1.Key points
A short summary to help you find your way. The full policy below is what applies.
- We use your account details, projects and chats to run the Service, which includes sending your prompts and code to AI model providers.
- We use your chats and code to train and improve AI models, ours and our AI providers’. Organizations on the Ultimate plan are excluded, and you can opt out by emailing us.
- Product analytics and session recordings are off unless you turn them on, and you can turn them off at any time in Settings → Privacy.
- Session recordings hide passwords, secrets and code, but show your chat messages. They’re deleted after 30 days.
- We don’t sell your personal data, and we don’t use it for advertising.
- Previews, deployed apps and community listings are public.
- In the office, your organization sees where you are and what you’re doing, never how long. Voice is never recorded and office chat isn’t kept.
- Paddlewheel is only for people aged 18 and over.
- You can ask us to access, correct, export or delete your data.
2.Who we are
Paddlewheel, based in Bengaluru, Karnataka, India, decides how and why personal data is processed to provide the Service. Under the EU and UK GDPR that makes us the controller, and under India’s Digital Personal Data Protection Act, 2023 the data fiduciary.
For privacy questions and requests, and anything else, email support@paddlewheel.dev.
- Grievance Officer (India): [Grievance Officer name], support@paddlewheel.dev, Bengaluru, Karnataka, India
- Representative in the EU and UK: [Counsel: whether we need one, and their details]
3.What we collect
| Category | What it includes | Where it comes from |
|---|---|---|
| Account | Email address, name, username and profile picture; your password, stored as a hash, if you set one; two-factor authentication settings and backup codes; your referral code. If you sign in with GitHub, your GitHub name, email address, profile picture and account ID. | You, or GitHub |
| Sign-in and security | Your sessions, with the IP address and browser (user agent) each was created from; when you signed in and out; a security check when you sign in (Cloudflare Turnstile, which receives your IP address); any suspension or ban. | Your device and our systems |
| Organizations and sharing | Organizations you create or join and your role in them; invitations, including the email addresses of people invited; people you share projects with. | You and other members |
| Projects and AI chats | Prompts and chat messages, conversation history, answers you give the agent, files and images you attach, design systems, task lists, your projects’ code and files, build output, and what the AI generates. | You and the Service |
| Environment variables | Names and values you add to a project. Values you enter on a project’s Environment Variables page are also kept in your browser’s local storage. | You |
| Connected services | GitHub: installation details, access tokens and repositories. Supabase: access tokens, project details and keys. Hosting accounts: access tokens and the account’s email address. Dodo Payments: your API key, if you connect your own account. Connectors from our catalog: your credentials, and a log of which tools were called — without their inputs or results. | You and the service you connect |
| Deployments, domains and previews | Deployments and their build logs; custom domains and their DNS status. When people visit your previews or deployed apps, their requests pass through our servers, which process their IP address to deliver the page. | You and our systems |
| Community | Listings you publish — title, text, category and screenshots — the stars you give, reports you make, and which signed-in users viewed a listing. | You |
| Billing | Your organization’s plan, subscription status and billing period; payment records (amount, currency, date and status); your customer ID at Dodo Payments. We create that customer record when you sign up, with your name and email address. Card and bank details go to Dodo Payments — we never receive them. | You and Dodo Payments |
| Usage and activity | An activity log of what you do in the Service, such as creating a project, deploying or changing settings, with the IP address and browser used; your credit, AI and sandbox usage. | Our systems |
| Communications | Emails we send you, such as sign-in links, invitations and billing notices, and what you send to support. | You and our systems |
| Product analytics and session recordings | Only if you turn them on — see Product analytics and session recordings. | Your device and our systems |
| Privacy choices | Your analytics and recording choices, when you made them, the version of this policy they were made under, and your browser and language. For visitors who aren’t signed in, a random identifier instead of an account. | You |
Don’t put other people’s personal data or secrets into prompts or chat messages unless you need to — keep secrets in environment variables or connector settings instead. We don’t ask for special categories of personal data, such as health information.
