Privacy Policy

Last updated: April 3, 2026

1. Information We Collect

Account data: Email address, username, and hashed password when you register. Optional two-factor authentication (TOTP) secret if you enable 2FA.

Git provider data: Personal access tokens (encrypted), git identity (name and email), repository metadata (names, paths, branches, descriptions) accessed through GitHub, GitLab, or Bitbucket APIs.

Session data: Chat conversation history (messages, tool calls, token usage), workspace state snapshots (git diffs, untracked file archives, agent session files), and container activity logs.

API credentials: Anthropic API keys, OpenAI API keys, OAuth tokens (Claude and ChatGPT subscriptions), and webhook endpoint secrets — all stored with Fernet symmetric encryption.

Usage data: Token usage per session (input, output, cache tokens), model selections, session duration, and cost estimates. Browser push notification subscriptions (VAPID endpoints).

Analytics: We use PostHog for product analytics (user actions, session creation, feature usage). We use Sentry and BetterStack for error tracking and log aggregation.

2. How We Use Your Information

We do not sell your personal data to third parties. We do not use your code or conversation content to train AI models.

3. Code Processing

Your code is cloned into isolated Docker containers per session. Code content is sent to the AI provider you configure (Anthropic's Claude API or OpenAI's API) for analysis and modification as you direct. We do not access, review, or process your code outside of providing the Service.

Container workspaces are ephemeral and destroyed after idle timeout. Workspace state (diffs and untracked files) is captured before cleanup and stored in encrypted S3-compatible object storage (Hetzner Cloud) to allow session resumption. This state data is deleted when the session is permanently cleaned up.

4. Credential Storage and Security

All sensitive credentials are encrypted at rest using Fernet symmetric encryption (AES-128-CBC with HMAC-SHA256). This includes:

Credentials are decrypted only when injected into container environments at session start. Encryption keys are stored separately from the database.

5. Container Security

Each session container runs with:

6. Third-Party Services

We use the following third-party services to operate the platform:

7. Data Retention

8. Data Location

The Service infrastructure runs on European servers. Object storage (Hetzner S3) is located in the EU. Analytics data (PostHog) is processed in the EU. Email delivery (Resend) may process data in the US.

9. Your Rights

You have the right to:

To exercise these rights, contact us at [email protected].

10. Cookies

We use session cookies for authentication (Django session cookie). We use a CSRF token cookie for security. We do not use advertising or tracking cookies. PostHog uses a first-party cookie for anonymous analytics which can be opted out of.

11. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via the email address associated with your account.

12. Contact

For privacy-related inquiries, contact us at [email protected].