# Privacy policy

> **Draft. Not legal advice and not in force.** This policy was drafted from how the software works and has not been reviewed by a lawyer. It must be reviewed by a qualified lawyer before Cordbay is sold or this page is relied on. Text in [SQUARE BRACKETS] is a placeholder that still has to be filled in or confirmed.

Last updated: [EFFECTIVE DATE]

This policy explains what information Cordbay handles, where it goes and what [YOUR COMPANY NAME] ("we", "us") does with the little of it that reaches us. It covers the Cordbay desktop app, the `cordbay` command-line tool, the `cordbay-tui` terminal UI (together, "the app") and the website at cordbay.com.

## The short version

- The app keeps its data on your computer.
- Your skills and agents sync through a git repository that you own. We do not run a sync server, and your skills and agents are never sent to us.
- To activate a licence and check it about once a day, the app sends our licence service the licence key and a few details about the computer: a random id, its name in Cordbay, its operating system and the app version.
- The app calls GitHub and skills.sh to find, install and update skills.
- The app sends the text of a skill to TypeSafe AI only if you add your own Jev API key, and only to score that skill.
- The app contains no analytics, advertising or tracking. [TO CONFIRM BEFORE RELEASE: still true once update checks are added.]
- If you ask for launch news on cordbay.com, your email address is kept with our email provider, Resend, so we can send you one email when Cordbay launches. Every email has an unsubscribe link.

## Who is responsible

[YOUR COMPANY NAME], [YOUR REGISTERED ADDRESS], is the controller of the personal data described in "What reaches us" below. Contact: [YOUR CONTACT EMAIL].

For everything the app stores on your own computer or sends to your own git repository, you are in control and we have no access.

## What the app stores on your computer

| Data | Where | Purpose |
| --- | --- | --- |
| Settings: the coding agents you manage, the URL and local folder of your sync repository, the folders you watch for git repositories | `settings.toml` in your user config folder | To run the app as you set it up |
| Machine identity: a random id and a label, which starts as your computer's hostname | `machine.json` in the same folder | To tell your machines apart |
| Sync bookkeeping | `applied.json` and `sync.lock` in the same folder | To know what has been synced |
| Licence state: the licence key (which contains your email address), when the trial started, and the licence service's last signed answer | `licence.json` in the same folder, readable only by your user | To know whether the app is licensed, also while offline |
| A clone of your sync repository | The app's data folder | To sync while offline |
| API keys you add (a Jev API key) | Your operating system's keychain (macOS Keychain, Windows Credential Manager, Linux Secret Service), or a file only your user can read where no keychain is available | To call the service the key belongs to |
| Your skills and agents | `~/.agents/skills`, `~/.agents/agents` and the skill folders of the coding agents you manage | They are your files; the app reads and writes them at your request |
| Only if you turn the agent mesh on: the machine's private mesh keys | Your operating system's keychain, or the file used where there is none | To sign and decrypt tasks between your machines |
| Only if you turn the agent mesh on: the machines you trust and their public keys, the tasks sent from and to this machine (prompts and answers), and a log of what happened | The app's config and data folders, readable only by your user | To run tasks between your machines and show you what happened |

None of this is sent to us, except what licence activation sends (see "What reaches us"). API keys, the licence key and private mesh keys are never written to the sync repository.

## What the app sends to your git repository

When you sync, the app commits and pushes to the private git repository you configured, using the git program and the credentials already on your computer:

- your skills and agents;
- an optional `cordbay.toml` file with per-machine rules;
- on a separate `state` branch, one file per machine with: the machine's id and label (your hostname by default), its operating system, the names and sources of its installed skills, the names of its agents, and, for each git repository under the folders you chose to watch, its local path, current branch, whether it has uncommitted changes, how far it is ahead of or behind its upstream, when it was last fetched, and the address of its remote with any user name, password or token removed; which coding-agent programs are installed and their versions; and, only while the agent mesh is on, the machine's public mesh keys;
- only if you turn the agent mesh on, on a separate `cordbay-mailbox` branch: tasks sent between your machines and their answers, each encrypted so that only the receiving machine can read it. Your git host can see which machine sent a message to which, when, and its size, but not its contents. Messages are removed once delivered.

This goes to the git host you chose (for example GitHub, GitLab or your own server) and is governed by your agreement with that host. We never receive it.

## Outside services the app calls

The app contacts these services directly from your computer. As with any internet request, each service sees your IP address. We do not receive copies of these requests.

| Service | When | What is sent |
| --- | --- | --- |
| Your git host | When you set up sync or sync | The contents described in the section above, through git |
| GitHub (`api.github.com`) | When you check skills for updates | The owner and name of each GitHub repository your skills were installed from. No login is sent. [TO CONFIRM: if a GitHub token setting is added, the token is sent to GitHub with these requests.] |
| GitHub (`github.com`) | When you install or update a skill | A `git clone` of the repository that holds the skill, using your own git credentials if the repository is private |
| skills.sh [TO CONFIRM: operator and its privacy policy] | When you search for skills | Your search text and the number of results asked for |
| TypeSafe AI (`api.typesafe.ai`), the Jev service | Only if you have added a Jev API key, and only when a skill is scored | The text of that skill's `SKILL.md` file, the scoring question, and your Jev API key |
| A coding-agent command-line tool on your computer (Claude Code or Codex) | Only when you ask the app to generate an agent | The name, one-line description and skill names you typed. That tool then contacts its own provider (Anthropic or OpenAI) under your account with them |

Each of these services handles what it receives under its own terms and privacy policy. If you never add a Jev API key, the app sends nothing to TypeSafe AI.

