Privacy Policy
Last updated: 7 September 2026
Bivy is a local-first, open-source AI agent workspace that runs on your own machine. For launch, Bivy Cloud is the hosted control plane and relay; it is not a hosted AI inference service. This policy explains what the hosted services do and do not collect. It does not apply to software you run entirely on your own hardware without signing in to the hosted service.
What we collect
| Data | Why |
|---|---|
| Email address | To create your account and send passwordless magic-link sign-in emails. |
| Billing data (via Stripe) | If you subscribe, Stripe processes your payment. We store your Stripe customer and subscription identifiers, plan, and subscription status — not your card details. |
| Native push notifications, when enabled | We associate an Apple push token with your signed-in device to deliver alerts. Apple receives generic alert text and opaque session or run links, not your prompts, session titles, or tool output. Registration is refreshed while you use the app, stops being eligible after sign-out revocation, and expires after seven days without refresh. Offline sign-out cannot retract an alert already delivered to your device. |
| App Store billing data, where offered | Apple processes in-app subscription payments. We verify purchase identifiers, product, subscription status, renewal and expiry dates, and a pseudonymous purchase-ownership token. We do not receive your payment-card details or Apple Account password. |
| Machine registry metadata | The identifier and display name you give each machine, plus online/offline status and last-seen time, so you can manage your machines. |
| Session/work metadata | Optional cross-machine session and work-queue metadata such as machine id, session id, status, repo slug, issue number, and timestamps. This is routing metadata, not transcript content. |
| Slack and generic webhook instructions | Slack commands and generic automation webhook payloads call the control plane directly. We store the bounded instruction text with the queued work item until that item is deleted. Do not include secrets in these instructions. |
| Encrypted credential sync blobs | If enabled, machines may upload encrypted model-auth vault ciphertext and per-machine wrapped keys so another enrolled machine can sync credentials. Bivy Cloud cannot decrypt these blobs. |
| Operational logs | Connection counts, timestamps, and privacy-safe product milestones used to keep the service running, understand activation, and detect abuse. These never contain session payloads, prompts, account identifiers, or email addresses. |
| Website analytics, with your consent | Google Analytics 4 measures website visits and engagement using browser identifiers and cookies. It receives information such as the visited page, referring site, and browser/device information. We use aggregate reports to understand how visitors find and use the website. The marketing-site integration does not send Bivy account identifiers, prompts, repository contents, or agent session activity. |
What we never collect
- The content of your interactive agent sessions — prompts, responses, files, or tool output.
- Your plaintext model provider API keys, provider OAuth tokens, GitHub repo tokens, or other local secrets.
- Agent transcripts, terminal output, prompts you type into an active session, workspace files, or tool output.
- Your model calls: Bivy Cloud does not proxy normal AI inference at launch.
- The end-to-end encryption keys used between your machine and your devices (the relay never holds them).
Third parties we share data with
- Stripe — payment processing and subscription management (privacy policy).
- Apple — native push delivery when enabled, App Store purchase processing, subscription verification, and renewal/refund notifications for in-app subscriptions (privacy policy).
- Resend — delivery of sign-in and account emails (privacy policy).
- Google Analytics — optional marketing-site usage analytics, loaded after you accept analytics cookies. Google processes this data under its applicable terms and privacy policy (privacy policy; how Google uses information from partner sites).
- Our hosting provider — runs the control plane and relay servers.
We do not sell your personal data.
Cookies and local storage
The web and remote-control interfaces store a session token in your
browser's local storage to keep you signed in. The marketing site stores
your analytics preference in local storage. Google Analytics loads only
after you accept; declining does not prevent you from using the site.
If accepted, analytics cookies such as _ga and
_ga_* help measure visits and engagement. The marketing-site
integration disables Google Signals and advertising personalization.
You can change your choice using the Analytics preferences
button on marketing pages. Withdrawing consent stops this site's Google
Analytics integration, clears its _ga cookies on this domain,
and reloads the page. It does not erase data already sent to Google.
If your browser blocks local storage, your choice may not persist across
pages. Browser tracking protection or blocking scripts may also prevent
analytics from running.
Data retention
We keep account and machine metadata for as long as your account is active. Magic-link and connection tokens are short-lived and expire automatically. When you delete your account, we remove your account and machine metadata; billing records may be retained where required by law. We also retain pseudonymous App Store purchase-ownership records to prevent receipt replay, reassignment, or recreation of access after account deletion. Deleting your Bivy account does not cancel a subscription billed by Apple; cancel it separately in your Apple Account subscription settings.
Data controller
The data controller for the hosted services is Sjulstad Labs (Norwegian organization number 923640940), Norway. For any privacy or data-protection question, contact us at support@bivy.sh.
Your rights
Depending on where you live (including the EU/EEA under the GDPR), you may have the right to access, correct, export, or delete your personal data, and to object to or restrict its processing. To exercise these rights, contact the data controller, Sjulstad Labs, at support@bivy.sh.
Work queues
For GitHub issue and comment jobs, the hosted control plane retains routing metadata such as repository, issue number, target machine, status, and timestamps. It does not retain the issue title or body; the claiming machine fetches that content directly from GitHub immediately before running. Slack commands and generic webhook instructions are different: their instruction text reaches the control plane in plaintext and is stored with the queued work item until deletion. Sanitized outcome reports contain allowlisted routing, check, retry, branch, and pull-request metadata — never transcripts, diffs, file contents, secrets, or raw tool output.
Changes
We may update this policy from time to time. Material changes will be reflected by the "last updated" date above.
Contact
Questions about privacy? Email support@bivy.sh. The hosted services are operated by Sjulstad Labs (Norwegian organization number 923640940), Norway.