Back to GDELT Cloud
Last updated September 3, 2026

Privacy Policy

This plain-language policy explains the information GDELT Cloud uses to operate accounts, subscriptions, product access, agent runs, and support.

Information we collect

We collect account details such as email address, authentication identifiers, subscription status, plan information, and support messages.

We may use account contact details, signup time, plan, plan source/mode, and basic usage rollups for customer success, inbound sales, and account outreach workflows.

We collect product usage telemetry such as API endpoints used, feature access, timestamps, status, row counts, query units, and related operational metadata.

How we use information

We use account and usage information to provide the service, enforce plan limits, secure API and MCP access, debug issues, improve product workflows, and support customers.

We use aggregated usage patterns to understand product adoption and prioritize improvements.

Customer content and AI interactions

GDELT Cloud may process API queries, MCP requests, agent prompts, and generated responses to provide the service, troubleshoot errors, prevent abuse, and improve reliability.

For Monitoring Briefs, we store the brief scope prompt you supply, the supporting evidence sources gathered during generation, and the generated brief document, so we can deliver the brief, render its source appendix, support you, and improve brief quality.

GDELT Cloud does not sell customer data. GDELT Cloud does not provide customer API queries, prompts, uploaded content, or private workspace activity to third parties for the purpose of training foundation models.

Agent runtime and observability

When customers use the research agent, Monitoring Briefs, or other agent-driven features, the agent runs on a hosted agent platform (LangSmith). The runtime processes the customer's prompt, tool calls, and intermediate responses, and produces traces we use to debug runs, evaluate quality, and improve agent reliability.

Agent runtime data and traces are operational data, not training data. We do not redistribute agent traces and do not use them to train third-party foundation models.

Email we send you

We send two kinds of email. Operational mail — sign-up confirmation, billing and payment notices, security notices, and the alerts and Briefs you configured — is part of the service and is not something you can opt out of while your account is active.

We also send occasional account-usage notices: when your organization approaches or reaches its monthly query-unit allowance, we may tell you how much you have used, when the counter resets, and what the plans include. These are capped at two per calendar month per organization, and you can turn them off at any time from the unsubscribe link in any one of them. Opting out stops usage notices only; billing, security and alert mail continues.

Email delivery and subscription preferences are handled by Resend, our email subprocessor. Your opt-out choice is recorded there and enforced at send time, so it applies to every later send without any action from you.

Service providers and subprocessors

GDELT Cloud relies on third-party subprocessors for hosting, the operational database, analytical storage, MCP infrastructure, agent observability, payments, CRM/customer success workflows, and email. Each subprocessor processes information only as needed to provide its service to GDELT Cloud.

Our current subprocessor list, the purpose each one serves, and the data each one processes are published on the subprocessors page.

Public-office and public-designation data

Beyond account data, GDELT Cloud processes a narrow class of personal data about people who are not our customers: individuals who hold, or have held, a public office published by a government or legislature, and individuals named on public restricted-party lists (sanctions, export-control, debarment and similar designations). This data is gathered from the publishing authority's own public rosters and lists, and from Wikidata, by our open-source crawler lane. We rely on the fact that the source is a public record published by a public authority for the purpose of identifying the office-holder or designated party; we do not obtain this data from private sources, data brokers, or compiled commercial databases.

For each such person we store and serve only: a name, aliases, citizenship, a Wikidata identifier, gender, birth year, the offices held with their published start and end dates, and any public-list memberships with their published dates. We deliberately do not store a date of birth, a passport, national-identity or tax number, an address, a birthplace, or any contact detail, even where the public source publishes them. Where a source does publish such a value, the crawler reduces a date of birth to its year and discards every other such value at the moment of writing; a salted one-way hash of the discarded value is kept in a raw, non-served layer solely so the same public record can be recognised across two sources, and that hash never reaches any table the API, MCP or web app read from. No served table has a column that could hold these values, and this is enforced by an automated test on every build.

Public-office and public-designation data is served as analytical context for geopolitical research. It is not a politically-exposed-persons list, it is not a sanctions-screening or KYC/AML service, and we do not make or supply compliance determinations about any individual. Every response from the political-offices endpoints says so.

Retention follows the source. A person's record exists in the product for as long as the publishing authority carries it. When the publisher removes an entry, the current view no longer returns it; a dated removal fact, or the end date of the office, is retained so that a query about a past date remains answerable. We do not use this data for advertising, profiling for marketing, or automated decisions about the individuals concerned.

If you are the subject of such a record and want to ask what we hold, request a correction, or object to the processing, email hello@gdeltcloud.com with the name and public office or list you are asking about. Because every record is a projection of a public source, a correction we make applies to our copy; the publishing authority remains the place to change the underlying public record, and we will tell you which source a record came from so you can do so.

Data retention and security

We retain account, billing, usage, and operational logs as needed to operate the product, support users, enforce limits, and maintain security.

We use reasonable technical and organizational measures to protect account and API access information. Our security posture is summarised on the security page.

Contact

You can delete your account yourself from Settings (Danger zone): it removes your account, personal workspace, API keys, Monitors, Briefs and usage history. Email hello@gdeltcloud.com for privacy questions or corrections to account information. For security-specific questions, vendor reviews, or responsible disclosure, email security@gdeltcloud.com.

Questions?

We are happy to clarify product, API, data, or account questions.