Privacy Policy
Last updated: 2026-06-15
1. What We Collect
- Account identity: You sign in with a third-party account (e.g. Google, Apple, on both web and mobile); we store only the identifier that account returns (provider + subject), your display name, and email if the provider supplies one. We do not set or store any password.
- Usage: AI conversation content, files uploaded to workspaces, Task configs and versions, collected snapshots
- Runtime metadata: AI token usage, model used, estimated cost, collection success/failure status
- Device/environment: IP address, User Agent, mobile push device tokens, locale preference
2. How We Use It
- Provide the service: generate micro-apps, collect data, detect changes, send notifications
- AI inference: conversation and compile requests are sent to Anthropic Claude API
- Notification delivery: via email or mobile push channels you configure
- Troubleshooting: operations staff may access relevant data when debugging
- Usage accounting (future): per-user AI consumption metrics
3. Third-Party Processors
| Processor | Purpose | Data |
|---|
| Identity providers (Google, Apple, etc.) | Third-party sign-in | Your account identifier, email, display name |
| Anthropic Claude API | AI compilation/chat/analysis | Your conversations, collected data snippets |
| Email provider (SMTP) | Notifications | Your email, signal summaries |
| Cloud servers (platform host) | Storage and compute | All data |
| Logging/monitoring (internal) | Troubleshooting | Request logs, error stacks |
Third-Party AI Processing (Anthropic)
- What is sent: your task descriptions and conversations, files uploaded to your workspace, and data snippets collected by your monitoring tasks.
- Purpose: compiling your requests into monitoring tasks, building data dashboards, analyzing collected data, and translating content.
- No training: we process data through Anthropic's commercial API; your data is not used to train AI models.
- Retention: Anthropic retains API data per its commercial terms and data policy.
- Consent: in the mobile apps, an explicit consent prompt is shown before your data is first sent to AI; continued use constitutes agreement to the processing described in this section.
4. Data Retention
- Raw fetched responses (snapshot raw_data): cleared after 30 days; only processed display/diff data is kept
- Snapshots, signals, conversation history: until the corresponding task is deleted
- Execution logs: 30 days
- Diagnostic issue context: cleared 30 days after resolution / 90 days after creation if unresolved; also cleared when the corresponding task is deleted
- Uploaded files and attachments: until the corresponding task is deleted
- AI usage and billing records, user feedback, notification settings and push tokens: until account deletion
- Data export packages: download link valid for 24 hours, cleaned up after it expires; export job records kept until account deletion
Deleting a task also clears that task's snapshots, signals, conversations, execution logs, uploaded files (including cloud-storage objects) and diagnostic context. Deleting your account clears all of your data.
5. Your Rights
- Access: View all your Tasks, conversations, files, signals in the app
- Export: One-click request via Settings → Account → Export my data. See §11 below
- Correct: Modify via conversation or direct edits
- Delete: Settings → Account → Delete account wipes everything. Immediate and irreversible.
- Contact: Via Settings → Feedback & Support
6. Cookies & Local Storage
We use browser localStorage for:
- JWT token (for staying logged in)
- Locale preference
No third-party tracking or advertising cookies.
7. Data Security
- Transit: HTTPS (post-launch)
- Authentication: sign-in is via third-party OAuth (e.g. Google, Apple); we do not collect or store passwords. Sessions are maintained with a JWT token
- AI-generated code: iframe sandbox; cannot access parent DOM or cookies
- API keys: in environment variables only; never in DB, logs, or AI prompts
8. Children
This service is not directed at children under 13. Discovered child accounts will be deleted.
9. Cross-Border Data Transfer
Anthropic Claude API operates in the United States. By using this service you consent to your conversations and collected snippets being transferred to the US for processing. If you are in mainland China, please consider applicable data export compliance.
10. Changes & Contact
This policy may be updated. Material changes will be announced in-product. Contact us via Settings → Feedback & Support.
11. Data Export & Portability
You can request a data export at any time via Settings → Account → Export my data. Within a few minutes we will prepare a ZIP file containing your tasks, conversations, uploaded files, historical snapshots, signals, settings, and more.
The export does not include AI-generated frontend code, collector code, data schemas, or other derived artifacts (these are inferred/derived data exempt under GDPR Art. 20). It also excludes data already removed by retention policies (see manifest.json inside the export bundle for details).
You may request one export every 24 hours. Download links remain valid for 24 hours and are automatically cleaned up afterwards.