Privacy Policy

Last updated: 17 September 2026

Draft for review — not in effect. This document hasn’t been approved yet. Highlighted text in [brackets] is a detail still to be confirmed.

This Privacy Policy explains how Paddlewheel (“we”, “us”) collects, uses, shares and protects personal data when you use Paddlewheel: the website at paddlewheel.dev, the Paddlewheel app, and everything we provide through them (together, the “Service”). Read it together with our Terms of Service.

It doesn’t cover the apps you build with Paddlewheel. For the people who use those apps, you decide what data your app collects and why, and we process it on your behalf — see Your apps and their users.

1.Key points

A short summary to help you find your way. The full policy below is what applies.

  • We use your account details, projects and chats to run the Service, which includes sending your prompts and code to AI model providers.
  • We use your chats and code to train and improve AI models, ours and our AI providers’. Organizations on the Ultimate plan are excluded, and you can opt out by emailing us.
  • Product analytics and session recordings are off unless you turn them on, and you can turn them off at any time in Settings → Privacy.
  • Session recordings hide passwords, secrets and code, but show your chat messages. They’re deleted after 30 days.
  • We don’t sell your personal data, and we don’t use it for advertising.
  • Previews, deployed apps and community listings are public.
  • In the office, your organization sees where you are and what you’re doing, never how long. Voice is never recorded and office chat isn’t kept.
  • Paddlewheel is only for people aged 18 and over.
  • You can ask us to access, correct, export or delete your data.

2.Who we are

Paddlewheel, based in Bengaluru, Karnataka, India, decides how and why personal data is processed to provide the Service. Under the EU and UK GDPR that makes us the controller, and under India’s Digital Personal Data Protection Act, 2023 the data fiduciary.

For privacy questions and requests, and anything else, email support@paddlewheel.dev.

  • Grievance Officer (India): [Grievance Officer name], support@paddlewheel.dev, Bengaluru, Karnataka, India
  • Representative in the EU and UK: [Counsel: whether we need one, and their details]

3.What we collect

CategoryWhat it includesWhere it comes from
AccountEmail address, name, username and profile picture; your password, stored as a hash, if you set one; two-factor authentication settings and backup codes; your referral code. If you sign in with GitHub, your GitHub name, email address, profile picture and account ID.You, or GitHub
Sign-in and securityYour sessions, with the IP address and browser (user agent) each was created from; when you signed in and out; a security check when you sign in (Cloudflare Turnstile, which receives your IP address); any suspension or ban.Your device and our systems
Organizations and sharingOrganizations you create or join and your role in them; invitations, including the email addresses of people invited; people you share projects with.You and other members
Projects and AI chatsPrompts and chat messages, conversation history, answers you give the agent, files and images you attach, design systems, task lists, your projects’ code and files, build output, and what the AI generates.You and the Service
Environment variablesNames and values you add to a project. Values you enter on a project’s Environment Variables page are also kept in your browser’s local storage.You
Connected servicesGitHub: installation details, access tokens and repositories. Supabase: access tokens, project details and keys. Hosting accounts: access tokens and the account’s email address. Dodo Payments: your API key, if you connect your own account. Connectors from our catalog: your credentials, and a log of which tools were called — without their inputs or results.You and the service you connect
Deployments, domains and previewsDeployments and their build logs; custom domains and their DNS status. When people visit your previews or deployed apps, their requests pass through our servers, which process their IP address to deliver the page.You and our systems
CommunityListings you publish — title, text, category and screenshots — the stars you give, reports you make, and which signed-in users viewed a listing.You
BillingYour organization’s plan, subscription status and billing period; payment records (amount, currency, date and status); your customer ID at Dodo Payments. We create that customer record when you sign up, with your name and email address. Card and bank details go to Dodo Payments — we never receive them.You and Dodo Payments
Usage and activityAn activity log of what you do in the Service, such as creating a project, deploying or changing settings, with the IP address and browser used; your credit, AI and sandbox usage.Our systems
CommunicationsEmails we send you, such as sign-in links, invitations and billing notices, and what you send to support.You and our systems
Product analytics and session recordingsOnly if you turn them on — see Product analytics and session recordings.Your device and our systems
Privacy choicesYour analytics and recording choices, when you made them, the version of this policy they were made under, and your browser and language. For visitors who aren’t signed in, a random identifier instead of an account.You

Don’t put other people’s personal data or secrets into prompts or chat messages unless you need to — keep secrets in environment variables or connector settings instead. We don’t ask for special categories of personal data, such as health information.

