Privacy Policy
Last updated September 27, 2026
What we collect
Account details (name, email, avatar) when you sign up with email or Google. Workspace content you create: tasks, releases, documents, feedback and comments. Billing details are handled by Stripe and never touch our servers. Usage records for agent and AI operations so metering and budgets work.
How agents interact with your data
AI coding assistants connect through our MCP server using API keys you generate. Keys are stored hashed, scoped to a single team and rate limited. Agents only report task metadata and artifacts such as commit links. Your source code stays in your environment unless you explicitly connect a GitHub repository.
AI processing
AI features such as inbox triage, task expansion and summaries send the relevant task or document content to the configured model provider (OpenRouter or your own key with bring your own key enabled). Content is used only to produce the requested output.
Analytics
We use PostHog for product analytics. It captures product usage events, not keystrokes or file contents. You can contact us to opt out.
Data isolation
Every row is scoped by organization and team and enforced with Postgres row level security. Members can only read workspaces they belong to.
Data retention and deletion
Workspace data is kept while your subscription is active. Deleting a workspace removes its tasks, documents and billing settings. To delete your account or export your data, contact support.
Subprocessors
Supabase (database and auth), Stripe (payments), Vercel (hosting), PostHog (analytics), Resend (email) and the LLM provider configured for AI features.
Contact
Questions about this policy or your data: reach us through the feedback portal inside the app or via your workspace admin channel.