Privacy Policy
Delvin
What we store
Account records (email, hashed password), projects, sessions, messages, agent runs, tool calls, terminal commands and file changes needed to operate the workspace.
Audit log
Approvals, consent records and security-relevant actions are written to an audit log with timestamps and IP address for accountability.
Provider keys
Model provider credentials live in server-side environment configuration. They are never sent to the browser and never written into the database.
Your code
Repository contents stay inside the workspaces you configure on infrastructure you operate. We do not train on your code.
Retention
Session history is retained until you delete it. Deleting a session removes its messages, runs, tool calls and events.
Third parties
Requests sent to a configured model provider are governed by that provider's privacy policy. Nothing is sent to a provider unless a run is started.
Contact: [email protected]