4.How we use it, and why

PurposeFor exampleLegal basis (EU and UK)
Providing the ServiceYour account, projects, sandboxes, the AI agent, deployments, domains, integrations and community listingsPerforming our contract with you
Payments and creditsSubscriptions, credit packs, and billing emails such as failed-payment noticesContract; legal obligation, for tax and accounting records
Security and preventing abuseSign-in checks, rate limits, bans, reviewing community listings, investigating reportsOur legitimate interest in keeping the Service and its users safe; legal obligation
Support and service emailsAnswering you; sign-in links, invitations and billing noticesContract; legitimate interests
Understanding and improving the ServiceActivity logs, errors, AI cost and qualityLegitimate interests
Training and improving AI modelsChats and code, used to fine-tune our models, evaluate and improve our agents, and by AI providers to train theirs — see Training AI modelsLegitimate interests in improving the Service. You can opt out at any time
Product analytics and session recordingsSee Product analytics and session recordingsYour consent
Legal mattersResponding to lawful requests, enforcing our Terms, defending legal claimsLegal obligation; legitimate interests

[Counsel: confirm these legal bases, and the equivalent grounds under India’s DPDP Act]

We don’t sell your personal data or use it for advertising. An AI model checks community listings before they go live; if you think a decision about your listing is wrong, email support@paddlewheel.dev and a person will review it.

5.How AI processes your content

What goes to AI models

The agent sends AI model providers what it needs to do the work you ask for, including:

  • your messages, recent conversation history, and earlier conversations you mention;
  • your project’s code and files;
  • results from services you’ve connected, when the agent uses them;
  • for community listings, your app’s page text and your screenshots.

Requests go through an AI routing provider, which passes them to third-party AI model providers. If those fail, some coding requests go to free models through a second AI routing provider, which can route them to other model providers. [Confirm the current list of model providers, where they process data, how long they keep requests, and whether any of them may train on them]

Training AI models

We use your chats — your messages and the AI’s replies — and the code in your projects, including code the AI writes, to:

  • train and fine-tune our own AI models;
  • evaluate and improve our agents and prompts; and
  • let AI model providers use your requests to train and improve their models, under their own terms.

We don’t use environment variables or the credentials of services you connect. Content from organizations on the Ultimate plan isn’t used for training.

To opt out, email support@paddlewheel.dev from the email address on your account. Opting out applies to content from then on: it can’t be removed from models that have already been trained, or from requests AI providers already received.

Design and image tools

  • An AI design tool receives your app description to generate designs, and keeps the design projects it creates.
  • A web search and scraping provider receives a search term based on your app idea, to find design inspiration on public websites.
  • Stock image providers receive image search queries the AI writes. Images they return are loaded from their servers when your app is viewed.

Sandboxes

Your code runs in cloud sandboxes from a third-party provider. A sandbox holds your project and the keys it needs to work, such as an AI key for your organization, your Supabase project’s public key, and short-lived access to your connectors — not the connector credentials themselves.

Monitoring AI requests

For every AI request we record which organization, project, user, conversation and message it belongs to, the model used, and the tokens and cost — in our database and with an AI monitoring provider. The monitoring provider receives this metadata, not your prompts or the AI’s responses. [Confirm where the AI monitoring provider stores data]

Staff access and logs

Authorized Paddlewheel staff can view accounts, prompts, chats, code, sandboxes and logs, and can sign in as you (impersonation), when that’s needed to give you support, investigate abuse or security problems, or fix issues. Impersonation sessions are time-limited and recorded in the activity log, and they’re never included in product analytics. Our servers keep application logs, which can include the content of requests, such as prompts and the responses of services you’ve connected, for 30 days. [Confirm the staff access policy]

