Draft, pending legal review
Privacy notice
Last updated
Who we are
PipeXP is run by CMDZ Ltd, Ireland. For personal data in your workspace, your organisation is the controller and we are its processor. For account, billing and website data, we are the controller. Contact: privacy@pipexp.dev.
What we collect
- Account: your name, work email and, if you use it, your GitHub username.
- Pull request data from GitHub: titles, authors, reviewers, reviews, checks and statuses. Not your source code.
- Agent run events your machines send: steps, snags, models, tokens, cost and times.
- Machine setup checks: which tools are set up, never secrets.
- Billing: company name, address and VAT number. Card details go to Stripe, not to us.
- Website visits, first-party only: a random browser id kept in your browser, the page path, and where you first came from (the utm_source or ref tag, the referring site's name and your first page). No cookies, no third-party trackers, no IP address or full URLs.
- Basic logs needed to keep the service secure and working.
Why, and on what legal basis
- To provide PipeXP under our contract with your organisation.
- To keep it secure and fix problems, which is in our legitimate interest.
- To bill and keep tax records, which the law requires.
- To send product emails you ask for. You can stop them at any time.
We do not sell personal data, show ads, or use your data to train AI models.
If your organisation turns it on, a project owner may post a standup summary (names and work counts) to your team's own chat channel.
Where it is kept
Your workspace data is hosted in the EU (Ireland). Where a sub-processor handles data outside the EU, it is covered by EU Standard Contractual Clauses or an adequacy decision.
Sub-processors
| Company | What for | Where |
|---|---|---|
| Vercel | Hosts the website and app | EU (Ireland) |
| Convex | Database and backend | EU (Ireland) |
| Sign in with Google, through WorkOS, if you choose it | US, under EU Standard Contractual Clauses | |
| WorkOS | Runs every sign-in: Google, GitHub, Microsoft, passkey or email code, and single sign-on on Business. SCIM directory sync on Enterprise | US, under EU Standard Contractual Clauses |
| Stripe | Payments and invoices | EU and US, under EU Standard Contractual Clauses |
| Resend | Invites and notification emails (sign-in codes come from WorkOS) | US, under EU Standard Contractual Clauses |
| GitHub | Source of pull request data you connect, and sign in with GitHub, through WorkOS, if you choose it | US, under EU Standard Contractual Clauses |
| Microsoft | Sign in with Microsoft, through WorkOS, if you choose it; Teams alerts, only if you connect Teams | Sign-in: US, through WorkOS. Teams alerts: Microsoft's Bot Service, then your Microsoft 365 tenant. Both under EU Standard Contractual Clauses |
| PostHog | Product analytics: per project, when it is created, a service or machine is connected and an agent run starts (no person or content). Pages and feature use only after you press Allow, with a user id, never names, emails or PR content | EU (Frankfurt) |
| TypeSafe | Files human review comments by category (their text, PR title, file path and diff lines) | US, under EU Standard Contractual Clauses |
How long we keep it
The board, Insights and Team read back as far as your plan allows:
- Free: 14 days
- Team: 1 year
- Business: 3 years
- Enterprise: as long as your contract says
We keep a project's history for its plan's window plus 30 days, then delete it each night. Business and Enterprise owners can keep less. Open pull requests, running agent sessions, settings and the XP ledger are kept while the project exists.
An owner can export a project's data as a zip. To have a project's data deleted, email us: we delete it within 30 days, apart from billing records we must keep by law.
Your rights
You can ask to see, correct, export or delete your personal data, or object to how we use it. If your organisation runs your workspace, we will pass the request to them. Email privacy@pipexp.dev. You can also complain to the Irish Data Protection Commission at dataprotection.ie.
Cookies
We use only the cookies needed to sign you in and keep you signed in. No advertising cookies.
PipeXP counts, per project, when a project is created, a service or machine is connected, its first pull requests arrive and an agent run starts. These counts go to PostHog (EU) with the project's id only: no person, name or content. Which pages and features are used is counted only if you press Allow on the banner, and never with Do Not Track or Global Privacy Control on; it then carries an id for your account and your project, never your name, email, code or pull request content. A project owner can instead choose, for the whole project in Settings > Security, to turn all of this off (the per-project counts too), or to allow only anonymous counts of pages and features, with no cookie, no person and no banner. Page addresses are sent without their query. Screen recordings run only on our public pages and onboarding, with every field and text masked. Clear your choice by clearing this site's storage.