Policies
Privacy policy
Effective October 8, 2026
This policy explains what personal information Établi collects, what we use it for, who processes it for us, and the choices you have. It covers the website at etabli.io, the API at api.etabli.io, the MCP connector that assistants such as ChatGPT and Claude use, and the messages Établi sends to businesses.
In short
- We collect what you send us (requests, answers, applications, bids and messages) and the contact details that come with them.
- We use it to plan your work, get bids, run contracts and orders, and answer you.
- We don't sell personal data, and we don't use it to train AI models.
- The public website sets no cookies and has no analytics or ads.
- You can ask for a copy of your information, or ask us to correct or delete it, through our support page.
What we collect
From buyers and visitors
- Quote requests. The request you write, your answers to our questions, your name and email, and your company and note if you add them. When you preview a plan, on etabli.io or through an assistant, we keep the plan for up to a day, so that asking for firm prices doesn't plan the work again.
- Requests for API access. Your email, whether you're building something or run a workshop, and your note.
- API accounts and keys. Your account's name and email, and your API keys. We store a fingerprint (hash) of each key, never the key itself.
- Work requested through the API and the MCP connector. What you or your agent sends, such as requests, answers, awards and orders, including each order's delivery address and the name on it, and the records they create: projects, contracts, orders and proof.
From workshops
- Applications. Your name or business name, email, country and area, what you make or do, and your website, trades, weekly capacity and note if you give them.
- Bids and questions. Your price, capacity and lead time; your business details (name, email, phone, website, location and what you make); links to photos of your work; and your questions and notes.
- Work records. Each order's status and proof, such as photos and tracking numbers, and your record: ratings, on-time deliveries and completed orders.
From support requests
- Messages. Your name, email, topic and message, and the page or app you came from.
From businesses we contact
When no workshop on Établi fits a job, Établi's sourcing agent searches the web for businesses that could do it. From their websites and public directories, it records publicly available business details: the business's name, website, location, what it makes, and its business contact details, such as an email address, a phone number or a contact page.
A person at Établi approves every message before it goes out, by email or through the contact form or marketplace page the business publishes. We keep a record of each message and of the replies. Every message says how to opt out: reply “no thanks”. We keep opt-outs on a do-not-contact list, so that business isn't contacted again.
When you connect
Like any website, the servers that host Établi receive your IP address and browser details when you connect. The API uses your IP address, in memory, to limit how many requests one address can send. Vercel, our host, may keep request logs for a short time to run and secure the service.
What we use it for
- Planning requests and getting bids. Turning a request into legs, specs and questions, and putting each leg out to bid.
- Matching workshops. Comparing a job with what workshops and businesses say they do, to choose whom to invite.
- Contacting businesses about work. Inviting businesses that could do a job to bid on it.
- Running contracts and orders. Awarding contracts, sending orders to workshops, collecting proof and arranging payment.
- Support. Answering your messages and requests.
- Security and abuse prevention. Limiting requests, declining prohibited work, and keeping Établi and the people who use it safe.
What we don't do
- We don't sell personal data.
- We don't use personal data to train AI models.
- We don't show ads or track you across other sites.
Who processes it for us
These companies process personal information for us, to provide their service to Établi:
- Vercel hosts the website and the API. Its AI Gateway computes text embeddings (numbers that summarize what a text is about) with an OpenAI embedding model, which we use to match jobs with workshops and businesses.
- Neon runs our database.
- Anthropic provides Claude, which plans requests into legs, writes specs and questions, searches the web for businesses that could do a job, drafts messages to them, and sorts their replies.
- Resend sends Établi's email to businesses, when we contact them by email.
We store personal information in the United States.
ChatGPT, Claude and other assistants
You can use Établi through an assistant such as ChatGPT or Claude. A request sent through an assistant comes to Établi like any other: the assistant sends the request and your answers to its questions. Your name and email are shared with Établi only when you ask for firm prices.
What you tell the assistant is handled under its provider's privacy policy. Établi receives only what the assistant sends to Établi's tools.
How long we keep it
We keep personal information for as long as we need it to provide the service and to keep records of contracts and orders, then delete it. Plans from previews are kept for up to a day. A business that opted out stays on our do-not-contact list, so we don't contact it again.
Your choices and rights
You can ask for a copy of the personal information we hold about you, or ask us to correct or delete it. Send your request through our support page and choose “Privacy and my data”. We'll check that the request comes from you before we act, and we may keep what the law requires us to keep.
Depending on where you live, you may have other rights over your information, such as objecting to how we use it. Ask, and we'll help.
If Établi contacted your business and you'd rather we didn't, reply “no thanks” to the message, or tell us through the support page.
Security
Connections to Établi are encrypted (HTTPS). We store API keys and bid-link codes only as fingerprints (hashes), and we encrypt the keys we hold for services such as email. The admin panel needs an operator's key.
Children
Établi is for businesses and adults. It isn't meant for children, and we don't knowingly collect personal information from anyone under 18. If you think a child has sent us information, tell us through the support page and we'll delete it.
Changes to this policy
When we change this policy, we'll post the new version here and update the effective date at the top. If a change affects how we use information you've already given us, we'll tell you before it takes effect.
Contact
Questions about this policy or your information: write to us through our support page. We don't publish an email address yet, so the form is the way to reach us.