Privacy Policy
What we collect, what we never collect, and who else sees it.
Effective 10 September 2026
The short version
We store your email, your organisation, and a record of what you paid for. We count how many requests you make and which model served them.
We do not store your code, your prompts, or the model's replies. Not in a log, not in a database, not for training. That is enforced at the gateway rather than promised by the app, because software that promises its own privacy is promising nothing.
What we collect when you have an account
Your email address, and your name if you give one.
Your organisation's name, its plan, and the history of plan changes: what changed, when, and who did it.
If you sign in with GitHub or Google, the provider's account id and the email it gives us. We never receive your password for those.
If you sign in by emailed code, a HASH of that code and when it was used. The code itself exists only in the email we sent.
Metadata about API keys you create: a label, the first few characters, when it was created and last used. The key itself is stored only as a hash and cannot be recovered by us or by anyone who reaches our database.
If you refer people, or were referred
When somebody follows a referral link we record which link, the page that linked to it with its query string removed, an optional campaign label the link's owner chose, and a keyed hash of the visitor's IP address. The hash cannot be turned back into the address; it is kept so we can see many clicks coming from one place, which is how fake clicks look.
If you create an account after following one, we record who referred you. The person who referred you sees a masked version of your email address (the first letter and the domain), the date you joined, your plan, and whether you pay. They never see your name, your full address or anything you do in the editor.
Stripe gives us a fingerprint of the card that paid each invoice: a code that is the same for the same card and says nothing else about it. We use it only to notice an affiliate paying for accounts they claim to have referred.
Affiliates have an account of their own, separate from any customer account: an email address, a name if given, and sign-in codes stored only as hashes. If the same address also has a customer account, we note that the two belong to one person, only to stop anyone earning commission on themselves.
Affiliates: the country you are paid in, the email for Stripe's payout invitation or your eSewa or bank details if you are paid in Nepal, and the tax form you upload. The form is stored outside the website and only our staff can open it.
What we collect when you use the editor
For each request: which account made it, which surface it came from (chat, agent, completion), which model served it, how many tokens it used, and whether it succeeded.
That is the whole record. The content of the request and the reply are not part of it and are never written down by us.
What we deliberately do not collect
The contents of your files, your repository, or your workspace.
Your prompts or the model's responses.
Anything an MCP server returns to the agent on your machine.
Your provider API key, when you bring your own. It is used for that one request and never stored.
Who else sees your data
Model providers. To answer a request, its content is sent to the provider serving that model. We instruct providers not to train on it. Their handling is governed by their own terms.
Stripe, for payments. Stripe holds your card details; we never see or store a card number. We hold Stripe's customer and subscription identifiers so we know what you are on.
Google Analytics, on the astracode.io website only. It sets cookies and records page views and approximate location. The editor does not run analytics.
Our email provider, to send sign-in codes, receipts and service notices.
GitHub, if your organisation connects it. The access token is encrypted before it is stored and never sent to any client.
Cookies
A session cookie, so you stay signed in. A CSRF cookie, so a form on another site cannot act as you. Both are strictly necessary and cannot be turned off without breaking sign-in.
A download cookie, set only when you start a download. It holds a random number and nothing about you. Its only purpose is to connect a download to an account if you create one afterwards on the same browser, so we can tell how many people who downloaded AstraCode went on to use it. It expires after 30 days, and if you never create an account it never refers to anyone.
A referral cookie, set only when you follow somebody's referral link. It holds the number of that click, signed so it cannot be altered, and nothing about you. It lets us credit the person who shared the link if you create an account within 60 days, and expires then.
Google Analytics cookies on the website. These are not necessary, and blocking them costs you nothing.
How long we keep it
Account data, for as long as the account exists.
Sign-in codes expire in minutes and are deleted after use.
Usage records, for as long as needed to bill and to show you your own history.
Records of what you paid, for as long as tax and accounting law requires, which outlives the account itself.
Your rights
Ask us for a copy of what we hold about you. Ask us to correct it. Ask us to delete your account and the personal data in it.
Deletion does not remove records we must keep for tax purposes, and it does not reach data already sent to a model provider under their own retention.
Write to privacy@astracode.io and we will respond within 30 days.
Security
Passwords are hashed. Sign-in codes are hashed. API keys are hashed. Third-party integration tokens are encrypted at rest with a key that is not stored in the database.
Everything is served over HTTPS. Access to production data is limited to people who need it.
No system is perfectly secure, and we will not pretend otherwise. If a breach affects you, we will tell you.
Children
AstraCode is not for anyone under 16, and we do not knowingly collect data from them.
Changes
If we change what we collect or who sees it, the effective date above changes and we email account owners before it applies.
Getting in touch
Privacy questions go to privacy@astracode.io.