Updated Sep 26, 2026

Privacy

Cactus reads the sources a team connects. This page says what we hold, what we do with it, how long it stays and who else touches it.

What we collect

  • Your account. The name and email on the account you sign in with.

  • The sources an owner connects to a product: code repositories, a help site, Intercom conversations, and Slack channels the owner picks.

  • Messages people send to Cactus on Slack and on Discord.

  • Conversations people have with Cactus, including the ones a visitor starts on a published Help Center without an account.

  • Usage events and errors: which pages get opened, which questions get asked, and whether an answer worked.

Some of what reaches us is never used. Slack sends an event for every message in a workspace where Cactus is installed. We keep only the messages from channels an owner picked, and the rest are dropped without being stored. On Discord we keep only the messages addressed to Cactus.

How we use it

We use it to answer questions and write pages for that product. That is the whole list. Cactus does not train models on it, it is not sold, and it is not handed to anyone for advertising.

How long we keep it

  • Slack channel messages: a rolling 90 days. Remove the channel, or disconnect Slack, and everything from it is deleted.

  • Discord messages: only the ones addressed to Cactus, kept with the conversation they belong to and deleted when it is.

  • Conversations and the pages Cactus writes: until the owner deletes them, or closes the account.

  • What we read from a repository, a help site or Intercom: for as long as that source is connected to a product. Delete the product and it goes with it.

  • Your account name and email: until the account is closed.

  • Usage events and errors: while the account is open. Write to us and we delete them sooner.

Who else sees it

Nobody buys it from us. These are the companies that run parts of Cactus, and what each of them receives.

  • Cloudflare runs the website, the app and every Help Center, and keeps a log of each request.

  • Microsoft Azure runs the server where Cactus reads your sources and writes pages and answers.

  • Restate runs Cactus's jobs, and keeps a record of each job's steps, including what each step read, for seven days.

  • Neon stores the database, including the search index of your code.

  • Convex carries live updates, including the words of an answer while it is being written.

  • Modal copies your repositories, builds the search index of your code, and runs the commands Cactus reads it with.

  • The Vercel AI Gateway carries every call Cactus makes to a model.

  • OpenAI runs the models that read your sources and write pages and answers, and the model that turns text into search vectors.

  • TypeSafe AI runs Jev, the model that makes some small decisions, such as whether your customers would notice a release.

  • Firecrawl reads your product's public website, to find its logo, its colours and its links, and fetches a public page for Cactus when a site turns a plain request away.

  • Resend sends our email, including the email your customers get when they write to your team.

  • PostHog records usage events, errors and recordings of visits to the app and to Help Centers, and keeps traces of model calls for debugging, which only Cactus's two founders can open.

  • Google and logo.dev supply the small logo shown beside a product's name. The browser asks them for it by the product's web address.

  • Google and GitHub sign you in, when you choose to sign in with them.

What Cactus reads from GitHub, where your code goes, and the controls Cactus has in place are on the Trust Center.

Your choices

  • Disconnect any source in Settings, and Cactus stops reading it.

  • Delete a product, and the pages and conversations under it go with it.

  • Close the account, and your account data goes.

  • Write to us for a copy of everything we hold about you, or to have all of it deleted.

Contact

hello@heycactus.ai. We reply within two business days, and you do not need an account to write to us.

Cactus Corp.
Based in Vancouver, Canada.

How an AI client connects to Cactus, and what it can see, is on the MCP page.

What Cactus keeps in your browser is on the cookie notice. How Cactus handles personal data for a team that uses it is in the Data Processing Addendum.