Earlier

Privacy Policy

Earlier Labs Ltda.

Last updated: 10 June 2026 · Version 1.0

1. Who we are and what this policy covers

Earlier Labs Ltda. (“Earlier”, “we”, “us”) runs an API that keeps one time-ordered record of the changes made to your production systems, such as deploys, infrastructure applies, feature flag changes and edge rule edits, and returns the changes that came before a given moment when you ask. It connects to your change sources with read-only credentials. It does not read your logs, metrics, source code or your own customers' data, and it takes no action in your systems.

Registered at Rodovia José Carlos Daux 4150, Sala 12, Saco Grande, 88032-005 Florianópolis, Brazil.

We handle personal data in two different situations, and different rules apply to each:

Whose dataOur roleWhat applies
Part APeople who visit this website, ask about the service or write to usController: we decide why and how the data is usedThis policy
Part BThe change events your sources send us, including the names and work emails of the engineers who made each change, your service catalog, the incident and alert details sent to us when an incident opens, the record of which change a responder named, and the account, key, usage and invoice records that come with having an account.Set out in B.1, because it depends on the dataThis policy and the data processing agreement we sign with each customer

If the data processing agreement (“DPA”) and this policy ever disagree about Part B, the DPA wins.

2. Part A: this website and our contact with you

This part covers the personal data we collect for our own purposes: running this website, answering requests, and staying in touch with people who are or might become customers.

A.1 What we collect

What you give us. When you send the form on this site, we collect what you type into it, such as your name, email address, phone number or company, and the fact that you agreed to be contacted. If you email or talk to us, we keep that correspondence and any contact details in it.

What is collected automatically. Our web server records the IP address a request came from, the browser used, the pages requested, the page you came from and the time. These logs exist to keep the site running and secure.

We don’t ask for sensitive data (the “special categories” in Article 9 GDPR) through this website, so please don’t send any through the form.

A.2 Why we use it, and what allows us to

WhyWhatLegal basis (GDPR Art. 6)
Answering your request and working out whether the service fitsWhat you sent in the form, our correspondenceArt. 6(1)(b): steps you asked for before a contract
Looking after customers, billing and supportContact details, correspondenceArt. 6(1)(b): carrying out a contract
Keeping the site running, secure and free of abuseServer logsArt. 6(1)(f): our legitimate interest in running a secure service
Contacting you about the serviceEmail address, companyArt. 6(1)(f): our legitimate interest in business-to-business marketing. You can object at any time
Meeting tax, accounting and legal dutiesBilling and contract recordsArt. 6(1)(c): a legal obligation

Where we rely on legitimate interest, we have weighed that interest against your rights, and you can ask to see the assessment.

A.3 How long we keep it

A.4 Your rights

If you are in the EEA or the UK, you can ask to see your data, correct it, have it deleted, limit or object to how we use it, get a copy you can take elsewhere, and withdraw consent where we rely on it. Write to [email protected] and we will answer within one month.

You can also complain to a data protection authority. If you are in the EEA, that can be the authority where you live or work.

3. Part B: data inside the service

Two kinds of data reach Earlier and we treat them differently. The first is yours: the ledger of change events, the service catalog and the incident records. It identifies your engineers by name and work email, because who made a change is part of the record. The second is ours and small: the account, key and billing records for the people who signed up. This part covers both, in that order.

B.1 What we handle, and in what role

For the ledger, the service catalog and the incident records we are your processor and act only on your instructions, which are the API calls and connector settings you make. For account and billing data we are the controller. Nothing in the ledger is used for any purpose other than answering your queries, improving the mapping and ordering for your account as described under the AI disclosure, and preparing your invoice.

We do not read logs, metrics, traces, source code contents, database contents or any data about your own customers. No connector asks for a scope that would allow it.

Values that Terraform marks sensitive, and strings matching common secret patterns, are dropped at ingestion before anything is stored. If one gets through, an account admin can file a signed redaction, which removes the text and leaves a visible tombstone in its place.

B.2 What we do with it

Where it is held. The ledger, the service catalog and the incident records are stored and processed on cloud infrastructure in Oregon, United States. Each account's data is logically separated and every query is scoped by the account's key.

Encryption and credentials. Data is encrypted in transit and at rest. The read-only tokens you give us for your sources are stored encrypted, used only to fetch change events and never returned by any endpoint. Every token we ask for is read-only; if a source offers only a broader scope we say so before you connect it.

Model inference. The embedding model that matches change targets to services runs on cloud GPU capacity we control in Oregon, and the ranker that orders a list runs on CPU beside it in the same place until it becomes a cross-encoder. No change event, alert text or service name is sent to a third-party hosted model API, and no model provider appears in our list of subprocessors.