6.The office

The office is a shared space where your organization’s people, and a project’s agents, appear as characters. In it:

  • Presence. People in your organization, and people on projects you share, see whether you’re online, away or busy, your status, which Paddlewheel page or project you’re on, which room you’re in, and when you were last seen. They see where you are, never how long: nothing in the office measures anyone’s time, and there are no per-person reports.
  • Voice. Proximity voice and meetings go through a real-time media provider, between the people who are near each other. Voice is never recorded. We keep how long each person was connected, for the organization’s plan limits and billing; if your account is deleted, those rows stay for the organization without your name.
  • Chat. Office chat (nearby and everyone) isn’t stored: it lives in the server’s memory while the office is open, and is gone after a restart. Notes left on a desk are kept for 30 days.
  • Cloud computers. A cloud computer at your desk runs with our sandbox provider. What’s on it is private to you unless you share your screen with people standing near your desk; watching is view-only. It pauses when nobody’s using it, and it’s deleted after 30 days unused, if you leave the organization, or if your account is deleted.
  • Games, whiteboards and your look. Game results are kept for the organization’s leaderboard. Whiteboards keep what was drawn on them. Your avatar is kept per organization.
  • Reports and moderation. If someone reports you, the organization’s owners and admins see who reported whom, what they wrote, and where in the office it happened, never what was said in chat. Owners and admins can remove someone from the office for 10 minutes or turn their voice or chat off; each of these is recorded in the organization’s activity log.

Deleting your account removes your office data: your status, looks, desk and notes, game results, reports and your cloud computer, which is shut down first.

7.Product analytics and session recordings

To understand where Paddlewheel gets in people’s way, we use PostHog, hosted in the European Union (Frankfurt, Germany). Both are off unless you turn them on, and session recording can only be on while product analytics is.

How we ask

  • Visitors who aren’t signed in see a banner with equal Accept and Reject buttons. Your choice is kept in your browser, and we record it under a random identifier. If you sign in and haven’t chosen on your account yet, the choice is copied to your account.
  • New accounts are asked when they pick a username, with both options off; existing accounts are asked once.
  • If you say no, we won’t ask again for about six months, unless this policy changes in a way that affects them.
  • If your browser sends a Global Privacy Control signal, we don’t ask. Anything you turn on yourself in Settings still applies.

Product analytics

If you turn product analytics on, PostHog receives:

  • the pages you open, and your clicks on links, buttons and menus — with their visible text, such as the names of projects in the sidebar — and clicks that don’t seem to do anything;
  • events such as creating a project, sending a message (its length, not its text), how long a preview takes to load, deploy attempts and their results, errors in Paddlewheel, and requests that fail (the kind of request and its status code);
  • activity from our servers for things you do, such as a deployment that failed — as identifiers and counts, without error text or content;
  • errors from the app you’re building, while you preview it: the error’s name, the first line of its message (emails, web addresses and anything that looks like a secret removed; at most 200 characters), the file and the page path — and page changes within the preview;
  • your device type, browser, screen size, the page that referred you and campaign tags in links, and your IP address, which PostHog uses to estimate your location (country and city) and then discards;
  • answers you choose to send in surveys, such as Report a problem, with anything that looks like an email address or secret masked.

PostHog identifies you by your Paddlewheel user ID, never by your name or email address, and anything that looks like an email address or a secret is masked in the text of clicks and errors. Web addresses are sent without their query strings, except campaign and referral tags. Staff accounts are marked, so their activity can be left out of our reports.

Session recordings

If you also turn session recording on, PostHog records a replay of what you see and do in Paddlewheel: page changes, mouse movements, clicks, scrolling, and what’s on screen. In recordings:

  • your chat messages and notifications are visible, with anything that looks like a secret or email address hidden;
  • code in the editor and in diffs is masked, and text you type is hidden, except in the chat box;
  • the sign-in form, passwords, environment variables, connection credentials, the terminal, database queries and results, and account security settings are hidden completely;
  • email addresses are masked where the app shows them, such as in account menus and member lists, but names — yours and other people’s — can appear;
  • network requests are recorded as addresses and timing only, never their contents; console output isn’t recorded;
  • the preview of your app appears as a blank area, because it’s on a different website.

