Draft — pending attorney review. This page describes our actual data practices
accurately, but has not yet been reviewed and finalized by counsel. Treat it as directionally correct,
not yet a signed legal document.
Privacy policy
PinkyAI's local engine runs on your own machine and evaluates your code, commands, and prompts there — that content is never sent to us. This policy covers the smaller, separate set of data our cloud side (accounts, entitlements, opt-in telemetry) actually holds.
What we collect
| Data | Why | Retention |
|---|---|---|
| Account email and name | Identifies who signed in, via Auth0 | Until you delete your account |
| Organization membership and role | Authorization — what you can do in your org | Until you leave or are removed |
| Entitlement (plan, seat count) | What your org is licensed for | Indefinite, overwritten on plan change |
| Telemetry (rule-fire counts, tokens-saved buckets) — opt-in only | Understand product usage, in aggregate | Governed by our telemetry retention policy |
| Scanned file/command content | Never collected — evaluated locally by the engine, never sent to us | N/A |
Who processes it on our behalf
- AWS — Hosting for account, entitlement, and telemetry data
- Auth0 (Okta) — Identity and authentication
- Sentry — Error tracking — PII scrubbed before it's sent
We don't sell your data, and we don't share it with anyone outside this list except as required by law.
Your rights
You can request a copy of what we hold about you, or request deletion, by contacting us through your account's support channel. Account deletion removes your account, org memberships, and telemetry history from our systems.
See also: Security & trust, Data Processing Agreement, Cookie policy.