Last updated 12 August 2026

Privacy

This page describes what actually happens, checked against the code that does it. If you find a difference between this page and the product, the product is the bug — write to us and we will fix one of the two.

What we store

Your address

Signing in needs an email address, and we keep it. There is no password to store. The six-digit codes are kept hashed and expire in ten minutes; your session is a cookie whose token we also only ever hold as a hash.

What is on your board

Tasks, their specs, the zone map you agreed with your agent, grants, access requests and the event record of what was decided and when. This is the product — it is the reason the board exists — and it is yours. We do not read it to build anything else, and it is not used to train any model.

Machines you connect

When you pair a machine or create a connector, we store a hash of its token, the label you gave it, who paired it and when it was last seen. The token itself we cannot recover — which is also why revoking is the only remedy if one leaks, and why the machines table on the pairing page shows you every one that exists.

If you filled in the form on the home page

Your address, which harness you use and roughly what size of team. Three fields, in our own database, used to decide what gets built next.

What we do not do

Cookies

Three kinds, and two of them only if you agree:

Who else sees it

Three, and only these three:

How long it stays

Board content stays until you delete it or ask us to. Sign-in codes die in ten minutes. Sessions end when you sign out. Revoked machines stay listed, deliberately: the record that something was connected is part of what an audit trail is for.

Getting it back, or getting rid of it

Write to paulo@commitcycle.com and ask for a copy of your data or for it to be deleted. We will do it, and we will tell you when it is done. If you are in the EU or the UK you have these rights by law; you have them here regardless of where you are, because two policies would just mean the worse one is the real one.

Who operates this

CommitCycle is operated by the maintainer of the CommitCycle project, reachable atpaulo@commitcycle.com, which is the address for privacy questions, deletion requests and legal notice.

Stated plainly because it matters to anyone deciding whether to trust this:a registered company entity and its jurisdiction are not published here yet. If your policy requires a named legal counterparty before you connect a repository, that requirement is not met today — and we would rather you knew that from this page than found out later.

Changes

If this page changes in a way that affects what we do with your data, we will write to the address you signed in with. The date at the top is the date it last changed.