Updated Sep 26, 2026

Data Processing Addendum

When your team uses Cactus, Cactus handles personal data for you: your teammates', and your customers' when they read your Help Center or write to you. This is what Cactus may do with it and what it owes you.

What this addendum is

It is part of the Terms of Service between Cactus Corp. and your company, and it applies whenever Cactus processes personal data for you. You do not need to sign anything for it to apply. If you need a copy signed by both of us, write to hello@heycactus.ai.

Where this addendum and the Terms disagree about personal data, this addendum is the one that counts.

Words it uses

  • Personal data: information about a person who can be identified, as data protection law defines it.

  • Your personal data: the personal data Cactus processes for you under the Terms.

  • Data protection law: every law about personal data that applies to that processing, such as the GDPR in the EU and the UK, PIPEDA in Canada, and the CCPA in California.

  • Subprocessor: a company Cactus uses that processes your personal data.

  • Security incident: a breach of security that leads to your personal data being lost, changed, disclosed, or reached by someone without permission.

Who decides

You decide why and how your personal data is processed, and Cactus processes it for you. In the words of the GDPR you are the controller and Cactus is your processor; in the words of the CCPA you are the business and Cactus is your service provider.

For its own records of who uses Cactus, such as your name and email as a Cactus user, Cactus decides for itself. The privacy page covers those.

What Cactus processes

  • Whose data: the people on your team; the people who read your Help Center, ask in the Messenger or use your public MCP address; the people in the conversations, channels and messages you connect; and the people named in the code and commits you connect.

  • What data: names and email addresses; the messages and conversations, and anything a person writes in them; the names of commit authors; a random id for each visitor's browser; the email address a visitor leaves when they ask for a person; IP addresses in request logs and sign-in records; and recordings of visits to the app and to Help Centers.

  • What for: to run Cactus for you and for nothing else, which means reading your sources, writing your pages and answers, answering your customers, and keeping Cactus secure.

  • Memory: when memory is on, Cactus keeps each person's earlier conversations with the product, readable only on that person's own conversations. A team owner can erase a person's memory at any time, and memory can be turned off for the product.

  • For how long: while you use Cactus, and after that for as long as the privacy page says for each kind of data.

  • Sensitive data: Cactus is not built for health records, payment card numbers, government ID numbers or other special categories of data, and the Acceptable Use Policy asks you not to connect them.

What Cactus does

  • Processes your personal data only on your instructions. The Terms, your settings and what you connect are those instructions. If we think an instruction breaks data protection law, we tell you.

  • Makes sure everyone at Cactus who can reach your personal data is bound to keep it confidential.

  • Protects it with the measures on the Trust Center, and keeps them up to date.

  • Helps you answer people who ask to see, correct or delete their data. Much of it you can do yourself: delete a page, a conversation or a product, or disconnect a source. For the rest, write to us.

  • Tells you without undue delay once we know of a security incident that affects your personal data: what happened, what it touches, and what we are doing about it. We keep you updated as we learn more.

  • Helps you, within reason, with a data protection impact assessment or a regulator's questions about Cactus.

  • Gives you the information you need to check that we keep this addendum, and answers your security questionnaires.

  • Deletes your personal data when you delete it, and when your account closes, as the privacy page says. Until then, you can ask us for a copy.

Subprocessors

You agree that Cactus uses these companies. Each receives only what it needs for its part, under data protection terms that protect your personal data at least as well as this addendum does.

  • Cloudflare runs the website, the app and every Help Center, and keeps a log of each request.
    Where: Worldwide (Cloudflare's network).

  • Microsoft Azure runs the server where Cactus reads your sources and writes pages and answers.
    Where: United States (East US 2, Virginia).

  • Restate runs Cactus's jobs, and keeps a record of each job's steps, including what each step read, for seven days.
    Where: United States (AWS us-east-2, Ohio).

  • Neon stores the database, including the search index of your code.
    Where: United States (AWS us-east-1, Virginia).

  • Convex carries live updates, including the words of an answer while it is being written.

  • Modal copies your repositories, builds the search index of your code, and runs the commands Cactus reads it with.
    Where: United States for stored copies; the sandboxes can run in any region Modal uses.

  • The Vercel AI Gateway carries every call Cactus makes to a model.

  • OpenAI runs the models that read your sources and write pages and answers, and the model that turns text into search vectors.

  • TypeSafe AI runs Jev, the model that makes some small decisions, such as whether your customers would notice a release.

  • Firecrawl reads your product's public website, to find its logo, its colours and its links, and fetches a public page for Cactus when a site turns a plain request away.

  • Resend sends our email, including the email your customers get when they write to your team.
    Where: United States.

  • PostHog records usage events, errors and recordings of visits to the app and to Help Centers, and keeps traces of model calls for debugging, which only Cactus's two founders can open.
    Where: United States (AWS us-east-1, Virginia).

  • Google and logo.dev supply the small logo shown beside a product's name. The browser asks them for it by the product's web address.

  • Google and GitHub sign you in, when you choose to sign in with them.

Before a new company starts receiving your personal data, we add it here and email your team's Owners. If you object on data protection grounds, tell us within 30 days and we will work it out with you. If we cannot, you may end the Terms for the part of Cactus the change touches.

Where the data is

Cactus Corp. is based in Vancouver, Canada. The database, the server that reads your sources and the records of Cactus's jobs are in the United States. The list above says where each company processes your data; where it names no place, we are still confirming it with that company.

When your personal data leaves the European Economic Area, the UK or Switzerland for a country the law does not already recognise as protecting it, the Standard Contractual Clauses apply between us, filled in by this addendum.

What you do

  • Have a lawful basis for the personal data you give Cactus, and tell the people it is about, for example in your own privacy notice.

  • Give Cactus only instructions that data protection law allows.

  • Keep your team's sign-ins safe, and choose with care who can see what.

Liability

What each of us owes the other under this addendum is limited as the Terms of Service say.

Contact

Write to hello@heycactus.ai about anything in this addendum. We reply within two business days.

Cactus Corp.
Based in Vancouver, Canada.


This page is a working draft. A lawyer has not reviewed it yet, and its words may change when one does. Questions about it go to hello@heycactus.ai.