Recordings are deleted after 30 days. Analytics events are kept for 1 year.

Changing your mind

Turn either one off at any time in Settings → Privacy, or with Privacy choices at the bottom of our home page if you aren’t signed in. It takes effect straight away. Data already collected isn’t deleted automatically — email support@paddlewheel.dev and we’ll delete it. When an account is deleted, its analytics data and recordings in PostHog are deleted too.

Nothing is recorded while a staff member is signed in as you.

8.Who we share it with

Service providers

We use these providers to run the Service. They process personal data for us, under our instructions.

ProviderWhat they do for usWhere
Web hosting providerHosts the Paddlewheel website and appUnited States and worldwide
Google CloudRuns our servers, database and background jobsIndia [Confirm the database region]
CloudflareDNS, network protection, file storage and sign-in security checksWorldwide
Managed database providerSessions, sign-in links and short-lived dataIndia
Cloud hosting providerServes previews, deployed apps and custom domainsIndia
Sandbox providerThe sandboxes your code runs in, and cloud computers in the office[Location]
Real-time media providerVoice in the office, between the people talking. Nothing is recorded[Location (LiveKit Cloud, or self-hosted on our servers)]
AI routing providers, and the AI model providers aboveThe AI agent[Locations]
AI monitoring providerMonitoring AI requests (metadata only)[Location]
Design, web research and stock image providersDesigns, design research and stock imagesUnited States and elsewhere
Email delivery providerSending emailsUnited States
Dodo PaymentsPayments, as merchant of record[Location]
App hosting providerHosting deployed apps, on our account unless you connect your ownUnited States and worldwide
PostHogProduct analytics and session recordings, only if you turn them onEuropean Union (Germany)

[Confirm this list, each provider’s location, and that a data processing agreement is in place with each]

Services you connect

When you connect GitHub, Supabase, a hosting account, your own Dodo Payments account or a connector, we exchange with that service what’s needed to act on your behalf — for example, pushing your project’s code to GitHub. Their own privacy policies apply to what they do with it.

Other people

  • Your organization. Members of an organization can see its projects, its activity, and each other’s names, usernames and email addresses. Depending on their role, they can also manage members and billing.
  • The public. Anyone with the address of a preview or deployed app can open it. Community listings show your name, username and profile picture, and are public, including to people who aren’t signed in.

Other disclosures

We may disclose personal data when the law requires it or to respond to valid requests from authorities; to protect the rights, safety and property of our users, the public or us; in connection with a merger, acquisition or sale of assets, in which case we’ll tell you before your data becomes subject to a different privacy policy; or when you ask us to.

We don’t sell personal data, and we don’t share it for cross-context behavioral advertising.

9.International transfers

We’re based in India, and our providers process data in India, the United States, the European Union and other countries, so your data may be processed outside the country where you live. Where the law requires it, we protect those transfers with appropriate safeguards, such as the European Commission’s standard contractual clauses. [Counsel: the transfer mechanisms to name]

10.How long we keep it

DataHow long
Account and profileWhile your account exists. Deleting your account removes it from our database.
Projects, code and chatsWhile the project exists. Deleting a project in the app hides it, and it’s permanently removed from our database 30 days later.
SessionsUntil you sign out, or 7 days after you were last active
Sign-in links24 hours, or until used
Temporary data for resuming AI replies24 hours
Activity log180 days. If your account is deleted, entries remain without your user ID, but can still include the IP address and browser they were recorded with.
Billing records8 years, as Indian tax and accounting law requires
Privacy choice recordsKept as evidence of what you agreed to, including after your account is deleted, for 3 years after you made the choice.
Session recordings and analytics eventsRecordings: 30 days. Events: 1 year. Both are deleted when your account is.
Community listingsUntil you unpublish them. We keep a listing’s versions and statistics after that, and screenshots already published at public addresses may remain.
Server logs and backups30 days

Copies we don’t yet remove automatically

When you delete a project or your account, some copies aren’t removed automatically yet: your project’s code in our file storage, apps hosted on our hosting account, design projects at our AI design tool, and your customer record at Dodo Payments. Email support@paddlewheel.dev and we’ll delete them. [Engineering: remove these automatically, then update this section]

We may keep data longer where the law requires it, or to resolve disputes and enforce our agreements.