## What reaches us

We receive personal data only in these cases:

- **Buying a licence.** Payments are handled by [PAYMENT PROVIDER], acting as [merchant of record / payment processor, TO CONFIRM]. They collect your name, email address, billing details and payment details. We receive [TO CONFIRM: for example your name, email address, country, what you bought and a licence key], and never your full card number.
- **Licence activation.** When you activate a licence key, about once a day while one is activated, and when you deactivate it, the app sends our licence service, Sealcord (`api.sealcord.com`): the licence key, which contains the email address it was sold to; the computer's random id from `machine.json`; the computer's name in Cordbay (your hostname unless you renamed it); its operating system (for example `macos`); and the app's version. We keep a record of each computer a licence is activated on and when it was last seen, so a licence stays within the computers it covers (up to 3) and you can free one to use another. Like any web service, it also sees the IP address each request comes from, which it uses to limit how often it can be called. [TO CONFIRM: where the service is hosted and how long activation records and logs are kept.]
- **Update checks.** [TO CONFIRM once built: what the app sends when it checks for a new version, for example the current version and operating system.]
- **Launch news.** If you enter your email address in the form on cordbay.com, see "Launch news by email" below.
- **Support.** If you email us, we receive your email address and whatever you include in the message.
- **The website.** Our hosting provider, [HOSTING PROVIDER], keeps standard server logs (IP address, time, page requested, browser type) [TO CONFIRM: retention period]. The website sets no cookies and loads no analytics or advertising scripts. It stores one value in your browser's local storage, your light or dark theme choice, which never leaves your browser. Search in the documentation runs inside your browser.

## Launch news by email

Before Cordbay goes on sale, the home page at cordbay.com has a form for one email when it launches.

- **What we keep.** The email address you enter, and when you entered it. Nothing else is asked for.
- **Where.** The form sends your address to a small program on our hosting provider's servers, which adds it to a contact list held by Resend ([resend.com](https://resend.com)), the service we use to send email. That program keeps nothing itself. It sees your IP address, as any web request does, and uses it only to limit how many times one address can submit the form in a few minutes; it does not store it. [TO CONFIRM: where Resend stores contact data, and the data processing agreement with Resend.]
- **Why.** To tell you when Cordbay launches. We use the address for nothing else, do not share it with anyone but Resend, and do not add it to any other list.
- **Unsubscribing.** Every email we send has an unsubscribe link, which takes you off the list at once. You can also write to [YOUR CONTACT EMAIL] and we will delete your address.
- **How long.** Until you unsubscribe or ask us to delete it, or until [RETENTION PERIOD after launch, TO CONFIRM], whichever comes first.

## Why we use it and on what basis

[FOR LAWYER REVIEW: confirm the legal bases for each jurisdiction you sell in.]

| Purpose | Data | Legal basis (GDPR) |
| --- | --- | --- |
| Selling you a licence and keeping it valid | Purchase and licence data | Performance of a contract |
| Tax and accounting records | Purchase data | Legal obligation |
| Sending launch news you asked for | Email address | Consent, which you can withdraw by unsubscribing |
| Answering support requests | Support messages | Legitimate interests |
| Keeping the website running and secure | Server logs | Legitimate interests |

We do not sell personal data, use it for advertising, or use your skills, agents or any other content to train AI models. We never have your content in the first place.

## Who we share it with

Only with service providers that act for us: [PAYMENT PROVIDER], [HOSTING PROVIDER], Resend (email), [the hosting provider of the licence service]. [TO CONFIRM: list, locations and data processing agreements.] We also disclose data where the law requires it.

## International transfers

[TO CONFIRM: where each provider stores data, and the safeguard used for transfers outside your country or the EEA/UK, for example standard contractual clauses.]

## How long we keep it

- Purchase records: [RETENTION PERIOD, usually set by tax law].
- Licence records: for as long as the licence is valid, then [RETENTION PERIOD].
- Launch news addresses: until you unsubscribe or ask us to delete yours, or [RETENTION PERIOD after launch], whichever comes first.
- Support messages: [RETENTION PERIOD].
- Server logs: [RETENTION PERIOD].

Data on your computer and in your git repository stays until you delete it. Removing the app does not delete your skills, agents or sync repository.

## Your rights

Depending on where you live, you may have the right to see, correct, delete, restrict or receive a copy of the personal data we hold about you, to object to its use, and to complain to your data protection authority. To use any of these, write to [YOUR CONTACT EMAIL]. [FOR LAWYER REVIEW: add jurisdiction-specific wording, for example GDPR, UK GDPR, CCPA/CPRA.]

## Security

API keys are kept in your operating system's keychain, or in a file restricted to your user account. The app reaches your git host with your existing git credentials and never stores them. No system is perfectly secure; keep your computer, your git host account and your API keys protected.

## Children

Cordbay is a tool for software developers and is not directed at children under [16 / AGE TO CONFIRM].

## Changes to this policy

We will post changes on this page and change the date at the top. [TO CONFIRM: how customers are told about material changes.]

## Contact

[YOUR COMPANY NAME], [YOUR REGISTERED ADDRESS], [YOUR CONTACT EMAIL].
