AutoDevTool

Privacy Policy

Last updated: September 8, 2026

This policy explains what data we process when you use AutoDevTool, what we use it for, who we share it with and what you can require from us. It is written so that anyone can understand it, not just a lawyer.

Document in preparation. AutoDevTool is in a pre-commercial-launch phase and the company that will own the service is still being incorporated, so the controller's details, its registered address and the jurisdiction appear as [ENTIDAD], [DOMICILIO] and [JURISDICCIÓN]. The processing described corresponds to how the product actually works, but the text must be reviewed with a lawyer and completed with those details before being published as final.

1. Who processes your data

The data controller is [ENTIDAD], with registered address at [DOMICILIO]. You can contact us at [CORREO DE PRIVACIDAD].

This policy covers the website, the customer portal and the development automation service.

2. Our commitment regarding your data and artificial intelligence

On our side, your data is not used to train any artificial intelligence model, nor is it transferred or shared with third parties for that purpose. Your code, your tickets and the content of your projects are processed solely to provide you with the service you have purchased.

When you connect your own account with an artificial intelligence provider, the terms of that account are what govern what that provider does with the data it processes using your key. That relationship is between you and your provider: review their terms, because we cannot modify them and we are not liable for them.

In full mode, access to the model provider is supplied by us and we contract it under terms that exclude the use of your content for training.

You should know the exact scope: whether you use your account or ours, your code is cloned and executed on our infrastructure, and the key you entrust to us is stored encrypted in our systems. What changes with your own account is which credential is used to call the provider and who pays for that consumption.

3. What data we process

We process the following categories of data:

If you link Telegram to receive notifications, we process your identifier for that account and the content of the notifications we send you.

  • Contact details you provide in the forms: name, email address and the message you write. We do not record your IP address or your browser when you submit them.
  • Account data: email, name, encrypted password, language, time zone and your dashboard preferences.
  • Billing data: your customer and payment identifiers at the payment gateway, amounts and status. Your card details are processed directly by the payment provider and are never stored in our systems. In the payment records we do store the IP address and browser from which the payment was made, as an anti-fraud measure.
  • Integration credentials that you hand over to us to access your repositories, your ticket tracker and your artificial intelligence provider. They are stored encrypted and are not readable from the application.
  • Content of your projects: tickets, source code and the artifacts the service generates while working on them.
  • Execution records: what the engine did with each ticket, with what result, how much consumption it generated and the full transcripts of each agent session, which include fragments of your code.
  • Security records: open sessions, relevant changes to the data and the associated IP addresses and browsers, necessary to detect improper access.

4. What we use it for and on what basis

We use your data to provide you with the service you have purchased, which is the main legal basis: without it we cannot carry out the work you ask of us.

We also use it to comply with legal obligations, such as accounting and tax obligations, and for our legitimate interest in maintaining the security of the platform, preventing abuse and improving the product based on aggregated data that does not identify you.

When you write to us through a form, we use that data to reply to you. If you also want to receive commercial communications, we will ask you separately and you will be able to withdraw it whenever you want.

5. Who we share it with

We do not sell your data. We share it only with the providers necessary for the service to work, who act on our instructions and are subject to confidentiality obligations:

We may also disclose data when a legal obligation or an order from a competent authority requires us to.

  • Anthropic, as the provider of the artificial intelligence models. It receives the fragments of tickets and code needed to generate the changes. In full mode we create a separate workspace for each customer.
  • Stripe, as the payment gateway. It processes your billing data and your card details, which never reach our systems.
  • Resend, as the email provider, for service notifications and replies to your enquiries.
  • Telegram, only if you link that account to receive notifications.
  • Contabo, as the hosting provider, where the platform and the service instances run.
  • The systems you connect, such as your ticket tracker and your code repositories, which remain yours and are governed by your own agreements with them.

6. Isolation between customers

Each customer operates on its own instance of the engine, in a container with dedicated storage volumes, its own database and its own credentials. One customer's work and code do not run in the same environment as another's.

You should know the exact scope: that isolation is at the container and storage level, not at the physical machine level. The instances share a server, and account and billing data live in a database common to all customers, protected by access control.

7. International transfers

Some of our providers may process data outside your country. When that happens, we will rely on the appropriate legal transfer mechanisms, such as standard contractual clauses.

The specific destinations will be detailed in this policy once the list of providers is finalized.

8. How long we keep it

The full transcripts of agent sessions and the audit reports, which are the most sensitive data because they contain your code, are deleted automatically after ninety days. The summary of the work and its metadata are retained so that you can consult your history.

Telegram notification messages are deleted after thirty days.

Your account, project and billing data are retained while the contract is in force. Once the contract ends, we delete or anonymize it, except for what we must keep by legal obligation, such as accounting and tax documentation, and except for what is necessary to defend ourselves against possible claims during the applicable limitation period.

The entries in the consumption log are immutable by design: they are not edited or deleted, because they are the evidence of what you have been charged.

9. Security

We apply technical and organizational measures to protect your data. The credentials you entrust to us are stored encrypted and are not readable from the application; traffic travels encrypted; each customer has its own instance and its own separate volumes; and sessions use cookies that are inaccessible from the page's code.

We log relevant changes to the data so that they can be audited.

No system is infallible. If a security breach affecting your data were to occur, we would inform you and would notify the competent authority where the law requires it.

10. Your rights

You may exercise the following rights at any time by writing to us at [CORREO DE PRIVACIDAD]:

We will respond within the period set by applicable law. If you consider that we have not handled your request properly, you may lodge a complaint with the data protection authority of your country.

  • Access the data we hold about you.
  • Rectify data that is inaccurate.
  • Request its erasure when it is no longer necessary.
  • Restrict or object to certain processing.
  • Receive your data in a portable format.
  • Withdraw your consent where the processing is based on it, without this affecting what was processed beforehand.

11. Cookies and browser storage

This site does not use cookies. There is no third-party analytics, no advertising pixels and no tracking tools of any kind.

We use browser storage for one thing only: if you arrive from a referral, storing the identifier of whoever referred you for ninety days, so that it can be attributed correctly. You can delete it by clearing the site data.

The customer portal does use cookies that are strictly necessary to keep your session logged in and to remember whether your side menu is open or closed. They do not require consent because without them the portal does not work.

12. Minors

The service is aimed at professionals and companies. We do not offer it to minors and we do not knowingly process their data.

13. Changes to this policy

If we modify this policy, we will update the date in the header. When the change is material, we will notify you by email or from within the product before it takes effect.

To exercise your rights or ask anything about this policy, write to us at [CORREO DE PRIVACIDAD].

← Back to AutoDevTool