Privacy Policy
We built aForce so your code stays yours. This policy explains what we collect, why, where it's processed, and your choices.
01. Scope and who we are
This Privacy Policy explains how Neotyk Labs, LLC ("Neotyk", "we", "us") collects and uses personal data when you visit neotyk.ai, use console.neotyk.ai, start a trial, or use the aForce Services. For personal data contained in Customer Materials that we process on a customer's behalf, we act as a processor under the customer's instructions and our agreement with them.
Contact: [email protected].
02. Information we collect
- Account and trial data: name, work email, company, team size, plan, and authentication identifiers (for example GitHub, Google or SSO).
- Integration metadata: connected repository names, issue-tracker tickets you assign, chat channels you connect, and scoped access tokens you authorize.
- Execution data: code checked out into sandboxes, test and build output, and agent activity logs that form the audit trail.
- Billing data: plan, invoices and tax location. Card details are handled by our payment provider; we do not store full card numbers.
- Technical data: IP address, browser details, session logs, usage metrics (such as model token counts) and error diagnostics.
03. How we use information
- To provide the Services: run agents on assigned work, post standups and reports, and enforce approval gates.
- To manage accounts, trials, usage allowances and billing.
- To secure the Services: authentication, sandbox isolation, abuse and fraud prevention, and sanctions screening.
- To provide support and send service communications.
- To improve the Services using aggregated, de-identified usage metrics (never your code or Outputs).
04. Legal bases (EEA/UK users)
Where the GDPR or UK GDPR applies, we process personal data to perform our contract with you, for our legitimate interests in operating and securing the Services, to comply with legal obligations, and with your consent where required (for example, optional marketing emails).
05. Your code is never training data
We do not use Customer Materials, code, tickets or Outputs to train, retrain or fine-tune any AI model. We use AI model providers under terms that prohibit training on customer data.
06. Where data is processed
Starter and Teams data is processed and stored in the United States. Enterprise customers may run the platform in their own cloud account, with data kept in the region they choose, or on a dedicated single-tenant Neotyk instance. We may introduce additional regions, including a European region, as demand grows.
When personal data is transferred from the EEA, UK or Switzerland to the United States, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses. A Data Processing Agreement is available on request.
07. Service providers (subprocessors)
| Provider | Purpose | Location |
|---|---|---|
| Cloudflare, Inc. | DNS, CDN, DDoS protection, website hosting | Global / USA |
| Cloud hosting providers | Application hosting, databases, secret management | United States |
| AI model providers | Model inference for agents, under no-training terms | United States |
| Stripe, Inc. (when paid plans are enabled) | Payments, tax calculation, seller of record for self-serve plans | United States |
We require service providers to protect personal data under written agreements. We will update this list as providers change.
08. Retention
- Sandboxes: deleted when each task ends.
- Audit trail: retained for the life of your account, or as configured on Enterprise.
- Trial accounts: if a trial is not converted, account data is deleted within 30 days after the trial ends.
- Closed accounts: data is available for export for 30 days, then deleted, unless the law requires us to keep it longer (for example, billing records).
09. Your rights
Depending on where you live, you may have the right to access, correct, delete or port your personal data, to object to or restrict certain processing, and to withdraw consent. California residents have rights under the CCPA/CPRA, including the right to know and delete. We do not sell or share personal data for cross-context behavioral advertising. To exercise your rights, email [email protected]. You may also lodge a complaint with your local data protection authority.
10. Cookies
We use only essential cookies needed for sign-in, security and session management. We do not use third-party advertising or behavioral tracking cookies.
11. Security
We protect data with isolated sandboxes, scoped short-lived credentials, encryption in transit and at rest, access controls and audit logging. No method of transmission or storage is completely secure.
12. Children
The Services are intended for businesses and are not directed to children under 16. We do not knowingly collect their personal data.
13. Changes to this policy
We may update this policy from time to time. We will post the updated version here and, for material changes, notify account holders by email or in the console.