the United States and processes data in the U.S. and other regions where our subprocessors operate. When we transfer personal data from the European Economic Area, United Kingdom, or Switzerland to a country that has not received an adequacy decision, we rely on Standard Contractual Clauses approved by the European Commission and equivalent UK and Swiss instruments, and we apply additional safeguards where required.

Data retention

We retain account, billing, and core platform data for as long as your account is active. After account deletion, we retain limited records (such as billing history, audit logs, and abuse signals) for up to seven years to meet legal, tax, and security obligations. Project data is retained per your plan and your retention settings; on account closure, project data is deleted within 30 days unless you request earlier deletion or longer retention is required by law.

Your privacy rights

Subject to applicable law, you have the right to access, correct, export, restrict, and delete your personal data, and to object to or withdraw consent to certain processing. To exercise any right, email founders@recursiv.io. We will respond within the time frame required by applicable law (typically 30 days, with extensions as permitted). You also have the right to lodge a complaint with your local data protection authority.

California residents (CCPA/CPRA)

If you are a California resident, you have the right to know what personal information we collect, the categories of sources and recipients, and the purposes of collection; to request deletion of your personal information; to correct inaccurate personal information; to opt out of any sale or sharing of personal information; and to limit use of sensitive personal information. We do not sell or share personal information for cross-context behavioral advertising. To exercise California rights, email founders@recursiv.io. We will not discriminate against you for exercising these rights.

EU/UK/Swiss residents (GDPR)

If you are in the EU, UK, or Switzerland, you have the rights described under "Your privacy rights" above plus the right to data portability and the right to object to processing based on legitimate interests. The Recursiv contact for data protection inquiries is founders@recursiv.io. We do not currently appoint a Data Protection Officer; one will be appointed if and when required by law.

Cookies and analytics

We use a small number of first-party cookies to keep you signed in, remember preferences, and measure product usage. We do not use advertising cookies and do not allow third-party advertising trackers. You can disable cookies in your browser; some features will not work. We use privacy-respecting analytics tools to understand aggregate product usage; identifiable analytics events are tied to your account only when needed for product or security purposes.

Security

We encrypt data in transit (TLS 1.2+) and at rest (AES-256 or equivalent). We scope API keys to the minimum permissions required, log and audit platform actions, and follow the security policies published in our internal compliance program (HR security, access control, change management, encryption, vendor management, logging, risk assessment). If we learn of a material security incident affecting your data we will notify you without undue delay and in any event within the time frame required by applicable law.

Children’s privacy

The Service is not directed to children under 13 (or under 16 in the EU/UK), and we do not knowingly collect personal information from children. If you believe a child has provided personal information to us, contact founders@recursiv.io and we will delete it.

Changes to this policy

We may update this policy. Material changes will be announced in the product and by email to the address on file. Older versions are available on request. Your continued use of the Service after changes take effect constitutes acceptance of the updated policy.

Contact

Privacy questions can be sent to founders@recursiv.io. Postal mail can be sent to Recursiv Labs, Inc., legal department, at the address listed on the website.

Terms of Service →

Acceptable Use Policy →

Data Processing Addendum →

Subprocessors →

Email the founders

Build, run and govern autonomous agents. Everything you need in one SDK, connected to your data, tools and systems.

Products

Apps

Agents

Integrations

Orchestration

Memory

Automation

Identity

Verification

Observability

Use cases

Build an app

Add agents to your app

Put agents to work

Hire our team

Enterprise

Developers

Docs

SDK

MCP

REST API

GitHub

Company

About

Built on Recursiv

Book a demo

Pricing

FAQ

Privacy

Terms

Accessibility

© 2026 Recursiv Labs, Inc.

Built on Recursiv.

Questions? hello@recursiv.io. See also our Terms of Service.