01The short version
- Your agent conversations, project files and code stay on your computer. We do not upload or store them.
- Requests to the AI models pass through our gateway so we can bill credits. We keep usage metadata (time, level, model, token counts, status), not the content of your prompts or answers.
- Payments are processed by XPay. Card details are entered in the secure XPay field on our checkout page; we never see or store your card number.
- We do not sell your data and we do not use it for advertising.
02Information we collect
Account information
Your email address, display name and avatar, and your sign-in method (email and password, Google or GitHub). Passwords are handled by our authentication provider and are stored only as secure hashes.
Usage and billing records
- For every model request: date and time, quality level, model, prompt and completion token counts, latency, result status and the credits charged.
- Your credit ledger: top-ups, plan grants, redeemed codes, coupons used and usage charges.
- Purchase records: amount, currency, coupon, status and the payment reference returned by XPay.
Image generation
When you ask the agent to generate an image, we store the English prompt, the mode, the model, the status and the file size, to enforce daily limits and charge credits. The generated image itself is saved in your project folder, not on our servers.
Diagnostics
If the app or website hits an error, it may send an error report: the error message and stack trace, app version, operating system and the page path (never query strings). Reports never include your files or conversation content.
Feedback you choose to send
If you rate a reply or send a remark, we store your rating or note together with a short excerpt of that prompt and reply, so we can improve the service. Sending feedback is always optional.
Information stored on your device
- The desktop app keeps your sign-in session, conversations, settings and any service connections (for example GitHub) in your user folder (
~/.dsh). - The website stores your language and theme preferences and your sign-in session in your browser.
- An anonymous install identifier is used to tell installations apart in diagnostics.
03Your prompts, code and files
The agent runs on your computer. It reads and edits files only inside the folders you open and within the permission mode you choose. To answer you, the relevant part of the conversation is sent through our gateway to the AI model provider configured for your quality level, and the answer is streamed back.
Our gateway does not store request or response bodies. The model providers we route to process the content to produce the answer, under their own terms and privacy policies.
Do not paste secrets such as passwords or private keys into a conversation. Anything in the conversation can be sent to the model.
04How we use information
- To provide the service: sign-in, routing model requests, enforcing your plan, credits and daily limits.
- To bill accurately and show you your balance, usage history and receipts.
- To send service notifications such as a low balance or a plan about to expire.
- To keep the service secure, prevent abuse and fraud, and fix errors.
- To improve quality, using aggregated statistics and the feedback you choose to send.
06How long we keep it
- Gateway request logs: 30 days.
- Credit ledger and purchase records: kept while your account exists and as long as accounting and tax rules require.
- Error reports and feedback: kept as long as they are useful for fixing and improving the service.
- Account data: until you ask us to delete your account.
07Security
Traffic is encrypted with HTTPS. Database access is restricted per user by row-level security. Provider API keys are encrypted in a secrets vault, and server backups are encrypted before they leave the server. No system is perfectly secure, so please use a strong, unique password.
08Your choices and rights
- View and edit your profile at any time from the website.
- See your full usage and credit history on the dashboard.
- Sign out of the desktop app at any time; this removes the session stored on that computer.
- Ask for a copy of your data, a correction, or deletion of your account by writing to [email protected]. Deleting your account permanently removes any remaining credits, which are not refundable.
09Children
CodeScout is not intended for children under 16, and we do not knowingly collect their information.
10Changes and contact
We may update this policy. When we make a significant change we will notify you on the website or in the app, and the date at the top will change.
Questions? Contact us at [email protected].