4.How we use it, and why
| Purpose | For example | Legal basis (EU and UK) |
|---|---|---|
| Providing the Service | Your account, projects, sandboxes, the AI agent, deployments, domains, integrations and community listings | Performing our contract with you |
| Payments and credits | Subscriptions, credit packs, and billing emails such as failed-payment notices | Contract; legal obligation, for tax and accounting records |
| Security and preventing abuse | Sign-in checks, rate limits, bans, reviewing community listings, investigating reports | Our legitimate interest in keeping the Service and its users safe; legal obligation |
| Support and service emails | Answering you; sign-in links, invitations and billing notices | Contract; legitimate interests |
| Understanding and improving the Service | Activity logs, errors, AI cost and quality | Legitimate interests |
| Training and improving AI models | Chats and code, used to fine-tune our models, evaluate and improve our agents, and by AI providers to train theirs — see Training AI models | Legitimate interests in improving the Service. You can opt out at any time |
| Product analytics and session recordings | See Product analytics and session recordings | Your consent |
| Legal matters | Responding to lawful requests, enforcing our Terms, defending legal claims | Legal obligation; legitimate interests |
[Counsel: confirm these legal bases, and the equivalent grounds under India’s DPDP Act]
We don’t sell your personal data or use it for advertising. An AI model checks community listings before they go live; if you think a decision about your listing is wrong, email support@paddlewheel.dev and a person will review it.
5.How AI processes your content
What goes to AI models
The agent sends AI model providers what it needs to do the work you ask for, including:
- your messages, recent conversation history, and earlier conversations you mention;
- your project’s code and files;
- results from services you’ve connected, when the agent uses them;
- for community listings, your app’s page text and your screenshots.
Requests go through an AI routing provider, which passes them to third-party AI model providers. If those fail, some coding requests go to free models through a second AI routing provider, which can route them to other model providers. [Confirm the current list of model providers, where they process data, how long they keep requests, and whether any of them may train on them]
Training AI models
We use your chats — your messages and the AI’s replies — and the code in your projects, including code the AI writes, to:
- train and fine-tune our own AI models;
- evaluate and improve our agents and prompts; and
- let AI model providers use your requests to train and improve their models, under their own terms.
We don’t use environment variables or the credentials of services you connect. Content from organizations on the Ultimate plan isn’t used for training.
To opt out, email support@paddlewheel.dev from the email address on your account. Opting out applies to content from then on: it can’t be removed from models that have already been trained, or from requests AI providers already received.
Design and image tools
- An AI design tool receives your app description to generate designs, and keeps the design projects it creates.
- A web search and scraping provider receives a search term based on your app idea, to find design inspiration on public websites.
- Stock image providers receive image search queries the AI writes. Images they return are loaded from their servers when your app is viewed.
Sandboxes
Your code runs in cloud sandboxes from a third-party provider. A sandbox holds your project and the keys it needs to work, such as an AI key for your organization, your Supabase project’s public key, and short-lived access to your connectors — not the connector credentials themselves.
Monitoring AI requests
For every AI request we record which organization, project, user, conversation and message it belongs to, the model used, and the tokens and cost — in our database and with an AI monitoring provider. The monitoring provider receives this metadata, not your prompts or the AI’s responses. [Confirm where the AI monitoring provider stores data]
Staff access and logs
Authorized Paddlewheel staff can view accounts, prompts, chats, code, sandboxes and logs, and can sign in as you (impersonation), when that’s needed to give you support, investigate abuse or security problems, or fix issues. Impersonation sessions are time-limited and recorded in the activity log, and they’re never included in product analytics. Our servers keep application logs, which can include the content of requests, such as prompts and the responses of services you’ve connected, for 30 days. [Confirm the staff access policy]
6.The office
The office is a shared space where your organization’s people, and a project’s agents, appear as characters. In it:
- Presence. People in your organization, and people on projects you share, see whether you’re online, away or busy, your status, which Paddlewheel page or project you’re on, which room you’re in, and when you were last seen. They see where you are, never how long: nothing in the office measures anyone’s time, and there are no per-person reports.
- Voice. Proximity voice and meetings go through a real-time media provider, between the people who are near each other. Voice is never recorded. We keep how long each person was connected, for the organization’s plan limits and billing; if your account is deleted, those rows stay for the organization without your name.
- Chat. Office chat (nearby and everyone) isn’t stored: it lives in the server’s memory while the office is open, and is gone after a restart. Notes left on a desk are kept for 30 days.
