Privacy Policy

Last updated: August 5, 2026

Information We Collect

We collect information you provide directly to us when you create an account, use our services, or contact us for support. This includes: • Account information (name, email address, password) • Billing information (processed by Stripe; we never store full card numbers) • Usage data (DevBox launches, worker connections, API usage) • Communication data (support tickets, contact form submissions) • Technical data (IP address, browser and device type, and request logs), collected automatically when you use the service. We use it to operate the platform, diagnose errors, investigate abuse, and keep accounts secure — never for advertising or profiling. Requests you make while signed in are tagged with your internal account identifier so we can troubleshoot your issues; that identifier is meaningless outside our own systems. Whatever plan you're on, we never sell your data, use it for advertising, or use your source code, agent activity, or DevBox contents to train, fine-tune, or improve any model. Where your data lives depends on how you run: • Self-hosted / bring-your-own workers — your source code, DevBox contents, and any credentials you keep locally stay on your own hardware and never reach us (see "Data Architecture and Your Code"). • Cloud Workers and optional Session Portability — some of this data is processed or stored on our infrastructure so the service can run and your sessions can follow you across machines. It is always encrypted, and we use it only to deliver the features you asked for — never to read you, profile you, or train on your content (see the sections below).

How We Use Your Information

We use the information we collect to: • Provide, maintain, and improve our services • Process transactions and send related information • Send technical notices, updates, and support messages • Respond to comments, questions, and requests • Monitor and analyze usage patterns to improve the service • Detect, investigate, and prevent fraudulent transactions and abuse • Record resource usage on Cloud Worker DevBoxes — CPU, memory, disk and runtime — which we may use to help detect misuse and enforce our Acceptable Use Policy

How We Share Your Information

We do not sell your personal information. We share it only in these limited circumstances: • Service providers — with the third-party service providers (our sub-processors) listed under "Third-Party Services" below who perform services on our behalf (payment processing, email delivery, authentication, hosting), under contracts that restrict their use of your data. • Legal and safety — when we believe disclosure is reasonably necessary to comply with a law, regulation, legal process, or governmental request, or to protect the rights, property, or safety of ClusterCode, our users, or others. • Business transfers — in connection with, or during negotiations of, any merger, acquisition, financing, reorganization, or sale of assets, in which case your information may be transferred as part of that transaction. We will notify you of any such change and any choices you may have. • With your consent — when you direct us to share it or otherwise agree. • Aggregated or de-identified data — which can no longer reasonably identify you, for any purpose.

Data Architecture and Your Code

For self-hosted and bring-your-own workers, ClusterCode is architected so that your code, your AI agent outputs, and your development work never pass through our servers. The worker agent runs on your own hardware, executes Podman locally, and communicates telemetry (DevBox status, worker health) — not code content — to the orchestrator, and we never proxy AI calls. Secrets you keep locally — an API key or token stored on your own machine — stay there. If you instead choose to store a credential with ClusterCode (for example, to provision a Cloud Worker), we hold it encrypted and decrypt it only at launch to inject into your workload; it is never exposed to our AI models, logs, or run history. Cloud Workers are an exception. If you choose to run on a ClusterCode Cloud Worker, the compute is cloud-hosted and managed by ClusterCode, so the code, credentials, and agent activity for that run are processed on ClusterCode-managed cloud infrastructure (currently Microsoft Azure, in the United States) rather than on your own hardware. If you use Session Portability (see below), an encrypted copy of your session configuration is also stored so it follows you across workers; your workspace (your source code) is never copied to our storage, on any worker. Cloud Workers are optional and are not available on the Free plan.

Session Portability

Your agent can pick up exactly where you left off — on any worker. With portability, your session history travels with you instead of being stranded on the one machine that created it. When portability is on, we keep an encrypted copy of the covered data — your agent configuration and session history — in our cloud storage (Microsoft Azure, US), encrypted with a key unique to your account. We use it for one purpose only: restoring your sessions to your own workers when you launch. We never copy or store your workspace files (your source code), on any worker — your code lives in your repositories and on the machine that made it. We do not read it, analyze it, share it, or use it to train any model. You stay in control: • It is on by default for Cloud Workers and opt-in for self-hosted / bring-your-own workers. Only your session history and configuration ever sync — never your workspace files, on any worker. • You can turn it off at any time in Settings, and delete your stored data with a single action. • Deleted data leaves a short recovery window (currently 14 days) to undo an accidental deletion, then is permanently removed.

AI and Model Training

We do not use your source code, repository contents, or AI agent outputs to train, fine-tune, or improve any machine-learning model. For self-hosted workers, that content never reaches our servers at all (see "Data Architecture and Your Code"); for Cloud Workers, it is processed on our infrastructure only to run the workloads you initiate, and is never used to train, fine-tune, or improve any model. AI agents run on your hardware against the model provider you configure (for example, Anthropic) using your own API key. Your use of those providers is governed by their terms and privacy policies. We will not introduce any training use of your content without your explicit, opt-in consent.

