Bivy

Privacy Policy

Last updated: 7 September 2026

Bivy is a local-first, open-source AI agent workspace that runs on your own machine. For launch, Bivy Cloud is the hosted control plane and relay; it is not a hosted AI inference service. This policy explains what the hosted services do and do not collect. It does not apply to software you run entirely on your own hardware without signing in to the hosted service.

The short version. Your agent sessions — prompts, files, tool output, model API keys, provider OAuth tokens, and GitHub repo tokens — stay on your machine or in a vault you control. When you connect a phone through our relay, interactive session traffic is end-to-end encrypted and the relay only ever sees ciphertext. We never receive your interactive session content or plaintext model credentials. Slack commands and generic automation webhook payloads are exceptions: those senders call the control plane directly, so their instruction text reaches us in plaintext.

What we collect

DataWhy
Email addressTo create your account and send passwordless magic-link sign-in emails.
Billing data (via Stripe)If you subscribe, Stripe processes your payment. We store your Stripe customer and subscription identifiers, plan, and subscription status — not your card details.
Native push notifications, when enabledWe associate an Apple push token with your signed-in device to deliver alerts. Apple receives generic alert text and opaque session or run links, not your prompts, session titles, or tool output. Registration is refreshed while you use the app, stops being eligible after sign-out revocation, and expires after seven days without refresh. Offline sign-out cannot retract an alert already delivered to your device.
App Store billing data, where offeredApple processes in-app subscription payments. We verify purchase identifiers, product, subscription status, renewal and expiry dates, and a pseudonymous purchase-ownership token. We do not receive your payment-card details or Apple Account password.
Machine registry metadataThe identifier and display name you give each machine, plus online/offline status and last-seen time, so you can manage your machines.
Session/work metadataOptional cross-machine session and work-queue metadata such as machine id, session id, status, repo slug, issue number, and timestamps. This is routing metadata, not transcript content.
Slack and generic webhook instructionsSlack commands and generic automation webhook payloads call the control plane directly. We store the bounded instruction text with the queued work item until that item is deleted. Do not include secrets in these instructions.
Encrypted credential sync blobsIf enabled, machines may upload encrypted model-auth vault ciphertext and per-machine wrapped keys so another enrolled machine can sync credentials. Bivy Cloud cannot decrypt these blobs.
Operational logsConnection counts, timestamps, and privacy-safe product milestones used to keep the service running, understand activation, and detect abuse. These never contain session payloads, prompts, account identifiers, or email addresses.
Website analytics, with your consentGoogle Analytics 4 measures website visits and engagement using browser identifiers and cookies. It receives information such as the visited page, referring site, and browser/device information. We use aggregate reports to understand how visitors find and use the website. The marketing-site integration does not send Bivy account identifiers, prompts, repository contents, or agent session activity.

What we never collect

Third parties we share data with

We do not sell your personal data.

Cookies and local storage

The web and remote-control interfaces store a session token in your browser's local storage to keep you signed in. The marketing site stores your analytics preference in local storage. Google Analytics loads only after you accept; declining does not prevent you from using the site. If accepted, analytics cookies such as _ga and _ga_* help measure visits and engagement. The marketing-site integration disables Google Signals and advertising personalization.

You can change your choice using the Analytics preferences button on marketing pages. Withdrawing consent stops this site's Google Analytics integration, clears its _ga cookies on this domain, and reloads the page. It does not erase data already sent to Google. If your browser blocks local storage, your choice may not persist across pages. Browser tracking protection or blocking scripts may also prevent analytics from running.

Data retention

We keep account and machine metadata for as long as your account is active. Magic-link and connection tokens are short-lived and expire automatically. When you delete your account, we remove your account and machine metadata; billing records may be retained where required by law. We also retain pseudonymous App Store purchase-ownership records to prevent receipt replay, reassignment, or recreation of access after account deletion. Deleting your Bivy account does not cancel a subscription billed by Apple; cancel it separately in your Apple Account subscription settings.

Data controller

The data controller for the hosted services is Sjulstad Labs (Norwegian organization number 923640940), Norway. For any privacy or data-protection question, contact us at support@bivy.sh.

Your rights

Depending on where you live (including the EU/EEA under the GDPR), you may have the right to access, correct, export, or delete your personal data, and to object to or restrict its processing. To exercise these rights, contact the data controller, Sjulstad Labs, at support@bivy.sh.

Work queues

For GitHub issue and comment jobs, the hosted control plane retains routing metadata such as repository, issue number, target machine, status, and timestamps. It does not retain the issue title or body; the claiming machine fetches that content directly from GitHub immediately before running. Slack commands and generic webhook instructions are different: their instruction text reaches the control plane in plaintext and is stored with the queued work item until deletion. Sanitized outcome reports contain allowlisted routing, check, retry, branch, and pull-request metadata — never transcripts, diffs, file contents, secrets, or raw tool output.

Changes

We may update this policy from time to time. Material changes will be reflected by the "last updated" date above.

Contact

Questions about privacy? Email support@bivy.sh. The hosted services are operated by Sjulstad Labs (Norwegian organization number 923640940), Norway.