11.Your rights and choices

Depending on where you live, you may have the right to:

  • access the personal data we hold about you, and get a copy of it in a portable format;
  • correct data that’s wrong or incomplete;
  • have your data deleted;
  • object to, or ask us to restrict, how we use it — including where we rely on legitimate interests;
  • withdraw your consent at any time, without affecting what was done before;
  • complain to a data protection authority.

Doing it in the app

  • Product analytics and session recordings: Settings → Privacy.
  • Your name, username and password: account settings.
  • Connected services: disconnect them in your project or organization settings.
  • Community listings: unpublish them from the project.

Asking us

For anything else — including opting out of AI training, and deleting your account, which isn’t self-serve yet — email support@paddlewheel.dev from the email address on your account. We may need to confirm it’s you. We’ll respond within 30 days, and won’t treat you differently for using your rights.

India

Under the Digital Personal Data Protection Act, 2023, you can also nominate someone to exercise your rights if you die or become incapacitated, and raise a grievance with our Grievance Officer (see Who we are). If you’re not satisfied with our response, you can complain to the Data Protection Board of India.

European Economic Area and United Kingdom

You can complain to the data protection authority where you live or work, or where you think a breach happened.

United States

Some US state laws give residents rights to know, access, correct and delete personal data, and to opt out of its sale or sharing for targeted advertising. We don’t sell or share personal data that way. We treat a Global Privacy Control signal as a request not to be asked about analytics.

12.Cookies and browser storage

We use cookies and your browser’s local storage for these purposes. We don’t use advertising cookies.

WhatWhyHow long
Sign-in cookiesKeep you signed in, including to several accounts at once7 days after you were last active, or until you sign out
Last sign-in methodShow which way you signed in last time30 days
pw-theme, sidebar_stateRemember your theme and whether the sidebar is open1 year; 7 days
Cloudflare securityProtect sign-in against botsSet by Cloudflare
Local storageYour selected organization, display and theme settings, your privacy choices, progress through sign-in, deploy attempt counts, and environment variable values for projects you editUntil you clear your browser’s data
PostHog cookie (ph_…) and local storageProduct analytics and session recordings — only if you turn them on1 year, or until you turn them off

The Service doesn’t respond to Do Not Track signals, which have no agreed standard. It does respond to Global Privacy Control, as described in Product analytics and session recordings.

13.Security

We protect personal data with measures including:

  • encrypted connections (HTTPS) to the Service;
  • passwords stored as hashes, and optional two-factor authentication;
  • encryption of stored credentials for connectors, Supabase, hosting accounts, the GitHub app and your own Dodo Payments account;
  • a scan for secrets before code is pushed to GitHub;
  • access to production systems limited to authorized staff, and a record of staff sign-ins to user accounts.

No system is completely secure. If a breach affects your personal data, we’ll tell you and the relevant authorities as the law requires. To report a security issue, email support@paddlewheel.dev.

14.Children

Paddlewheel is only for people aged 18 and over, and we don’t knowingly collect personal data from anyone younger. If you think someone under 18 has an account, email support@paddlewheel.dev and we’ll delete it.

15.Your apps and their users

For personal data your apps collect from their users, you’re responsible as the controller, and we process that data only on your behalf, to build, host and run your app. That includes data in databases you connect, such as Supabase — which stays in your own Supabase account — and data that passes through your previews and deployed apps.

Give your app’s users the privacy information the law requires, and get any consent it needs, for example for analytics you add.

16.Changes to this policy

We’ll update this policy when the Service or the law changes. The “Last updated” date at the top shows when it last changed. If a change is material, we’ll tell you by email or in the app before it takes effect, and if it affects product analytics or session recordings, we’ll ask for your choice again — until you answer, they stay off.

17.Contact us

Paddlewheel
Bengaluru, Karnataka
India
Email: support@paddlewheel.dev

Privacy Policy — Paddlewheel