← Back to Graphite

This policy explains how Graphite — the managed OneCLI gateway service operated by Carbono Dev ("we", "us") — accesses, uses, stores and shares information, including data received from Google APIs. It applies to the Graphite web dashboard and gateway at graphite.carbonodev.com and to this website.

1. Who we are

Carbono Dev is a technology transformation and AI engineering firm. Graphite is our managed deployment of OneCLI, an open-source gateway that stores API credentials on behalf of customers and injects them into outbound requests made by their AI agents, so that the agents themselves never hold the credentials.

Controller Carbono Dev
Service Graphite (graphite.carbonodev.com)
Privacy privacy@carbonodev.com
General https://carbonodev.com/contact

2. Google user data

Graphite offers Sign in with Google as an authentication option. It is the only way we receive data from Google APIs.

What we access

When you sign in with Google, we request these OAuth scopes and nothing more:

  • openid — your Google account identifier.
  • email — your email address and whether it is verified.
  • profile — your name and profile picture.

We do not request access to Gmail, Google Drive, Calendar, Contacts, or any other sensitive or restricted scope.

How we use it

  • To create and authenticate your Graphite account.
  • To display your name, email and picture in the dashboard so your teammates can see who did what.
  • To attribute entries in the audit log — which person created, changed or revoked a credential, agent or policy.
  • To contact you about the service (security notices, incidents, scheduled maintenance).

How we store it

Your Google account identifier, name, email address and profile picture URL are stored in your Graphite instance's database, encrypted at rest. Session cookies are signed and scoped to the Graphite domain. We do not store your Google password, and we do not retain Google OAuth refresh tokens beyond what is needed to keep your session valid.

How we share it

We do not sell your data and we do not share it with third parties for advertising. Google user data is shared only with the infrastructure providers that host your Graphite instance, acting on our instructions under contract, and where we are legally required to disclose it.

Limited Use disclosure. Graphite's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Revoking access

You can revoke Graphite's access to your Google account at any time from your Google account permissions page. Revoking access prevents future sign-in; to delete the account data we already hold, see Retention and deletion below.

3. Customer credentials stored in the vault

The core purpose of Graphite is to hold API credentials that you choose to store — for example a Stripe key, a GitHub token, or a Google Cloud service account key. These are your credentials for third-party services, not data we receive from Google APIs about you.

  • Secrets are encrypted at rest with AES-256-GCM using a key held by your instance.
  • They are decrypted only in the gateway process, at the moment a matching request is proxied.
  • They are never written to the agent, to prompts, or to logs; audit records reference a credential by name and never by value.
  • Carbono Dev personnel do not access stored secret values in the course of normal operations. Any exceptional access is limited, logged, and governed by your engagement agreement.

4. Service and request data

To operate the gateway we process:

  • Audit events — who created, changed or deleted a credential, agent, grant or policy, and when.
  • Proxy metadata — which agent called which host and path, the response status, and the latency. Request and response bodies are not stored.
  • Operational telemetry — error rates, health checks and infrastructure logs used to keep the service available.

5. This website

graphite.carbonodev.com is a static marketing page. It sets no advertising or tracking cookies and runs no third-party analytics. Web fonts are loaded from Google Fonts, which receives your IP address as part of that request. Standard server access logs are kept by our hosting provider for security and abuse prevention.

6. Legal bases

Where the GDPR applies we process personal data on the basis of performance of a contract (operating the service you or your employer engaged us for), our legitimate interests (securing and improving the service), and legal obligations.

7. Retention and deletion

Account data is retained for as long as your Graphite instance is active. Audit and proxy metadata are retained for the period agreed in your engagement, and deleted afterwards. On termination we delete or return your vault contents and logs on request, and destroy backups on their ordinary rotation schedule.

To request access to, correction of, or deletion of your personal data, write to privacy@carbonodev.com. We respond within 30 days.

8. Your rights

Depending on where you live, you may have the right to access, correct, delete, port or restrict the processing of your personal data, and to object to it. You may also lodge a complaint with your local data protection authority.

9. Security

We encrypt data in transit (TLS) and at rest, isolate each customer's gateway and database, restrict administrative access, and keep an audit trail of state changes. No system is perfectly secure; if a breach affects your data we will notify you without undue delay and in line with applicable law.

10. International transfers

Your Graphite instance runs in the region you choose. Where data is transferred outside that region — for example to a support tool — we rely on appropriate safeguards such as the EU Standard Contractual Clauses.

11. Children

Graphite is a business service and is not directed to children under 16.

12. Changes to this policy

We will update this page when our practices change and revise the "last updated" date above. Material changes affecting Google user data will be communicated to account holders by email before they take effect.

13. Contact

privacy@carbonodev.com
https://carbonodev.com/contact