Legal
Privacy policy
How Potion handles account, commerce, security, analytics, publishing, and support data with bounded retention.
Potion processes the minimum data needed to provide accounts, publishing, purchases, security, and support. This policy describes the major categories and controls.
Data we process
Account identifiers, verified email status, publishing records, orders and entitlement state, security events, and support correspondence. Payment card details remain with the payment provider. Analytics use hashed actors, deduplicated buckets, and allowlisted metadata.
Security and retention
Credentials are hashed or encrypted as appropriate. Audit logs exclude passwords, tokens, keys, payment details, and raw MCP secrets. Records are retained only for product, security, accounting, and lawful obligations.
Your choices
You can review sessions, revoke API keys and devices, manage notification subscriptions, and request account assistance at privacy@potion.sh.