Skip to content

Draft, pending legal review

Privacy notice

Last updated

Who we are

PipeXP is run by CMDZ Ltd, Ireland. For personal data in your workspace, your organisation is the controller and we are its processor. For account, billing and website data, we are the controller. Contact: privacy@pipexp.dev.

What we collect

  • Account: your name, work email and, if you use it, your GitHub username.
  • Pull request data from GitHub: titles, authors, reviewers, reviews, checks and statuses. Not your source code.
  • Agent run events your machines send: steps, snags, models, tokens, cost and times.
  • Machine setup checks: which tools are set up, never secrets.
  • Billing: company name, address and VAT number. Card details go to Stripe, not to us.
  • Website visits, first-party only: a random browser id kept in your browser, the page path, and where you first came from (the utm_source or ref tag, the referring site's name and your first page). No cookies, no third-party trackers, no IP address or full URLs.
  • Basic logs needed to keep the service secure and working.

Why, and on what legal basis

  • To provide PipeXP under our contract with your organisation.
  • To keep it secure and fix problems, which is in our legitimate interest.
  • To bill and keep tax records, which the law requires.
  • To send product emails you ask for. You can stop them at any time.

We do not sell personal data, show ads, or use your data to train AI models.

If your organisation turns it on, a project owner may post a standup summary (names and work counts) to your team's own chat channel.

Where it is kept

Your workspace data is hosted in the EU (Ireland). Where a sub-processor handles data outside the EU, it is covered by EU Standard Contractual Clauses or an adequacy decision.

Sub-processors

Sub-processors
CompanyWhat forWhere
VercelHosts the website and appEU (Ireland)
ConvexDatabase and backendEU (Ireland)
GoogleSign in with Google, through WorkOS, if you choose itUS, under EU Standard Contractual Clauses
WorkOSRuns every sign-in: Google, GitHub, Microsoft, passkey or email code, and single sign-on on Business. SCIM directory sync on EnterpriseUS, under EU Standard Contractual Clauses
StripePayments and invoicesEU and US, under EU Standard Contractual Clauses
ResendInvites and notification emails (sign-in codes come from WorkOS)US, under EU Standard Contractual Clauses
GitHubSource of pull request data you connect, and sign in with GitHub, through WorkOS, if you choose itUS, under EU Standard Contractual Clauses
MicrosoftSign in with Microsoft, through WorkOS, if you choose it; Teams alerts, only if you connect TeamsSign-in: US, through WorkOS. Teams alerts: Microsoft's Bot Service, then your Microsoft 365 tenant. Both under EU Standard Contractual Clauses
PostHogProduct analytics: per project, when it is created, a service or machine is connected and an agent run starts (no person or content). Pages and feature use only after you press Allow, with a user id, never names, emails or PR contentEU (Frankfurt)
TypeSafeFiles human review comments by category (their text, PR title, file path and diff lines)US, under EU Standard Contractual Clauses

How long we keep it

The board, Insights and Team read back as far as your plan allows:

  • Free: 14 days
  • Team: 1 year
  • Business: 3 years
  • Enterprise: as long as your contract says

We keep a project's history for its plan's window plus 30 days, then delete it each night. Business and Enterprise owners can keep less. Open pull requests, running agent sessions, settings and the XP ledger are kept while the project exists.

An owner can export a project's data as a zip. To have a project's data deleted, email us: we delete it within 30 days, apart from billing records we must keep by law.

Your rights

You can ask to see, correct, export or delete your personal data, or object to how we use it. If your organisation runs your workspace, we will pass the request to them. Email privacy@pipexp.dev. You can also complain to the Irish Data Protection Commission at dataprotection.ie.

Cookies

We use only the cookies needed to sign you in and keep you signed in. No advertising cookies.

PipeXP counts, per project, when a project is created, a service or machine is connected, its first pull requests arrive and an agent run starts. These counts go to PostHog (EU) with the project's id only: no person, name or content. Which pages and features are used is counted only if you press Allow on the banner, and never with Do Not Track or Global Privacy Control on; it then carries an id for your account and your project, never your name, email, code or pull request content. A project owner can instead choose, for the whole project in Settings > Security, to turn all of this off (the per-project counts too), or to allow only anonymous counts of pages and features, with no cookie, no person and no banner. Page addresses are sent without their query. Screen recordings run only on our public pages and onboarding, with every field and text masked. Clear your choice by clearing this site's storage.