Legal Documentation

Logsmith Privacy Policy

Last updated: August 18, 2026

This Privacy Policy explains how Logsmith Inc., a Delaware corporation ("Logsmith", "we", "us"), collects, uses, and shares personal information. It applies to our website at logsmith.ai, our web application, and our sales, support, and marketing activities.

Logsmith is a software service that investigates production alerts across a customer's observability tools, delivers a root-cause analysis with its supporting evidence, and opens a pull request with a proposed fix in the customer's repository.

1. The Two Roles We Play

We handle two very different kinds of data, and this policy covers only one of them.

Data we control. For visitors to our website, people who create accounts, and people we communicate with in sales and support, we decide how and why personal information is used. This policy describes that processing.

Data we process for our customers. When a customer connects their systems to Logsmith, the Service accesses their telemetry — logs, metrics, traces, alerts, source code, and configuration ("Customer Data"). Customer Data belongs to the customer. We process it only on the customer's behalf and instructions, to provide the Service, under our Terms of Service and, where in place, a data processing agreement or signed customer agreement. This policy does not govern Customer Data.

Customer Data may incidentally contain personal information — for example, names, identifiers, or contact details appearing inside application logs. If your personal information reached us inside a customer's telemetry, the customer is responsible for that data, and you should direct requests about it to them; we will refer any request we receive to the relevant customer and support them in responding.

2. Information We Collect

You provide it:

  • Account information — name, business email address, company name, role, and password (stored in hashed form) when you create an account.
  • Billing information — company billing details, tax identifiers, and transaction history. Card and bank details go directly to our payment processor, Stripe; we do not receive or store full card numbers.
  • Communications — the contents of emails, support requests, sales conversations, and demo bookings.

Collected automatically:

  • Usage information — actions taken in the web application, features used, and log records of access, collected to operate and secure the Service.
  • Device and connection information — IP address, browser type, operating system, and referring pages, collected when you visit our website or use the application.
  • Cookies and similar technologies — as described in Section 6.

From other sources:

  • Business contact information from public sources (such as LinkedIn or a company website) or from an introduction, used for sales outreach to engineering teams.

We do not collect special categories of personal information, and we do not want them — please do not include sensitive personal details in support requests.

3. How We Use Information

We use the information in Section 2 to:

  • provide, operate, and secure the website and the Service, including authentication, access control, and abuse prevention;
  • set up and manage accounts, subscriptions, invoicing, and payments;
  • respond to support requests and communicate about the Service, including service and security notices;
  • conduct sales and marketing to businesses, including outreach and product updates (with an unsubscribe in every marketing email);
  • understand how the website and application are used, so we can improve them;
  • comply with law, enforce our agreements, and establish or defend legal claims.

Where the GDPR or similar laws apply, our legal bases are: performance of a contract (accounts, billing, support), legitimate interests (security, B2B sales and marketing, product improvement), consent where required (non-essential cookies, and marketing where consent is the required basis), and legal obligation (tax and accounting records).

We do not sell personal information, and we do not share it for third-party advertising. We do not use Customer Data to train or improve any machine-learning or artificial-intelligence model, ours or anyone's.

4. How We Share Information

We share personal information only with:

  • Service providers that support our business — hosting, payment processing (Stripe), email and communications, analytics (Google Analytics), marketing and sales tooling (HubSpot), and customer support tooling — under contracts limiting their use of the information to providing services to us. Our current subprocessors for the Service are listed on our subprocessor page.
  • Professional advisers — lawyers, accountants, and auditors, under confidentiality obligations.
  • Authorities, where disclosure is required by law or legal process; where lawful and practicable, we will notify you before disclosing.
  • A successor entity, if we are involved in a merger, acquisition, financing, or sale of assets, in which case this policy continues to apply to information transferred.

5. International Transfers

We are a US company, and personal information we control is processed in the United States and in other countries where our personnel and service providers operate. Where we transfer personal information from a jurisdiction that restricts international transfers, we rely on lawful transfer mechanisms — for the EEA and UK, standard contractual clauses where required.

Storage locations for Customer Data are a matter for the Terms of Service and each customer agreement, not this policy.

6. Cookies

Our website uses:

  • Essential cookies — required for the site and application to function, including session and authentication cookies. These cannot be switched off.
  • Analytics cookies — set by Google Analytics, which we use to understand how the website and application are used (pages visited, approximate location, device type). Google processes this data on our behalf.
  • Marketing and CRM cookies — set by HubSpot, which we use to recognize returning visitors and connect website activity with our sales and marketing records, so that our communications with you are informed by your interactions with us.

Where the law of your location requires it (for example, in the EEA or UK), we set analytics and marketing cookies only with your consent, which you can give, refuse, or withdraw through the cookie banner. We do not use cookies for third-party advertising or cross-site ad targeting.

7. Retention

We keep personal information only as long as needed for the purposes above:

  • Account information — for the life of the account, then deleted or anonymized within 90 days of account closure, except records we must keep for tax, accounting, or legal purposes.
  • Billing records — for the period required by tax and accounting law.
  • Sales and marketing contacts — until you opt out or the information is no longer useful, whichever is sooner.
  • Support communications — for 12 months after resolution, or longer where needed for an ongoing dispute or legal claim.

Customer Data retention is governed by the Terms of Service (raw Customer Data no longer than 90 days from ingestion; deletion within 30 days of termination).

8. Security

We protect personal information with technical and organizational measures including encryption in transit and at rest, role-based access controls, multi-factor authentication on administrative access, logging of access to production systems, and storage of credentials and secrets in a dedicated secrets manager. No system is perfectly secure, and we cannot guarantee absolute security; if we become aware of a breach affecting your personal information, we will notify you and any required regulator as applicable law requires.

9. Your Rights

Depending on where you live, you may have rights to access, correct, delete, or receive a copy of your personal information, to object to or restrict certain processing, and to withdraw consent where processing is based on consent.

  • If you are in India, the Digital Personal Data Protection Act, 2023 gives you rights of access, correction, and erasure, and the right to grievance redressal.
  • If you are in the EEA or UK, you have the rights under the GDPR / UK GDPR listed above, and the right to complain to your supervisory authority.
  • Everyone, regardless of location, can ask us what we hold about them and ask us to correct or delete it; we extend these rights as a matter of practice, not only where a statute compels it.

To exercise any right, email [email protected]. We will respond within the time applicable law requires, and in any case within 30 days. We may need to verify your identity first. If your request concerns personal information inside a customer's telemetry, Section 1 applies — we will refer it to the customer.

You can opt out of marketing email at any time via the unsubscribe link or by emailing [email protected]; service and security notices are not marketing and continue while you hold an account.

10. Children

Our website and Service are for business use and are not directed at anyone under 18. We do not knowingly collect personal information from children; if you believe a child has provided us personal information, contact [email protected] and we will delete it.

11. Changes to This Policy

We may update this policy from time to time. We will post the updated version at this URL with a revised "Last updated" date and, for material changes, notify account holders by email or in-product notice before the change takes effect.

12. Contact

Logsmith Inc.
2810 N Church St, STE 89321
Wilmington, DE 19802, USA
[email protected]