Who at Earlier can see it. Access to customer ledgers is limited to named engineers for support and incident response, is logged, and requires a ticket you opened or an alert on your account.

B.3 AI models: where they run and what they learn from

Where models run. Two models run inside Earlier: an embedding model that matches a change's target to one of your services, served on cloud GPU capacity we control in Oregon, and a ranker that adds an ordering hint to a list, running as gradient-boosted trees on CPU beside it in the same place until it becomes a cross-encoder. Both run on capacity we control and never on a third party's, beside the ledger on cloud infrastructure in Oregon. No change event, alert text, service name or engineer's name is sent to a third-party hosted model API, and no model provider is among our subprocessors.

Training. We do not train models on your data for the benefit of anyone else, with one stated exception. Confirmed target-to-service pairs, a raw target string and the service a person confirmed for it, are used to tune matching for your account only and are never shared. Confirmed alert-to-change pairs kept with their text, an alert title and the summary of the change a responder named for it, are used to tune ordering for your account only, are never shared and are deleted with the account. The ranker's shared corpus holds one row per confirmed or rejected alert-to-change pair and contains numbers only: the kind of change, minutes before onset, dependency distance, how many services it touched and whether it was named. It holds no text, no names and nothing that identifies an account, and it is the only thing pooled across customers.

Where a person decides. The models propose and a person decides. A service match under 0.80 confidence is not applied and waits in a queue for one of your people; the event stays visible as unmapped until they answer. When the ranker's calibrated confidence is low the response says ranked: false and the list is in plain time order. The API never returns a cause; one of your responders names the change. Earlier makes no automated decision with legal or similarly significant effect on any individual, and a row naming an engineer records that they made a change, not that they were at fault.

B.4 Where the data is kept

Customer data is stored and processed on cloud infrastructure in Oregon, United States, and model inference runs on capacity we control in Oregon, the embedding model on cloud GPU capacity there and the ranker on CPU beside it. The ledger is not replicated anywhere else, and backups are held on the same cloud infrastructure in Oregon.

If you are established outside the United States, sending change events to Earlier is a transfer to the United States, and the data processing agreement carries the transfer terms that apply.

The suppliers that handle data in the service are named on our subprocessor list, which comes with the data processing agreement and which we send to anyone who asks: write to [email protected].

B.5 How long we keep it, and what deleting can’t remove

Ledger rows and incident records are kept for 13 months from the time the change took effect, then deleted. The ledger is append-only during that time: rows are not edited or removed except by a signed admin redaction.

When an account closes, the ledger stays available for export for 30 days and is then deleted, with backups following within a further 30 days. Account and invoice records are kept for five years, the period Brazilian tax law sets for tax records.

Confirmed target-to-service pairs, and confirmed alert-to-change pairs kept with their text to tune ordering for your account, are deleted with the account. The ranker's shared training features, which contain no text, names or identifiers, are not.

B.6 Requests from people whose data is in the service

The account data we control is contact data for your employees acting for you. If one of them writes to us we answer directly: access, correction, deletion and objection, within thirty days. The ledger also names your engineers as the people who made changes. That is data you control and we process, so a request about it goes to you, and we help you answer it, including by redaction where you instruct it. A row in the ledger records that a change was made and by whom; it is not a finding that the person caused an incident.

For everyone

4. Moving data between countries

Earlier Labs Ltda. is a company in Brazil, outside the EEA, and handles personal data under Brazil’s LGPD (Law 13.709/2018) and, where it applies, the GDPR. Section B.4 says where the data in the service is kept. When personal data from the EEA or the UK reaches us, for example because someone there writes to us or a customer there uses the service, it is protected by the European Commission’s Standard Contractual Clauses and the technical measures described in our security documentation. You can ask us for a copy. In Brazil you can complain to the ANPD, Brazil’s data protection authority.

EU representative (Article 27 GDPR). Write to [email protected] with “EU representative” in the subject line and we will send you our representative’s details.

5. Security

We protect data in line with the risk. That includes encryption in transit and at rest, access limited to the people and systems that need it, each customer’s data kept separate from every other’s, and a log of every access to production systems.

If a personal data breach affects you, we tell you without undue delay, and at the latest within 36 hours of finding out, with the information you need to meet your own reporting duties.

6. Children

The service is sold to businesses and is not meant for children. We don’t knowingly collect personal data from anyone under 16.

7. Changes to this policy

We may update this policy. If a change matters, we email customers at least 30 days before it takes effect. The version number and date at the top of this page change every time.

8. Contact

Privacy questions and anything else: [email protected]
By post: Earlier Labs Ltda., Rodovia José Carlos Daux 4150, Sala 12, Saco Grande, 88032-005 Florianópolis, Brazil

← Back

Your request has been received.

Expect a message from Earlier. It goes to the address you gave.