Privacy Policy
Last updated: April 6, 2026
1. What We Collect
| Data | Purpose | Retention |
|---|---|---|
| GitHub username, email, avatar | Authentication | Until account deletion |
| Workspace activity (start/stop times) | Billing, monitoring | 90 days |
| AI request metadata (model, token counts) | Usage metering | 90 days |
| Team membership, knowledge entries | Collaboration features | Until team deletion |
| Waitlist email and name | Beta access communication | Until signup or opt-out |
2. What We Do NOT Collect
- We do not read, store, or log the contents of your AI conversations
- We do not access your source code except to provide the Service
- We do not sell your data to third parties
- We do not use your code to train AI models
3. AI Processing
When you use the AI agent, your prompts are sent to the AI provider you selected (Anthropic, OpenAI, or local Ollama). Before any request leaves your workspace:
- Our secret-scrubbing proxy detects and redacts API keys, tokens, passwords, and other credentials
- Scrubbed content is replaced with placeholder tokens
- Responses are un-scrubbed (placeholders restored) before reaching your workspace
If you use BYOK (bring your own key), your API key is stored encrypted and only used to authenticate with the respective provider.
Third-Party AI Providers
- Anthropic: Privacy Policy
- OpenAI: Privacy Policy
- Ollama: Runs locally in your workspace. No data leaves.
4. Cookies
We use a single session cookie for authentication. We do not use tracking cookies or third-party analytics.
5. Data Security
- All traffic is encrypted via TLS (HTTPS)
- Workspace data is isolated per user via Docker containers
- Database credentials are rotated regularly
- Admin access requires token-based authentication
- Audit logs track all administrative actions
6. Data Location
Workspaces and databases are hosted on infrastructure managed by Outlaw Research Labs. Data may be processed in the United States.
7. Your Rights
You may:
- Request a copy of your data
- Request deletion of your account and associated data
- Opt out of waitlist communications at any time
8. Changes
We will notify you of material changes to this policy via email or in-app notification.
9. Contact
Privacy questions? Email [email protected].