Legal Basis for Processing (GDPR)

If you are in the European Economic Area (EEA), the United Kingdom, or Switzerland, we process your personal data under the following legal bases: • Performance of a contract — to provide the service you signed up for (account, billing, support). • Legitimate interests — to secure, maintain, and improve the service and prevent abuse, balanced against your rights. • Consent — where required (e.g. optional communications); you may withdraw consent at any time. • Legal obligation — to comply with applicable laws, tax, and accounting requirements.

Your Privacy Rights

Subject to applicable law, you have the right to: access the personal data we hold about you; rectify inaccurate data; erase your data ("right to be forgotten"); restrict or object to processing; receive your data in a portable format; and withdraw consent. You also have the right to lodge a complaint with your local data protection supervisory authority. To exercise any of these rights, contact privacy@clustercode.io. We will respond within the timeframes required by law (generally one month under the GDPR). You will not be discriminated against for exercising your rights.

California Privacy Rights (CCPA/CPRA)

If you are a California resident, the California Consumer Privacy Act (as amended by the CPRA) gives you the right to: • Know the categories and specific pieces of personal information we collect, use, and disclose. • Delete personal information we have collected, subject to legal exceptions. • Correct inaccurate personal information. • Opt out of the "sale" or "sharing" of personal information. • Not be discriminated against for exercising your rights. We do not sell your personal information, and we do not share it for cross-context behavioral advertising. To exercise your California rights, contact privacy@clustercode.io. You may use an authorized agent to submit a request on your behalf.

International Data Transfers

ClusterCode LLC is based in the United States, and the data we process and store — account, billing, and telemetry data, plus any Cloud Worker activity and, where you enable it, encrypted session data — is currently hosted in the United States on Microsoft Azure. (For self-hosted workers, your source code and DevBox contents never reach our servers — see "Data Architecture and Your Code".) If you access the service from outside the United States, your personal data will be transferred to and processed in the United States. Where required for transfers from the EEA, UK, or Switzerland, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses (SCCs). As demand grows we may add data-processing regions elsewhere (e.g. Europe, Asia, or Latin America), and will update this policy to reflect any such change.

Children's Privacy

The service is intended for users who are at least 18 years old and is not directed to children. We do not knowingly collect personal information from anyone under 18. If we learn that we have collected such information, we will delete it promptly. If you believe a minor has provided us personal information, contact privacy@clustercode.io.

Security

We implement technical and organizational measures designed to protect your personal data, including encryption in transit (TLS) and at rest, access controls and least-privilege permissions for our systems, and ongoing monitoring. By design, when you use self-hosted or bring-your-own workers, your source code, AI agent outputs, and locally-stored secrets remain on your own hardware, which materially reduces the data at risk. Data that is stored with us — credentials you choose to save, and anything synced by Session Portability — is encrypted, including with a key scoped to your account (see "Data Architecture and Your Code" and "Session Portability"). No method of transmission or storage is completely secure, however, and we cannot guarantee absolute security. If we become aware of a personal-data breach that affects you, we will notify you without undue delay and, where the law requires it, notify the relevant supervisory authority within 72 hours of becoming aware. To report a vulnerability or a suspected security issue, contact security@clustercode.io.

Data Retention

We retain your account information for as long as your account is active or as needed to provide the service. DevBox run history and execution logs are retained for a limited period and then automatically purged; retention is applied on a flat schedule (it is not tied to your plan tier) and may change as the product evolves. If you use Session Portability, your encrypted sessions are kept until you turn the feature off or delete them, and remain in a short recovery window (currently 14 days) after deletion before they are permanently removed. Technical data (IP addresses, request logs, and diagnostic telemetry) is retained for 90 days and then automatically deleted. You may request deletion of your account and associated data at any time by contacting support, and you can delete your stored sessions yourself at any time from Settings. One exception: where we suspend or terminate an account for fraud, abuse, or a breach of our Acceptable Use Policy, we keep a record of that action — the reason for it, who took it, and what was removed — together with the logs and resource-usage telemetry that evidence the violation. We keep both for as long as we need them to resolve disputes, to stop the same person returning, and to meet our legal obligations. That means those specific records are held beyond the ordinary retention periods described above, including the 90-day technical-data window, and we keep them even if you ask us to delete your account. They are not accessible from the suspended account.

Third-Party Services

We use the following third-party services: • Stripe — payment processing • Clerk — authentication and session management • Microsoft Azure — infrastructure hosting and transactional email delivery (via Azure Communication Services) • Google Analytics (Google LLC) — privacy-respecting configuration: Consent Mode v2 with region-aware defaults (opt-in before any analytics cookie in the EEA, the UK and Switzerland; opt-out elsewhere, revocable at any time), no advertising features, no Google Signals. Used to measure page visits and product usage. Each of these services has its own privacy policy governing its use of your data.

Cookies

For details on the cookies and similar technologies we use, see our Cookie Policy.

Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will post the updated policy here with a new "Last updated" date and, where appropriate, notify you by email or an in-product notice. We encourage you to review this page periodically.

Contact

If you have questions about this Privacy Policy, please contact us at privacy@clustercode.io.