- Cloud computers. A cloud computer at your desk runs with our sandbox provider. What’s on it is private to you unless you share your screen with people standing near your desk; watching is view-only. It pauses when nobody’s using it, and it’s deleted after 30 days unused, if you leave the organization, or if your account is deleted.
- Games, whiteboards and your look. Game results are kept for the organization’s leaderboard. Whiteboards keep what was drawn on them. Your avatar is kept per organization.
- Reports and moderation. If someone reports you, the organization’s owners and admins see who reported whom, what they wrote, and where in the office it happened, never what was said in chat. Owners and admins can remove someone from the office for 10 minutes or turn their voice or chat off; each of these is recorded in the organization’s activity log.
Deleting your account removes your office data: your status, looks, desk and notes, game results, reports and your cloud computer, which is shut down first.
7.Product analytics and session recordings
To understand where Paddlewheel gets in people’s way, we use PostHog, hosted in the European Union (Frankfurt, Germany). Both are off unless you turn them on, and session recording can only be on while product analytics is.
How we ask
- Visitors who aren’t signed in see a banner with equal Accept and Reject buttons. Your choice is kept in your browser, and we record it under a random identifier. If you sign in and haven’t chosen on your account yet, the choice is copied to your account.
- New accounts are asked when they pick a username, with both options off; existing accounts are asked once.
- If you say no, we won’t ask again for about six months, unless this policy changes in a way that affects them.
- If your browser sends a Global Privacy Control signal, we don’t ask. Anything you turn on yourself in Settings still applies.
Product analytics
If you turn product analytics on, PostHog receives:
- the pages you open, and your clicks on links, buttons and menus — with their visible text, such as the names of projects in the sidebar — and clicks that don’t seem to do anything;
- events such as creating a project, sending a message (its length, not its text), how long a preview takes to load, deploy attempts and their results, errors in Paddlewheel, and requests that fail (the kind of request and its status code);
- activity from our servers for things you do, such as a deployment that failed — as identifiers and counts, without error text or content;
- errors from the app you’re building, while you preview it: the error’s name, the first line of its message (emails, web addresses and anything that looks like a secret removed; at most 200 characters), the file and the page path — and page changes within the preview;
- your device type, browser, screen size, the page that referred you and campaign tags in links, and your IP address, which PostHog uses to estimate your location (country and city) and then discards;
- answers you choose to send in surveys, such as Report a problem, with anything that looks like an email address or secret masked.
PostHog identifies you by your Paddlewheel user ID, never by your name or email address, and anything that looks like an email address or a secret is masked in the text of clicks and errors. Web addresses are sent without their query strings, except campaign and referral tags. Staff accounts are marked, so their activity can be left out of our reports.
Session recordings
If you also turn session recording on, PostHog records a replay of what you see and do in Paddlewheel: page changes, mouse movements, clicks, scrolling, and what’s on screen. In recordings:
- your chat messages and notifications are visible, with anything that looks like a secret or email address hidden;
- code in the editor and in diffs is masked, and text you type is hidden, except in the chat box;
- the sign-in form, passwords, environment variables, connection credentials, the terminal, database queries and results, and account security settings are hidden completely;
- email addresses are masked where the app shows them, such as in account menus and member lists, but names — yours and other people’s — can appear;
- network requests are recorded as addresses and timing only, never their contents; console output isn’t recorded;
- the preview of your app appears as a blank area, because it’s on a different website.
Recordings are deleted after 30 days. Analytics events are kept for 1 year.
Changing your mind
Turn either one off at any time in Settings → Privacy, or with Privacy choices at the bottom of our home page if you aren’t signed in. It takes effect straight away. Data already collected isn’t deleted automatically — email support@paddlewheel.dev and we’ll delete it. When an account is deleted, its analytics data and recordings in PostHog are deleted too.
Nothing is recorded while a staff member is signed in as you.
