Privacy Policy
DRAFT — requires attorney review. Last updated: 2026-04-16.
1. Data we collect
- Account data: username, email address, display name, hashed password, 2FA secrets, WebAuthn credentials, SSH public keys, personal access tokens (stored as SHA-256 hashes).
- Git content: repositories you push, including commits, branches, tags, file contents, commit messages, and author metadata embedded in commits.
- AI interactions: prompts you submit to AI features (chat, code review, explanations, completions) and responses generated by third-party AI providers.
- Usage telemetry: requests, request IDs, rate-limit counters, error traces, audit events, deployment events, gate run results.
- Network data: IP address, user-agent string, request timestamps, session cookie identifiers.
2. How we use it
- To operate, maintain, and secure the Service.
- To provide AI-assisted features that you explicitly invoke (code review, chat, explanations, test generation, auto-repair, dependency updates, incident summaries, semantic search).
- To detect, investigate, and prevent abuse, fraud, security incidents, and violations of our Terms or AUP.
- To comply with legal obligations, respond to lawful requests from authorities, and enforce our rights.
- To communicate service-related messages (security alerts, policy updates, incident notifications).
3. Data controller
The data controller is Gluecron (entity name placeholder — DRAFT; final legal entity name and registered address to be inserted prior to launch). Contact: support@gluecron.com.
4. Sub-processors
We engage the following sub-processors to operate the Service. This list is current as of the date above and may change; we intend to provide 30 days' notice of material changes.
| Sub-processor | Purpose | Data categories |
|---|---|---|
| Neon (neon.tech) | Managed PostgreSQL (primary database) | Account data, metadata, telemetry |
| Anthropic | Claude API (AI features) | AI prompts (including code snippets you submit) |
| Resend (if enabled) | Transactional email delivery | Email address, message contents |
| Fly.io / Railway | Application hosting (compute) | All transient request data |
| Cloudflare (if fronting) | CDN, DDoS mitigation, DNS | IP address, request metadata |
DRAFT — requires attorney review; sub-processor list must be verified against signed DPAs prior to launch.
5. Data retention
- Account data: retained while your account is active and for thirty (30) days after account deletion, after which we intend to purge it.
- Git repository content: retained for the lifetime of your account; deleting a repository is intended to purge its content within 30 days.
- Sessions: 30 days (rolling).
- Audit and security logs: up to 12 months for security and abuse-detection purposes.
- Backups: may persist for up to 30 days beyond the primary retention period.
6. GDPR compliance (EU / UK residents)
If you are in the European Economic Area, the United Kingdom, or Switzerland, we process your data under the following lawful bases (GDPR Art. 6): (a) performance of a contract (providing the Service to you); (b) our legitimate interests in securing and improving the Service; (c) compliance with legal obligations; and (d) where required, your consent (which you may withdraw at any time).
Article 13 disclosures. The identity of the controller, data categories, purposes, retention, recipients, and your rights are described throughout this Policy. International transfers of personal data outside the EEA/UK will rely on the EU Standard Contractual Clauses ("SCCs") or another approved transfer mechanism.
Your rights include access, rectification, erasure, restriction, portability, and objection. You may lodge a complaint with your local supervisory authority. DRAFT — requires attorney review.
7. CCPA / CPRA compliance (California residents)
If you are a California resident, you have the right to (a) know what personal information we collect, use, disclose, and sell or share; (b) delete your personal information, subject to legal exceptions; (c) correct inaccurate personal information; (d) opt out of the sale or sharing of personal information (we do not sell personal information); and (e) non-discrimination for exercising these rights.
8. Right to erasure / access
To exercise any of the rights above, email support@gluecron.com. We intend to respond within thirty (30) days. We may need to verify your identity before acting. Some data (e.g., audit logs required for security, legal holds) may be exempt from deletion.
9. Cookies
We use only strictly necessary cookies (session authentication, theme preference, CSRF). We do not use advertising cookies. We do not use third-party analytics cookies on our marketing surfaces.
10. Children
The Service is not directed to children under 18. We do not knowingly collect personal information from children under 13 (COPPA, U.S.) or 16 (GDPR, EEA). If you believe a child has provided us information in violation of this Policy, contact us and we will delete it.
11. Breach notification
In the event of a personal-data breach that is likely to result in a risk to your rights and freedoms, we intend to notify the relevant supervisory authority within 72 hours of becoming aware, as required by GDPR Art. 33, and to notify affected users without undue delay where required.
12. Changes to this Policy
We intend to provide thirty (30) days' notice of material changes to this Policy, by email or by posting a notice in the Service.
See also: Terms of Service · Acceptable Use Policy · DMCA Policy