Skip to main content
Use this page when you need a practical security and privacy overview for Custory. This page only includes details verified from current product behavior and public policy text. Where a control is not yet published or confirmed, it is marked as not specified instead of guessed.

Workspace access

A workspace is the top-level access boundary for a team, product, or product area. Custory checks the authenticated user and workspace membership before allowing workspace actions. Workspace roles are hierarchical: Public journey sharing, where enabled, is limited to viewer-style access for the shared journey. It does not grant workspace editing rights. For role assignment and invites, see Manage your team.

Authentication and sessions

Custory uses WorkOS AuthKit for authentication and session handling. Verified behavior includes:
  • password, OAuth, magic-auth, email-verification, and organization-selection flows where enabled
  • sealed session cookies
  • secure cookie behavior in production
  • session revocation and cookie clearing on sign-out
  • authenticated identity checks before workspace actions
Users are responsible for protecting their account credentials and controlling who has access to their workspace.

Data Custory processes

Custory may process:
  • account and authentication data, such as name, email, profile, workspace membership, organization state, and session state
  • workspace content, such as journeys, stages, steps, items, personas, comments, attachments, tasks, workflow data, settings, invitations, and collaboration history
  • integration data, such as OAuth tokens, refresh tokens, workspace or tenant metadata, install metadata, and scoped third-party content
  • usage, device, and analytics data, such as IP address, browser, device information, request metadata, product events, cookies, analytics, and feature-flag events
Custory does not sell personal information or share it for third-party advertising.

Integrations and credentials

Integrations are scoped to a workspace.
  • Owners and editors can connect and disconnect tools in Manage Integrations.
  • Viewers cannot manage integrations.
  • OAuth and manual integration credentials are encrypted before storage.
  • The UI may show safe identifiers such as account names, project names, or token prefixes.
  • Disconnecting an integration removes it from the workspace.
  • Linked task records associated with a disconnected integration are also removed.
Integration OAuth tokens and manual credentials are encrypted with AES-256-GCM before storage. Each encrypted value uses a unique initialization vector. Connected third-party tools remain governed by their own terms, scopes, and privacy practices. Disconnecting a tool in Custory does not delete data held by the third-party service.

Encryption

Verified encryption controls: Do not assume an unpublished at-rest encryption guarantee for all workspace content unless Custory has confirmed it for your review.

MCP keys

MCP lets external AI clients work with Custory workspace context through workspace-scoped keys. The CLI security and privacy page explains the terminal workflow, OAuth scopes, local credential storage, private briefs, website source limits, and the repository access boundary for coding agents. MCP keys support:
  • 30 days, 90 days, and Never expiry choices
  • copy-once generated tokens
  • stored token prefixes for later identification
  • key revocation from the Keys tab
Create separate keys for separate clients or use cases when you want easier cleanup.

AI, Google data, and workspace memory

Custory uses AI features to process workspace content at the user’s direction, such as importing, summarizing, analyzing, or transforming customer-journey material. Verified product implementation includes support for OpenAI, Anthropic, and Google model providers. Google embeddings are used for semantic search behavior in the product. For Google Workspace data, Custory’s public privacy policy states that Google user data is used only for user-facing features and is not used to develop, improve, or train generalized AI or machine-learning models. The broader model-training policy for every AI provider is not fully published in the verified docs. Confirm provider-level retention and training terms during vendor review if your team requires that detail. Workspace memory can store context from sources such as journey changes, attachments, external links, connected tools, chat messages, agent runs, and workspace profile data. Memory sources can be marked deleted, and Custory attempts to delete the corresponding provider document when the provider API is available.

Workspace deletion

Workspace deletion is owner-only and destructive. When an owner deletes a workspace, Custory cancels paid billing for that workspace as part of the deletion flow. Verified cascade behavior removes workspace-owned records such as journeys, items, invitations, personas, integrations, automations, notification rules, MCP keys, memory sources, linked tasks, notifications, agent runs, automation runs, and stored workspace logo files. Custory’s public privacy policy also states that retention may vary when data must be kept for legal, security, backup, billing, dispute, or agreement reasons. If the workspace should continue, transfer ownership or remove individual members instead.

Retention and data requests

Custory retains data as reasonably necessary to provide the service, maintain workspaces, comply with legal obligations, resolve disputes, enforce agreements, and support security or backup needs. Privacy rights may include access, correction, deletion, objection or restriction, portability, consent withdrawal, integration revocation, and communication preferences, depending on the applicable law and request context. For account-level privacy or data requests, contact Custory through the public contact process.

Vendor-review gaps

Some B2B security details are not currently specified in the verified product docs or public policy text.

Vendor review

This page does not replace a vendor security review. If your team has compliance, procurement, or legal requirements, confirm unpublished controls directly during evaluation.