9.International transfers
We’re based in India, and our providers process data in India, the United States, the European Union and other countries, so your data may be processed outside the country where you live. Where the law requires it, we protect those transfers with appropriate safeguards, such as the European Commission’s standard contractual clauses. [Counsel: the transfer mechanisms to name]
10.How long we keep it
| Data | How long |
|---|---|
| Account and profile | While your account exists. Deleting your account removes it from our database. |
| Projects, code and chats | While the project exists. Deleting a project in the app hides it, and it’s permanently removed from our database 30 days later. |
| Sessions | Until you sign out, or 7 days after you were last active |
| Sign-in links | 24 hours, or until used |
| Temporary data for resuming AI replies | 24 hours |
| Activity log | 180 days. If your account is deleted, entries remain without your user ID, but can still include the IP address and browser they were recorded with. |
| Billing records | 8 years, as Indian tax and accounting law requires |
| Privacy choice records | Kept as evidence of what you agreed to, including after your account is deleted, for 3 years after you made the choice. |
| Session recordings and analytics events | Recordings: 30 days. Events: 1 year. Both are deleted when your account is. |
| Community listings | Until you unpublish them. We keep a listing’s versions and statistics after that, and screenshots already published at public addresses may remain. |
| Server logs and backups | 30 days |
Copies we don’t yet remove automatically
When you delete a project or your account, some copies aren’t removed automatically yet: your project’s code in our file storage, apps hosted on our hosting account, design projects at our AI design tool, and your customer record at Dodo Payments. Email support@paddlewheel.dev and we’ll delete them. [Engineering: remove these automatically, then update this section]
We may keep data longer where the law requires it, or to resolve disputes and enforce our agreements.
11.Your rights and choices
Depending on where you live, you may have the right to:
- access the personal data we hold about you, and get a copy of it in a portable format;
- correct data that’s wrong or incomplete;
- have your data deleted;
- object to, or ask us to restrict, how we use it — including where we rely on legitimate interests;
- withdraw your consent at any time, without affecting what was done before;
- complain to a data protection authority.
Doing it in the app
- Product analytics and session recordings: Settings → Privacy.
- Your name, username and password: account settings.
- Connected services: disconnect them in your project or organization settings.
- Community listings: unpublish them from the project.
Asking us
For anything else — including opting out of AI training, and deleting your account, which isn’t self-serve yet — email support@paddlewheel.dev from the email address on your account. We may need to confirm it’s you. We’ll respond within 30 days, and won’t treat you differently for using your rights.
India
Under the Digital Personal Data Protection Act, 2023, you can also nominate someone to exercise your rights if you die or become incapacitated, and raise a grievance with our Grievance Officer (see Who we are). If you’re not satisfied with our response, you can complain to the Data Protection Board of India.
European Economic Area and United Kingdom
You can complain to the data protection authority where you live or work, or where you think a breach happened.
United States
Some US state laws give residents rights to know, access, correct and delete personal data, and to opt out of its sale or sharing for targeted advertising. We don’t sell or share personal data that way. We treat a Global Privacy Control signal as a request not to be asked about analytics.
13.Security
We protect personal data with measures including:
- encrypted connections (HTTPS) to the Service;
- passwords stored as hashes, and optional two-factor authentication;
- encryption of stored credentials for connectors, Supabase, hosting accounts, the GitHub app and your own Dodo Payments account;
- a scan for secrets before code is pushed to GitHub;
- access to production systems limited to authorized staff, and a record of staff sign-ins to user accounts.
No system is completely secure. If a breach affects your personal data, we’ll tell you and the relevant authorities as the law requires. To report a security issue, email support@paddlewheel.dev.
14.Children
Paddlewheel is only for people aged 18 and over, and we don’t knowingly collect personal data from anyone younger. If you think someone under 18 has an account, email support@paddlewheel.dev and we’ll delete it.
15.Your apps and their users
For personal data your apps collect from their users, you’re responsible as the controller, and we process that data only on your behalf, to build, host and run your app. That includes data in databases you connect, such as Supabase — which stays in your own Supabase account — and data that passes through your previews and deployed apps.
Give your app’s users the privacy information the law requires, and get any consent it needs, for example for analytics you add.
16.Changes to this policy
We’ll update this policy when the Service or the law changes. The “Last updated” date at the top shows when it last changed. If a change is material, we’ll tell you by email or in the app before it takes effect, and if it affects product analytics or session recordings, we’ll ask for your choice again — until you answer, they stay off.
17.Contact us
Paddlewheel
Bengaluru, Karnataka
India
Email: support@paddlewheel.dev