AICodeShare

Version 2026-08-19.1 / Effective 13 September 2026

Privacy Policy

Data controller: MAXIMUS CONSULTING AND INVESTMENTS INC., 3019 182nd PL SE, Bothell, WA 98012, USA. Contact info@aicodekeyshare.com.

01What AgentGov is

AgentGov is a governance and cost-attribution layer for AI coding agents. It has two parts: a local gateway installed on the developer’s machine, which proxies requests between the coding agent and the model provider; and a hosted control tower that stores policy configuration and usage telemetry and renders the dashboard.

02Data we never process

AgentGov does not read, store, log or transmit:

  • Prompt content.
  • Model completion content.
  • The contents of files your coding agent reads or writes.
  • Any part of the conversation transcript with the model provider.

These stay between your local coding agent and your model provider. Our gateway forwards response bytes verbatim without buffering the body. No subprocessor of ours sees this content, because we never process it in the first place.

03Data that stays on the developer's machine

  • Your model-provider OAuth session or API key. In passthrough mode the gateway forwards it unchanged; in vault mode it is decrypted per request from a sealed policy snapshot and exists only in memory.
  • The device private key used to decrypt those snapshots (file mode 0600).
  • Your AgentGov session token from `agentgov login` (file mode 0600).
  • A local cache of the signed policy snapshot, and a local queue of telemetry not yet uploaded.

04Data we hold in the control tower

  • Identity: email, name, role, and authentication subject claim.
  • Devices: device name, public key, a machine fingerprint (a hash of hostname and MAC address), and timestamps.
  • Credentials: only SHA-256 hashes of governance keys and service tokens — never the plaintext. Vaulted upstream credentials are stored as per-device ciphertext that our operators cannot read at rest.
  • Configuration you enter: repositories, grants, budgets, and work-item labels.
  • Sessions and work-item bindings: timestamps and attribution links.
  • Token events: per-request counts (input, output, cache), model name and timestamps. No content.
  • Authorisation decisions: allow or deny, a reason code, and a timestamp.
  • Terms acceptance: which version of our Terms and Privacy Policy you accepted, and when.

Work-item labels are free text that a developer types. Please do not put personal or sensitive information in them — they appear in dashboards and reports across your organisation.

05Why we process it

  • To provide the Service: authenticate you, enforce the policies you configure, and produce your dashboards.
  • To bill you for your subscription.
  • To keep the Service secure and diagnose faults.
  • To meet legal and accounting obligations.

Where the GDPR applies, our lawful bases are performance of a contract, our legitimate interests in operating and securing the Service, and compliance with legal obligations.

06Subprocessors

We rely on Vercel (hosting), Supabase (database), Auth0 (authentication), Stripe (billing), and your chosen model provider. None of them receives prompt or completion content. The current list is maintained in our published subprocessor documentation.

07Retention

  • Local gateway state is kept until you uninstall or delete it. Losing it is safe — snapshots are re-fetched and queued events re-sent.
  • Operational data is kept for the term of your subscription plus a 30-day wind-down after termination. Revoked devices are kept 90 days for forensics; grants and repository metadata for 12 months after they end; sessions and work-item bindings for 24 months.
  • The append-only usage ledger is kept for 6 years to meet tax and audit obligations, or until you request deletion where deletion is legally permitted.
  • Policy snapshots are kept on a 90-day rolling basis and revocation events for 12 months, both for debugging and rollback.

The usage ledger is hash-chained and append-only by design, so deleting a single record leaves a verifiable break in the chain. We will tell you when a deletion request has that effect.

08Cookies

We use one cookie, and only to keep you signed in. We do not use analytics, advertising, tracking or third-party cookies, and we do not share it with anyone.

  • agentgov_session — holds your dashboard session so you are not asked to sign in on every page. Set only after you sign in, expires after 30 days, and is sent only to this site.
  • It is httpOnly, so scripts running in your browser cannot read it, and it is marked Secure so it is only ever sent over HTTPS.
  • Signing out deletes it. Deleting it yourself signs you out; nothing else breaks.

Because this cookie does nothing except deliver the signed-in service you asked for, it is “strictly necessary” and we do not ask for consent to set it — consent is required for cookies that are not essential, and we do not set any. That is also why there is no cookie banner: a banner offering a choice we could not honour would be misleading. If we ever add analytics or any other non-essential cookie, we will ask for your consent first and update this section before doing so.

The gateway on your own machine sets no cookies at all. It stores its state in files under your home directory, described in section 3.

09Your rights

Depending on where you live you may have rights to access, correct, delete, port, or restrict processing of your personal data, and to object to it. Contact info@aicodekeyshare.com and we will respond within the period the law requires. You may also complain to your local data protection authority.

Where we process data on behalf of your employer, they are the controller and we act as processor. Address requests to them first; we will help them respond.

10Security

Credentials are stored hashed. Vaulted provider keys are encrypted per device so that our operators cannot read them at rest. Database access is row-level-security scoped per tenant. No system is perfectly secure, and the limitations in our Terms of Service apply.

11International transfers and changes

Our subprocessors may process data outside your country. Where required we rely on appropriate safeguards such as the EU Standard Contractual Clauses. If we change this policy materially we will update the version above and ask you to review it.